The Hidden Conduit: How Millions of TV Boxes Fuel a Global Data-Scraping Machine

the-hidden-conduit-how-millions-of-tv-boxes-fuel-a-global-data-scraping-machine

For the past four years, a sprawling, persistent Android-based botnet known as "Popa" has quietly co-opted millions of consumer streaming devices. Unlike the high-profile, destructive botnets of the past—which were designed to crash websites via distributed denial-of-service (DDoS) attacks—Popa operates as a silent, invisible relay. It transforms innocuous household TV boxes into residential proxies, creating a massive, encrypted tunnel that allows third parties to route internet traffic through unsuspecting home networks.

This week, a coalition of cybersecurity researchers has formally linked the Popa infrastructure to NetNut, a residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. The investigation reveals a disturbing symbiosis between the thriving market for "cheap" streaming hardware and the burgeoning, multi-billion-dollar economy of AI-driven data scraping.

The Anatomy of the Popa Botnet

Popa is not a standalone malware campaign in the traditional sense; rather, it functions as a modular plugin associated with the "Vo1d" botnet. The Vo1d campaign specifically targets unauthorized, non-certified Android TV boxes—devices marketed under thousands of obscure brand names and sold at top-tier e-commerce retailers. These devices are advertised as "all-in-one" streaming solutions, offering access to thousands of premium subscription services for a single, one-time fee.

However, the convenience comes at a hidden cost. Once plugged into a wall outlet and connected to a local Wi-Fi network, these boxes serve as a permanent gateway. Through the Popa plugin, they allow external entities to hijack the device’s internet connection, masking their own traffic as that of a genuine residential user. Researchers have observed that this architecture is designed for long-lived, encrypted connections, effectively creating a "communication tunnel" that remains open as long as the device is powered.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

A Chronology of Discovery

The origins of the Popa botnet began to surface in a 2025 investigative report by Chinese security firm XLAB, which identified nine specific domain names acting as command-and-control centers for compromised devices.

In June 2026, the security firm Qurium published a follow-up analysis after investigating a series of disruptive, high-volume data-scraping events. Qurium discovered that their servers were being flooded by requests originating from over 1.4 million unique IP addresses. By mapping the traffic, they identified several dozen control domains, including gmslb[.]net, safernetwork[.]io, and ninjatech[.]io.

The trail led directly to Ninjatech, a company founded by Moishi Kramer, who concurrently serves as the Vice President of Research and Development at NetNut. While Alarum Technologies acquired NetNut, records and professional histories link Kramer to the architectural design and scaling of the proxy network.

The timeline of these domains suggests a game of "whack-a-mole." In July 2025, after a joint intervention by Google, HUMAN Security, and Trend Micro dismantled the "Badbox 2.0" botnet—a close relative of Vo1d—many of the original control domains were seized. Almost immediately, however, a new set of domains, including those tied to Ninjatech, emerged to sustain the Popa network’s operations.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Supporting Data and Technical Findings

The scale of the Popa botnet is staggering. Chris Formosa, a senior lead information security engineer at Black Lotus Labs (a division of Lumen Technologies), notes that Popa maintains a daily average of between 1.5 million and 2.5 million distinct IP addresses.

"What makes Popa dangerous is its ubiquity," Formosa explains. "It is not just one service; it is the backbone for countless other proxy providers who resell NetNut’s infrastructure. Because Popa IPs appear across the entire ecosystem, the botnet’s reach is exponentially amplified."

Other experts corroborate these findings. Jérôme Meyer of Nokia Deepfield suggests that the total number of devices could be even higher. By monitoring a subset of just 26 relay nodes, Meyer observed 750,000 unique sources within a 24-hour period. Each node handles between 35,000 and 60,000 concurrent client connections, painting a picture of an industrial-grade proxy machine that dwarfs most traditional botnet operations.

Further forensic evidence comes from Synthient, a proxy-tracking firm. Their recent analysis of the Popa SDK revealed outbound traffic patterns that match NetNut’s signature. "The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients," the firm stated, asserting that the link between Popa and NetNut is technically undeniable.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Official Responses and Denials

In response to these findings, Moishi Kramer provided a statement via email, claiming that Ninjatech ceased operations approximately five years ago upon selling the Popa software development kit (SDK). "That code was sold and licensed to third parties years ago," Kramer argued. "Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it." Kramer explicitly denied any current involvement in or visibility into the infrastructure currently labeled as Popa.

Alarum Technologies issued a formal rebuttal, labeling the reports from Synthient and Qurium as containing "demonstrably inaccurate assertions." The company stated that their SDKs are designed for legitimate "bandwidth-sharing" rather than botnet activity. "NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services," the statement read, emphasizing their "Know Your Customer" (KYC) protocols and commitment to preventing misuse.

However, industry skepticism remains high. The proxy-tracking service Spur recently challenged the efficacy of these safeguards, noting that NetNut’s "verified corporation" policy is often little more than marketing. Spur’s research suggests that many downstream resellers—who tap into the same proxy pool—perform zero verification, allowing anyone with a burner email and $5 in cryptocurrency to purchase access to millions of residential connections.

The AI Scraping Economy: A New Paradigm

The rise of Popa coincides with the explosion of the generative AI sector. Large Language Models (LLMs) require massive amounts of text, image, and video data for training, and "scraping" the open web has become the primary method for acquiring this training data.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Modern websites, however, have become adept at blocking datacenter-based scraping. By using residential IP addresses—those belonging to actual homes—scraping bots can bypass these defenses, appearing to servers as legitimate, individual users. A report from Include Security highlights this irony: the same devices used to pirate streaming content are now being leveraged to feed the AI models of some of the world’s most prominent technology firms.

This activity has led to over 70 copyright infringement lawsuits, as non-profit organizations, libraries, and academic repositories report severe service degradation caused by aggressive scraping bots. The Confederation of Open Access Repositories (COAR) found that 90% of survey respondents face service disruptions from these bots at least once a week.

Implications for Corporate and Personal Security

The danger of residential proxy networks is not limited to the living room. Infoblox, a security firm that monitors network traffic, found that 65% of its customer base—including pharmaceutical, food, government, and banking entities—were querying domains associated with residential proxies.

When an employee brings a compromised "smart" device or uses an app with a proxy SDK on a corporate network, they effectively grant external actors a "backdoor" into that secure environment. If a threat actor uses that proxy to launch an attack, the source IP address traced by authorities will point back to the victim’s corporate network, resulting in legal exposure, brand damage, and massive incident response costs.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Conclusion: The Path Forward

The ubiquity of proxy SDKs in modern consumer electronics, from smart TVs to PDF viewers, has created a crisis of consent. Many apps use dense, legalistic privacy policies that are nearly impossible to navigate on a TV interface, allowing the app to monetize the user’s connection long after the initial installation.

While companies like Amazon and Roku have taken proactive steps to ban proxy-facilitating SDKs from their platforms, LG and Samsung still host thousands of applications that include these components. As security experts emphasize, the fundamental issue is that users have no intuitive way to understand that they are "selling" their home network to an unknown third party. Until device manufacturers, regulators, and software developers impose stricter controls on how residential bandwidth is accessed, the "Popa" phenomenon serves as a warning: in the age of AI, your home network may no longer be entirely your own.