Unmasking Popa: How a Mass Smart TV Botnet Powered a Nasdaq-Listed Proxy Enterprise and the AI Scraping Boom

Executive Overview

For over four years, an expansive Android-based botnet known as Popa has silently co-opted millions of consumer television boxes, smart TVs, and mobile devices globally. Functioning not as a traditional destructive botnet armed for massive distributed denial-of-service (DDoS) attacks, Popa was engineered with a singular, lucrative objective: establishing a persistent, encrypted communication layer designed to route third-party internet traffic on demand. This infrastructure has turned home internet connections into high-value "residential proxies," fueling everything from ad fraud and account takeovers to the aggressive, non-stop data scraping required to train modern artificial intelligence models.

Multi-agency security investigations have linked the infrastructure controlling the Popa botnet directly to NetNut, a major residential proxy service owned by Alarum Technologies Ltd [NASDAQ: ALAR], a publicly traded Israeli cybersecurity firm.

While Alarum and NetNut leaders deny managing malware or operating compromised infrastructure, technical analyses from leading cybersecurity research firms—including Qurium, Synthient, Black Lotus Labs, Spur, and Nokia Deepfield—demonstrate a direct operational pipeline between Popa-infected consumer hardware and NetNut’s commercial proxy pool.

This exposure highlights a growing shadow economy where low-cost hardware, pirated streaming software, dark-pattern user consent, and corporate data-scraping demands intersect.


Detailed Chronology of the Popa Ecosystem

   +-----------------------------------------------------------------------------------+
   | 2022 - 2024: Emergence & Underground Growth                                        |
   | - Popa operates covertly as a modular plugin tied to the "Vo1d" malware family.   |
   | - Pre-installed on off-brand Android TV boxes and modded streaming APKs.           |
   +-----------------------------------------------------------------------------------+
                                             │
                                             ▼
   +-----------------------------------------------------------------------------------+
   | 2025: Threat Intel Discovery & Industry Takedowns                                 |
   | - Chinese firm XLAB (Qianxin) flags initial C2 domains controlling Vo1d/Popa.     |
   | - July 2025: Google, HUMAN Security & Trend Micro disrupt Badbox 2.0/Vo1d.        |
   | - Popa operators rapidly deploy new C2 domains; maintain fallback on ninjatech.io.|
   +-----------------------------------------------------------------------------------+
                                             │
                                             ▼
   +-----------------------------------------------------------------------------------+
   | May - June 2026: Definitive Linkage & Public Exposure                            |
   | - May 2026: Qurium investigates massive data-scraping across 1.4M IP addresses.   |
   | - Trace reveals C2 infrastructure hosted via ninjatech.io (owned by NetNut VP).  |
   | - Synthient captures live NetNut commercial client traffic routing through Popa.  |
   | - Spur & Infoblox publish data detailing widespread Smart TV and enterprise exposure.|
   +-----------------------------------------------------------------------------------+

2022–2024: Underground Emergence and Proliferation

The foundation of Popa was laid within the ecosystem of off-brand Android streaming devices sold across top e-commerce platforms under thousands of generic model names (such as the X96 Mini). Promising free access to premium subscription video content for a one-time hardware purchase fee, these devices frequently arrived from overseas manufacturers pre-loaded with malicious software.

Popa initially operated in the background as a stealth plugin component linked to Vo1d, a wider malware family targeting unofficial Android platforms. Concurrently, software development kits (SDKs) embedding the Popa code were integrated into dozens of modded or pirated media applications—such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams.

2025: Initial Attribution and Takedown Countermeasures

In 2025, cybersecurity firm XLAB (a division of Chinese security giant Qianxin) published research exposing the inner workings of Vo1d, documenting at least nine command-and-control (C2) domains utilized to register infected systems and open communication channels.

Recognizing the threat, a coalition formed by Google, HUMAN Security, and Trend Micro executed a coordinated disruption in July 2025 targeting Badbox 2.0, a primary botnet framework closely integrated with Vo1d. While the action successfully seized and neutralized scores of control domains, Popa’s operators quickly adapted. Within days of the disruption, dozens of replacement control domains were registered to restore command capabilities over the compromised endpoints.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

May–June 2026: The Scraping Surge and Corporate Exposure

In May 2026, threat researchers at digital rights organization Qurium observed a massive, highly distributed data-scraping attack hitting hosted non-governmental and media organizations. The traffic originated from over 1.4 million distinct residential IP addresses, distributed evenly to evade automated anti-scraping blocks.

Tracing the orchestration layer, Qurium identified a synchronized network of command domains driving the traffic, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io.

A critical breakthrough occurred when domain records revealed that ninjatech[.]io was registered directly to Moishi Kramer, Vice President of Research and Development at NetNut. Public professional profiles show Kramer designed and built NetNut’s architecture prior to its acquisition by Alarum Technologies.

On June 18, 2026, complementary reports released by Qurium, Synthient, and Nokia Deepfield publicly tied Popa’s underlying infrastructure directly to NetNut’s commercial proxy inventory.


