Introduction to the Popa Botnet
The Popa botnet is a sprawling Android-based botnet that has been forcing millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts for the past four years.
Link to NetNut and Alarum Technologies
Researchers from multiple security firms have concluded that the Popa botnet is linked to NetNut, a residential proxy provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].
Malicious streaming devices sold online enroll the user's home Internet address in a residential proxy service, allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network.
Popa's Purpose and Functionality
Popa appears designed with a singular purpose: implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand.
Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.
Investigation and Findings
The first clues about Popa's origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names used to register and direct the activities of compromised devices.
In a report released in June 2026, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company's hosted organizations.
Qurium found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io.
NetNut's Involvement and Response
Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut.
Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device's bandwidth and to run only after the host application obtained user consent.
However, in a separate Popa research report, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut.
Alarum Technologies, NetNut's Tel Aviv-based parent company, said the reports by Synthient and Qurium contained demonstrably inaccurate assertions and flawed deductions rather than verified facts.
Prevalence and Impact of Popa
Chris Formosa, senior lead information security engineer for Black Lotus Labs, said what especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing.
Formosa said the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses each day, relying on between 250 and 300 Internet addresses that are used to direct its activities.
Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen's estimates.
Symbiosis of Proxies and Data Scraping
Experts say many of the world's largest proxy providers have updated their public-facing branding to highlight their utility for training AI platforms, implying it is a primary use case for their residential proxies.
NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy.
The non-stop content scraping has spawned more than 70 copyright infringement lawsuits against major tech companies that have acknowledged large-scale data scraping as a major source of the brains behind their commercial AI offerings.
Source: Krebs on Security