For the past four years, a sprawling, persistent Android-based botnet known as Popa has quietly commandeered millions of consumer streaming devices. These devices, ranging from obscure, unbranded TV boxes to popular smart televisions, have been turned into involuntary relays for global internet traffic. This traffic is not being used for traditional, destructive cyber-attacks like massive distributed denial-of-service (DDoS) campaigns, but rather for a more lucrative, commercialized purpose: large-scale data scraping, advertising fraud, and sophisticated account takeovers.
New research released this week by a coalition of security firms, including Qurium, Synthient, and Black Lotus Labs, has linked the Popa botnet directly to NetNut, a prominent “residential proxy” provider operated by the publicly traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. This revelation exposes the dark underbelly of the modern AI-driven internet, where residential IP addresses are treated as commodities to be traded, sold, and weaponized without the consent of the device owners.
The Mechanics of the Popa Botnet
Unlike the destructive malware of the past, Popa is designed for stealth and longevity. It functions as a plugin component associated with the broader Vo1d botnet, a campaign that specifically targets low-cost, unofficial Android TV boxes. These devices are sold by the thousands under various brand names on major global e-commerce platforms, marketed with the alluring promise of access to hundreds of subscription-based streaming services for a one-time fee.
However, the "free" access comes at a hidden cost. Once these devices are connected to a home network, they often function as residential proxies. This turns the user’s home internet connection into an exit node for third-party traffic. Because the traffic originates from a "residential" IP address rather than a datacenter, it can bypass the sophisticated bot-detection software used by websites to block automated scraping.
Security experts define Popa not as a conventional virus, but as a persistent communications layer. It is built to register a device, maintain long-lived encrypted tunnels, and open those tunnels on demand for anyone willing to pay for access to the residential proxy network.

Chronology of Discovery and Disruption
The existence of Popa was first brought to light in a 2025 report by the Chinese security firm XLAB, which identified at least nine domain names used to orchestrate the botnet. The investigation gained significant momentum in July 2025, when Google, HUMAN Security, and Trend Micro teamed up to dismantle Badbox 2.0, a botnet closely linked to Vo1d.
Following the seizure of those command-and-control (C2) domains, the operators of Popa did not fold. Instead, they rapidly registered dozens of new domains to maintain their grip on the compromised devices. Among these new domains was ninjatech[.]io.
Researchers at the security firm Qurium later discovered that ninjatech[.]io was not merely a random domain, but one with a direct link to the leadership of NetNut. The domain was founded by Moishi Kramer, who currently serves as the Vice President of Research and Development at NetNut. According to his professional profiles, Kramer was instrumental in designing the architecture of the NetNut proxy network from the ground up before the company was acquired by Alarum Technologies.
Despite these connections, the ecosystem remains elusive. When the control infrastructure is disrupted, the botnet simply migrates to new domains, often embedded within popular, pirated, or modified streaming applications like CRICFy, DooFlix, Sprozfy, and Flixoid.
Supporting Data: The Scale of the Infection
The sheer scale of the Popa botnet is staggering. Chris Formosa, a senior lead information security engineer at Black Lotus Labs, estimates that Popa manages between 1.5 million and 2.5 million distinct IP addresses every single day.

"What makes Popa particularly dangerous is the sheer ubiquity of NetNut as a reseller," Formosa explained. "Because other proxy services often rely on NetNut’s infrastructure rather than building their own, the Popa-infected IPs appear in thousands of different services across the web. This amplifies the power of the botnet, making it one of the most problematic proxy networks currently in operation."
Nokia Deepfield, another firm monitoring the network, suggests that these estimates may be conservative. Jérôme Meyer, a researcher at the firm, noted that even a small subset of 26 relay nodes was observed handling between 35,000 and 60,000 clients simultaneously, processing 750,000 unique source connections within a 24-hour window.
Official Responses and Denials
When confronted with these findings, representatives for the entities involved offered starkly different perspectives. Moishi Kramer, in an email response, stated that Ninjatech ceased operations five years ago when it sold a software development kit (SDK) known as Popa to third-party resellers.
"Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it," Kramer claimed, asserting that he has no visibility into, or control over, the current infrastructure being operated under the Popa name.
Alarum Technologies, the parent company of NetNut, issued a formal statement rejecting the characterization of their service as a "botnet." The company argued that the reports by Synthient and Qurium contain "demonstrably inaccurate assertions and flawed deductions."

"The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems," Alarum stated. They emphasized that NetNut maintains rigorous "Know Your Customer" (KYC) procedures and technological measures to ensure their services are used for lawful purposes.
However, the proxy-tracking service Spur challenges this narrative. In a June 2026 report, Spur alleged that NetNut’s "verified corporations only" policy is merely a marketing facade. "Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto," Spur reported, noting that downstream resellers perform virtually no due diligence on their customers.
The AI Scraping Economy: Why Your TV Matters
The core demand for residential proxies today is driven by the insatiable need for data to train Artificial Intelligence models. Major AI developers require massive datasets, including text, images, and videos. Since modern websites employ robust security measures—such as those provided by Cloudflare or DataDome—to block traffic from datacenters, AI companies have turned to residential proxies to make their scraping bots look like ordinary, local internet users.
This has led to a symbiotic relationship between proxy providers and the AI industry. As Include Security noted in their report this month, "The modern web isn’t scrapeable from a datacenter. The workaround is residential proxies."
This trend has profound implications for the health of the internet. Aggressive scraping is now causing service disruptions for universities, libraries, and nonprofit organizations, as their servers struggle to handle the deluge of automated traffic. The Confederation of Open Access Repositories (COAR) reported that over 90% of its surveyed members have experienced significant service slowdowns due to these persistent, aggressive bots.

A Growing Threat to the Enterprise
The threat is no longer confined to low-cost streaming boxes. Research from Infoblox indicates that residential proxy SDKs are being embedded into a wide array of mobile apps, including VPNs, PDF viewers, and productivity tools.
These apps are frequently brought into corporate environments on employee devices. Infoblox found that 65% of its customer base—including pharmaceutical, food and beverage, banking, and government entities—have queried residential proxy-related domains on their internal networks.
"If threat actors abuse the residential proxy to attack a third party, that third party’s incident response will correctly identify your corporate network as the source of the attack," warned Infoblox researchers Nick Sundvall and David Brunsdon. "Untangling that… costs time, creates legal exposure, and can damage your reputation."
Conclusion: The Need for Oversight
The Popa botnet is a symptom of a larger, systemic issue: the lack of transparency in how internet-connected devices monetize their bandwidth. While some major TV platforms like Roku and Amazon have taken steps to ban proxy-related SDKs, others like LG and Samsung are still navigating the challenge, with some estimates suggesting that nearly half of the apps in certain smart TV app stores contain components that can turn the television into an always-on proxy node.
For the average consumer, the "smart" nature of their devices has become a vulnerability. As the line between legitimate software monetization and botnet activity continues to blur, the burden of security falls heavily on the user—an unfair expectation given the complexity of modern device ecosystems. Until there is greater regulatory oversight of the residential proxy industry, millions of devices will continue to act as silent, involuntary participants in the scraping of the global web.
