The Silent Hijack: How Millions of Streaming Boxes Power a Global Proxy Botnet

For the past four years, a sprawling, sophisticated Android-based botnet known as "Popa" has quietly co-opted millions of consumer TV streaming boxes. These devices, often purchased as inexpensive, "no-name" alternatives to major brand-name media players, are being weaponized to relay massive volumes of internet traffic. While the botnet avoids the destructive, headline-grabbing tactics of traditional malware—such as massive Distributed Denial of Service (DDoS) attacks—its true purpose is far more insidious: it acts as a persistent, global communications layer for "residential proxy" services, enabling large-scale data scraping, advertising fraud, and clandestine account takeovers.

This week, a coalition of cybersecurity researchers from firms including Qurium, Synthient, and Black Lotus Labs published findings linking the Popa botnet directly to NetNut, a prominent residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR).

The Anatomy of the Popa Botnet

Unlike traditional botnets that seek to cripple infrastructure, Popa is designed for stealth and persistence. It functions as a specialized plugin component within the larger "Vo1d" malware campaign, which targets unofficial Android-based TV boxes. These devices, marketed under thousands of brand names and model numbers across global e-commerce platforms, are sold with the promise of "unlimited" access to subscription video content for a one-time fee.

However, the "price" for this access is often the total surrender of the device’s network integrity. Once connected to a local network, the Popa plugin registers the device, establishes long-lived encrypted connections, and opens communication tunnels on demand. This effectively turns the user’s home or office internet connection into a "residential proxy node." Because the traffic is routed through a legitimate residential IP address, it bypasses the security filters that websites use to block traffic from known data centers, effectively anonymizing the malicious actors using the service.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

A Chronology of Discovery and Disruption

The digital breadcrumbs leading to Popa began to surface in 2025. In a seminal report, Chinese security firm XLAB identified at least nine domain names responsible for registering and directing the activities of compromised Android TV boxes.

In May 2026, the security firm Qurium encountered these same domains while investigating a series of aggressive data-scraping events. The scraping activity was distributed across 1.4 million unique internet addresses, a scale that suggested a highly coordinated botnet. Qurium’s investigation uncovered dozens of control domains—including gmslb[.]net, safernetwork[.]io, and ninjatech[.]io—which were deeply embedded within popular pirated streaming apps like DooFlix, CyberFlix, and Rapid Streamz.

The landscape shifted in July 2025, when a coalition led by Google, HUMAN Security, and Trend Micro dismantled "Badbox 2.0," a botnet closely related to Vo1d. While many of the original control domains were seized, the botnet operators were remarkably resilient. Within days, dozens of new domains were registered, including the reuse of ninjatech[.]io.

Research now indicates that Ninjatech was founded by Moishi Kramer, who currently serves as the Vice President of R&D at NetNut. While Kramer claims Ninjatech ceased operations years ago after selling the Popa SDK, investigators at Synthient remain unconvinced. Their latest analysis confirms, with high confidence, that devices running the Popa SDK are actively forwarding traffic from NetNut clients.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Data-Driven Insights: The Scale of the Operation

The sheer magnitude of the Popa botnet is staggering. Chris Formosa, a senior lead information security engineer at Black Lotus Labs (a division of Lumen Technologies), notes that Popa averages between 1.5 million and 2.5 million distinct IP addresses every single day.

"It may not be the largest botnet we have ever seen, but its integration into the broader ecosystem is unparalleled," Formosa explains. "Because other proxy services often resell NetNut proxies, the Popa footprint is amplified, appearing across an array of different services globally."

Jérôme Meyer, a security researcher at Nokia Deepfield, suggests the numbers may be even higher. By monitoring a subset of only 26 relay nodes, Meyer observed over 750,000 unique sources in a 24-hour period. With at least 359 known relay nodes, the potential capacity for concurrent traffic routing is massive, with each node handling between 35,000 and 60,000 clients simultaneously.

Official Responses and Corporate Defenses

The allegations have triggered a sharp response from Alarum Technologies. In an official statement, the company rejected the "botnet" characterization, labeling the findings as "demonstrably inaccurate assertions and flawed deductions."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Alarum maintains that its SDKs are designed for legitimate bandwidth-sharing functionality and that the company enforces strict "Know Your Customer" (KYC) policies. "NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of our services," the company stated.

However, industry watchdogs are skeptical of these claims. The proxy-tracking firm Spur recently published a report alleging that NetNut’s "verified corporations only" claim is purely marketing. Spur’s research suggests that anyone with a burner email and a small amount of cryptocurrency can purchase access to the network, bypassing any meaningful due diligence. Furthermore, while newer versions of the Popa SDK theoretically include a consent prompt, researchers at Synthient found that none of the 20+ "genuine" Popa-enabled apps they analyzed actually displayed a consent dialog to the end user.

The AI Scraping Economy: A Symbiotic Relationship

The rise of the Popa botnet coincides with a massive explosion in the AI industry. Modern AI models require vast amounts of text, image, and video data for training. Because major platforms like Cloudflare and DataDome aggressively block traffic from known data centers, AI scrapers have turned to residential proxies to mimic human users.

This has created a "scraping-as-a-service" economy. Nonprofits, universities, and scholarly repositories report being overwhelmed by aggressive bot traffic, leading to service outages and increased operational costs. A survey by the Confederation of Open Access Repositories (COAR) found that 90% of respondents faced service disruptions from scraping bots at least once a week.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"The modern web isn’t scrapeable from a data center," notes a report by Include Security. "The workaround is residential proxies. A scraping job routed through a consumer’s home connection arrives at the target site from an IP that belongs to a paying, legitimate subscriber."

Implications for Corporate and Personal Security

The threat is not limited to cheap streaming boxes. Research from Infoblox indicates that proxy SDKs are being embedded into a wide variety of "productivity" apps, including PDF viewers, VPNs, and even screensavers, often finding their way into corporate environments on employee devices.

The implications for businesses are severe. When a residential proxy node is used to conduct a cyberattack or perform illegal scraping, the originating IP address is traced back to the owner’s network. If that network belongs to a corporation, the company may find itself facing legal inquiries, blacklisting, and severe reputational damage. Infoblox reports that 65% of its customers—including major pharmaceutical, banking, and government entities—have seen residential proxy-related traffic on their internal networks.

Protecting Your Network

For the average consumer, the "smart" home has become a major security vulnerability. Spur’s audit of the LG webOS and Samsung Tizen app stores revealed that a significant percentage of available apps—roughly 42% on LG and 25% on Samsung—contain residential proxy SDKs.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Security experts are calling for a fundamental shift in how hardware manufacturers handle app distribution. Companies like Amazon and Roku have already begun banning proxy-bundled apps from their platforms, a move that experts say should be the industry standard.

Until such policies are universal, the burden of defense falls on the user. Security professionals advise:

  • Audit your streaming devices: If you own a budget-tier Android TV box, consider factory resetting it or replacing it with a reputable brand.
  • Monitor outbound traffic: For corporate networks, implement traffic monitoring to detect beacons to known residential proxy domains.
  • Exercise extreme caution: Treat free "utility" or "streaming" apps on smart TVs with the same skepticism you would apply to an unknown email attachment.

As the AI industry continues to demand more data, the value of a residential IP address will only rise. Without stricter regulation of the proxy market and better oversight of the devices in our living rooms, the Popa botnet and its kin are likely to remain a permanent, silent fixture of the digital landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *