‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

🇧🇷 PT 🇺🇸 EN

hu, 18 Jun 2026

← Back

Executive Summary

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand. Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming...

Details

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.

Popa is a massive botnet, but by all accounts it is unlike traditional botnets that enlist compromised systems in destructive activities, such as coordinating huge distributed denial-of-service attacks. Rather, Popa appears designed with a singular purpose: Implementing a persistent communications layer capable of registering a device, maintaining long-lived encrypted connections, and opening communication tunnels on demand. Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes. These devices, which are marketed under thousands of brand names and model numbers and broadly available for purchase at top e-commerce destinations, all advertise the ability to stream hundreds of subscription video services for an up front one-time fee.

But as the FBI and security industry experts have warned repeatedly, these streaming boxes typically bundle or come pre-installed with software that turns the user’s TV into a “residential proxy” — allowing anyone to route their Internet traffic through that device for as long as it remains plugged into a wall socket and connected to a local network. More concerning, some of these proxy networks do little to stop malicious customers from communicating with and even compromising systems on the local network of the unsuspecting device owner. The first clues about Popa’s origins came in a 2025 report from the Chinese security company XLAB, which flagged at least nine domain names that were used to register and direct the activities of compromised devices. In a report released today, the security firm Qurium described how it stumbled on some of those same domains while investigating a series of disruptive and expensive data scraping events targeting the company’s hosted organizations in May 2026, in which the scraping activity was scattered evenly across more than 1.4 million Internet addresses.

Qurium said it found several dozen domains used to control Popa that were all hosted in lockstep across multiple Internet addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Digging deeper, Qurium discovered gmslb[.]net was referenced in dozens of pirated or modded video content streaming apps, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams. Qurium’s report notes that most of the domains long used to control the Popa botnet were seized or dismantled in July 2025, after Google, HUMAN Security and Trend Micro teamed up to disrupt Badbox 2.0, a botnet that is closely associated with Vo1d. Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Ninjatech is a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. That resume credits Kramer for helping NetNut to build from the “ground up,” “designing the architecture,” and “scaling the NetNut” before the company was acquired by Alarum Technologies. A self-created listing at the job board F6S references Kramer as the sole owner of the Ninjatech domain (a screen capture of it is pictured below). Image: F6S.com.

Responding via email, Mr. Kramer said Ninjatech ceased operations approximately five years ago, when the company sold a software development kit (SDK) called Popa that was designed to use a small portion of a device’s bandwidth and to run only after the host application obtained user consent. “That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.” Kramer said neither he nor NetNut builds, operates or maintains the infrastructure being described as Popa, nor does he control the Ninjatech domain.

“I didn’t register the June 2025 domains you mention, and I don’t know who did,” he continued. “I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut.” But in a separate Popa research report released today, the proxy-tracking company Synthient said a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut. “The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote.

“This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.” Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com. Alarum Technologies, NetNut’s Tel Aviv-based parent company, said the reports by Synthient and Qurium contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” Alarum shared a statement saying they reject the basic characterization of the SDKs and technologies discussed in the reports as a “botnet.” “The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate,” the statement reads. “Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.” Alarum said NetNut places “significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity.” “This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut’s customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network,” their statement continued.

However, in a report released on June 8, the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful “know your customer” procedures before allowing customers to purchase proxy access. “An individual can This entry was posted on Thursday 18th of June 2026 01:37 PM Brian, I really enjoy your work. Thank you for your deep dives into this world so few know about nor care about. When I try and tell my friends and family about these things they fall into a self-induced coma.

So much to stay on top of and you help us do that. “That code was sold and licensed to third parties including resellers years ago,” Kramer said. “Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.” – They aren’t violating any of your licensing policies in the agreements by doing crap like this? You don’t have civil lawsuits in Israel?

Or is Moishe playing possum. “Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent” – Which is crazy considering they’d probably get it if they did, people are net nuts! > Experts say it’s questionable whether TV apps with proxy SDKs can obtain meaningful consent from users Some “Experts” those are; it’s actually not questionable *at all*. That consent usually does not lie with the user, but their ISP.

I don’t know of a single one that has an AUP that allows proxies. My ISP’s prohibitions lists: > Allowing others (not including members of your household) to use your US Internet account. This is entirely an enforcement problem. And the ISPs aren’t enforcing it because very few *other* ISPs are holding their feet to the fire over abusive traffic.

That’s why I will not hesitate for a second to drop even the largest organizations into my firewall when I see clearly “inhuman” traffic coming from their network space. > one of those control domains was not new: **ninjatech[.]io** Which, hilariously, appears to be protected by Cloudflare. And, yes, all of **CLOUD14** is already in my firewall. Thanks for asking!

You make an excellent point about ISP enforcement of their own policies. I can’t remember the last time I heard anyone get a letter “warning” them not to torrent.. A dramatic story that is silent on remediation steps for consumers. The story links to several very interesting and useful reports.They list the offending apps and components to look for by name.

I didn’t print the list because it’s very long. Qurium’s report: https://www.qurium.org/forensics/finding-popa/ Synthient: https://synthient.com/blog/popa-from-sourcing-to-distribution Spur: https://spur.us/blog/how-proxy-providers-co-opt-entire-networks Nokia Deepfield: https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md Include Security: https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ Infoblox: https://www.infoblox.com/blog/threat-intelligence/residential-proxies-in-the-wild/ how can I ensure that my LG – 48″ CLASS C4 SERIES OLED 4K UHD SMART WEBOS is not “bugged”? you can’t, buy a book or go to the library… Better, I asked AI: Settings → Support → Software Update → Check for Updates LG pushes security patches regularly. But that doesn’t necessarily ‘unbug’ it if you have (or a previous owner?

or a reseller/mfctr) installed N+1 of these myriad malicious programs at any point. It’s a good start in general to update but if rogue apps have _ever_ been installed it’s a leap to assume it secure even if it reports that updates installed successfully. ^1 Oy gevalt, another senseless and unprovoked attack on the great Jewish state of Israel. It’s another shoah!

That reply from “Suzie” bears scrutiny Brian. This is great reading and informative combo with the Darknet Diaries episode, “Superbox” https://darknetdiaries.com/episode/172/ Just a thought experiment: The year, 2027 — War has broken out between various major residential proxy providers, each vying for dominance in a crowded field of competitors. The top five providers are each using their vast proxy networks to attempt to DDoS their rivals into oblivion. Peace envoys have been dispatched from the ITU, hoping to broker a lasting cease-fire.

Comments are closed. Mailing List Search KrebsOnSecurity Recent Posts Story Categories Why So Many Top Hackers Hail from Russia