Scale, Metrics, and Technical Architecture

Popa’s power lies not in raw destructive potential, but in its ability to maintain high-availability, long-lived, encrypted tunnels through consumer hardware without degrading home internet speeds enough to trigger user intervention.

Metric / Dimension Reported Data & Figures
Daily Active Footprint 1.5 Million to 2.5 Million unique residential IP addresses daily (Lumen Black Lotus Labs)
Relay Node Capacity ~359 known relay nodes; single node subsets handle 35,000–60,000 active concurrent clients (Nokia Deepfield)
24-Hour Unique Telemetry 750,000 unique IP sources recorded across just 26 relay nodes in a single day (Nokia Deepfield)
Control Domain Infrastructure 250 to 300 active internet addresses orchestrating traffic globally
Smart TV App Prevalence 42% of analyzed apps on LG webOS contain proxy SDKs; >25% on Samsung Tizen (Spur)
Enterprise Network Penetration 65% of monitored enterprise environments actively querying residential proxy domains (Infoblox)

Technical Architecture

Unlike typical malware that executes malicious payloads locally, Popa functions as an endpoint communication gateway:

[Target Web Server / AI Scraping Destination]
                       ▲
                       │ Clean Residential Traffic
[Compromised Android TV / Smart TV Node (Popa SDK)]
                       ▲
                       │ Encrypted Tunnel
       [Popa Relay & C2 Node Network]
                       ▲
                       │ Customer Requests
     [NetNut Commercial / Reseller Network]
                       ▲
                       │ Authentication & API Queries
          [End Buyer / Web Scraper]
  1. Persistence Layer: Once deployed via a modded app or pre-infected firmware, Popa registers the device’s network interfaces with remote C2 servers (gmslb[.]net, ninjatech[.]io).
  2. Tunneling Protocols: The client maintains persistent, low-overhead WebSocket or custom encrypted TLS connections to core relay nodes.
  3. Dynamic Routing: When a NetNut customer issues an HTTP/HTTPS request targeted at a web service, the request is directed through NetNut’s gateway, routed down to an active Popa relay node, and exit-routed through the consumer’s domestic connection.

Chris Formosa, senior lead information security engineer at Lumen Technologies’ Black Lotus Labs, highlights the amplified threat posed by this setup:

"What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing. So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

The Symbiosis: Residential Proxies and the AI Data-Scraping Boom

The rapid expansion of botnets like Popa is closely tied to the economics of generative artificial intelligence. Training competitive Large Language Models (LLMs) and powering real-time AI retrieval-augmented generation (RAG) agents requires continuous, large-scale extraction of web data.

The Anti-Scraping Wall and the Residential Solution

Major commercial websites, academic portals, and media platforms deploy advanced Bot Management Systems (BMS)—such as Cloudflare, DataDome, and HUMAN Security—to defend their infrastructure. These protection layers aggregate intelligence to instantly block or rate-limit request surges originating from traditional cloud data centers (e.g., AWS, Microsoft Azure, Google Cloud).

To bypass these defenses, scraping operators turn to residential proxy networks. When an automated scraping script routes traffic through a home TV streaming box connected via a residential Internet Service Provider (Comcast, AT&T, Vodafone), the target server sees an ordinary consumer visiting the site.

+-----------------------------------------------------------------------+
|                       THE AI SCRAPING DILEMMA                        |
|                                                                       |
|  [Data Center Scraping Bot] ───► [Bot Management Filter] ───► BLOCKED |
|                                                                       |
|  [AI Scraping Bot]                                                    |
|         │                                                             |
|         ▼                                                             |
|  [NetNut Proxy Pool]                                                  |
|         │                                                             |
|         ▼                                                             |
|  [Smart TV / Popa Node] ───► [Bot Management Filter] ───► ALLOWED |
+-----------------------------------------------------------------------+

Impact on Digital Infrastructure

This relentless search for training data has disrupted public internet infrastructure:

  • Academic Disruptions: Surveys conducted by the Confederation of Open Access Repositories (COAR) revealed that over 90% of open-access repositories experience aggressive scraping traffic weekly, leading to frequent service degradations and complete network outages.
  • Open Access Strains: Organizations like the Directory of Open Access Journals (DOAJ) report battling massive waves of unauthorized scraper bots that consume bandwidth intended for global researchers.
  • Copyright & Legal Exposure: With over 70 high-profile copyright infringement lawsuits pending against major AI vendors, proxy providers serve as an intermediary layer between AI developers and the scraped data sources.

Smart TVs, Dark Patterns, and Enterprise Risk

The reach of residential proxy SDKs extends beyond illegal Android boxes into mainstream consumer hardware and corporate network environments.

The Smart TV Consent Illusion

Research published by proxy tracking firm Spur reveals that users do not need to purchase an illicit streaming box to become an unconsenting node in a proxy network. Scanning official application stores for major Smart TV platforms, Spur found that 42% of apps in LG’s webOS store and more than 25% of apps in Samsung’s Tizen store incorporated background proxy SDKs.

