For the past four years, a sprawling, shadow-like infrastructure known as "Popa" has quietly commandeered millions of consumer streaming devices. These Android-based TV boxes, often purchased as inexpensive, "all-access" portals to subscription video services, are silently relaying global internet traffic. This hijacked bandwidth is being funneled into the world of residential proxy networks, fueling a massive ecosystem of advertising fraud, account takeovers, and high-intensity data scraping.
This week, a coalition of cybersecurity researchers has formally linked the Popa botnet to NetNut, a residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. The discovery sheds light on a dark side of the modern "AI-scraping economy," where the device sitting in your living room may be serving as a hidden node for anonymous, and often malicious, internet traffic.
The Anatomy of a Silent Botnet
Unlike traditional botnets—such as those designed to coordinate distributed denial-of-service (DDoS) attacks to crash websites—Popa operates with a different, more persistent mandate. It is not designed for destruction, but for "utility."
Security experts define Popa as a plugin component associated with the Vo1d botnet, a large-scale malware campaign specifically targeting unofficial Android-based TV boxes. These devices are ubiquitous on global e-commerce platforms, marketed under thousands of disparate brand names. They promise the allure of free, one-time-fee access to premium content, but the "price" is the covert installation of a software development kit (SDK) that transforms the device into an always-on residential proxy.

Once active, the device opens a tunnel that allows third parties to route their internet traffic through the user’s home network. Because this traffic originates from a residential IP address, it is frequently treated as "trusted" by websites, allowing bad actors to bypass anti-scraping measures, commit fraud, or infiltrate local home networks under the radar.
Chronology of Discovery: From XLAB to Qurium
The trail of breadcrumbs leading to Popa began in 2025, when the Chinese security firm XLAB identified at least nine domain names used to register and command compromised devices. However, the true scale of the operation was revealed in a comprehensive report released this week by the security firm Qurium.
Qurium researchers stumbled upon these control domains while investigating a series of aggressive and costly data-scraping events in May 2026. Their investigation revealed that scraping activity was being distributed with surgical precision across more than 1.4 million unique internet addresses.
Qurium identified dozens of domains controlling the Popa botnet, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. The investigation found that gmslb[.]net was deeply embedded in dozens of pirated or modded video streaming applications, including popular apps like DooFlix, Sprozfy, RTS Tv, and Flixoid.

While many of these domains were dismantled in July 2025 during a coordinated effort by Google, HUMAN Security, and Trend Micro to disrupt the "Badbox 2.0" botnet, the infrastructure proved resilient. New domains were registered almost immediately, including the notable ninjatech[.]io.
The "Ninjatech" Connection and Corporate Denials
The inclusion of ninjatech[.]io in the control infrastructure provides a direct link to industry insiders. Moishi Kramer, the founder of Ninjatech, is currently listed as the Vice President of Research and Development at NetNut. His LinkedIn profile credits him with designing the architecture and scaling NetNut from the ground up prior to its acquisition by Alarum Technologies.
In an email exchange, Mr. Kramer denied current involvement. He asserted that Ninjatech ceased operations five years ago when it sold a software development kit (SDK) called Popa. "That code was sold and licensed to third parties including resellers years ago," Kramer stated. "Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it."
However, this defense is countered by the findings of the proxy-tracking firm Synthient. Their latest analysis of the Popa SDK revealed outbound traffic patterns that correlate precisely with NetNut’s network. "The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients," Synthient concluded. "This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool."

Alarum Technologies, the parent company of NetNut, has rejected these findings as "demonstrably inaccurate." In an official statement, the company argued that its SDKs are designed for "bandwidth-sharing functionality" rather than malware. "NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use," the firm stated.
The Prevalence and Power of the Proxy Pool
The danger of Popa lies in its ubiquity. Chris Formosa, a senior lead information security engineer at Black Lotus Labs (a division of Lumen Technologies), notes that because NetNut is so widely used by other proxy resellers, Popa-infected IPs appear across a vast array of services.
"It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified," Formosa said. Estimates suggest the Popa botnet averages between 1.5 million and 2.5 million distinct IP addresses daily. Jérôme Meyer, a researcher at Nokia Deepfield, suggests the numbers may be even higher, estimating that specific relay nodes handle tens of thousands of clients simultaneously.
The infrastructure is so vast that it has become a cornerstone of the "AI-scraping economy." As AI companies race to train Large Language Models (LLMs), they require massive amounts of web-scraped data. Because major platforms like Cloudflare and DataDome block known data-center IPs, these companies rely on residential proxies to make their scraping attempts look like legitimate human traffic.

Implications: The Death of Privacy and Network Integrity
The implications of this botnet extend far beyond the living room. Security firm Infoblox recently reported that 65% of its customer base—including pharmaceutical, food and beverage, and even government and banking institutions—was querying residential proxy-related domains.
When these proxy-enabled devices enter the workplace, they create a significant security liability. If a threat actor uses an employee’s residential-proxy-enabled device to attack a third party, the incident response from the target will point directly back to the company’s own IP space.
"Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation," warn Infoblox researchers Nick Sundvall and David Brunsdon.
Furthermore, the rise of these SDKs is not limited to cheap TV boxes. An investigation by the security firm Spur revealed that approximately 42% of apps in the LG webOS store and over 25% of apps in Samsung’s Tizen store contain residential proxy components. Often, this is buried in "fine print" that the average consumer is unlikely to read or understand.

"A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted," says Sean Simmons, head of research at Spur.
A Call for Regulatory and Platform Action
As the industry grapples with this realization, there is a growing consensus that "consent" in this context is a failed model. Whether it is a child playing a game on a smart TV or an employee using a PDF viewer on a work laptop, the current system allows for the wholesale hijacking of bandwidth under the guise of "user agreement."
While platforms like Amazon and Roku have taken steps to ban apps that facilitate third-party proxy services, others remain permissive. Security experts are calling on manufacturers to implement more transparent controls and for regulators to scrutinize the business models of companies that build their profit margins on the silent, unconsented monetization of consumer internet connections.
For now, the advice to consumers remains simple but difficult to execute: audit your smart devices, delete unnecessary apps, and be wary of any hardware that promises "free" access to premium content. In the era of the AI-scraping economy, your home bandwidth is a valuable commodity—and there are many who are more than willing to take it for free.