These components are typically embedded in free utilities, basic games, or screensavers. Security experts point out that obtaining informed consent on a television is fundamentally broken:

  • Dark Patterns: Legal terms are hidden within lengthy privacy policies that are virtually impossible to read or navigate using a standard TV remote control.
  • Shared Device Dynamics: Any family member—including children downloading a free game—can click through setup prompts, effectively opting the entire home network into a commercial proxy network.
  • Asymmetric Monetization: Developers receive recurring revenue from proxy brokers for every active installation, while consumers bear the costs of network bandwidth consumption, potential IP blacklisting, and local security risks.
       TYPICAL SMART TV CONSENT FLOW
+------------------------------------------+
|  [ Install Free Game / Utility App ]     |
+------------------------------------------+
                     │
                     ▼
+------------------------------------------+
|  "Terms of Service" Displayed            |
|  - Navigated via D-Pad Remote            |
|  - Hidden clause: "Share Idle Bandwidth" |
+------------------------------------------+
                     │
                     ▼
+------------------------------------------+
|  [ Accept & Play ]                       |
+------------------------------------------+
                     │
                     ▼
+------------------------------------------+
| RESULT: TV operates as an always-on      |
| residential proxy node for third parties. |
+------------------------------------------+

Corporate Network Spillover

The proliferation of residential proxy SDKs also poses challenges for corporate IT and cybersecurity teams through Bring-Your-Own-Device (BYOD) policies and remote-work environments.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

In an analysis of enterprise DNS queries, security firm Infoblox discovered that 65% of its corporate client base regularly queried residential proxy domains, recording over 500 billion queries monthly—a 25% year-over-year increase. Crucially, over 90% of monitored pharmaceutical clients and 60% of government and financial institutions showed active residential proxy traffic originating from inside their perimeters.

Infoblox threat researchers Nick Sundvall and David Brunsdon warn of the severe incident-response risks involved:

"If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source. Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation."


Official Statements and Industry Pushback

The exposure of Popa’s infrastructure has sparked pushback between cybersecurity researchers, corporate operators, and executive leadership.

Moishi Kramer (VP of R&D, NetNut)

Addressing his ownership of the ninjatech[.]io domain identified as a Popa controller, Moishi Kramer stated via email that Ninjatech ceased active business operations approximately five years ago after selling an SDK named Popa designed for bandwidth sharing with user consent.

"That code was sold and licensed to third parties including resellers years ago. Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.

I didn’t register the June 2025 domains you mention, and I don’t know who did. I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut."

Alarum Technologies Ltd [NASDAQ: ALAR]

Alarum Technologies, NetNut’s parent company, issued a formal response rejecting the characterization of their underlying technology as a botnet, asserting that the research reports contained inaccurate deductions:

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate.

NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services… This method of operation is supported both by internal procedures and policies, including performing KYC [Know Your Customer] checks and additional due diligence of NetNut’s customers."

Synthient Counter-Analysis

Addressing claims that Popa relies on user consent and operates independently of NetNut, research firm Synthient published direct network packet captures demonstrating outbound commercial traffic from NetNut client accounts passing through devices running Popa.

"The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients. This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.

Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent."

Spur Industry Assessment

Spur disputed NetNut’s claims regarding corporate Know Your Customer (KYC) enforcement, documenting how proxy capacity is re-sold down the supply chain:

"The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies. A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands… Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto."


Future Outlook

The unraveling of the Popa botnet marks a turning point in how threat intelligence teams, regulatory bodies, and hardware ecosystems approach residential proxy networks. As the line between commercial proxy providers and malware-driven botnets blurs, several regulatory and technical shifts are expected to take shape:

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

1. Increased Regulatory Scrutiny for Publicly Traded Proxy Vendors

With Alarum Technologies traded on the NASDAQ exchange, the explicit technical linking of its primary revenue engine to illicit SDKs and compromised consumer hardware creates regulatory and legal exposure. Financial regulators and compliance authorities are likely to inspect whether disclosures surrounding network sourcing and "bandwidth-sharing" practices accurately reflect the reality of unconsented consumer infection.

2. Platform Enforcement and App Store Policy Shifts

Hardware platform policies are beginning to diverge:

  • Strict Bans: Amazon and Roku have updated developer guidelines to explicitly ban third-party proxy SDKs, aggressively removing any application that attempts to monetize idle user bandwidth.
  • Lagging Ecosystems: LG (webOS) and Samsung (Tizen) face mounting pressure from security researchers to follow suit, audit their application stores, and ban silent proxy monetization modules.

3. Escalating Enterprise Defense

As network defenders recognize that residential proxy SDKs effectively open backdoor traffic tunnels inside corporate networks, enterprises are expected to adopt stricter Mobile Device Management (MDM) policies, restrict personal TV and streaming devices on corporate Wi-Fi segments, and block DNS queries resolving to known proxy infrastructure.

Summary

The Popa ecosystem demonstrates how modern cybercrime, commercial proxy services, and AI data gathering have interconnected. As long as the market demand for residential bandwidth remains high, consumer devices—from off-brand Android streaming boxes to brand-name Smart TVs—will remain primary targets for stealthy, high-volume monetization schemes.

Leave a Reply

Your email address will not be published. Required fields are marked *