Over the past four years, the Popa botnet has commandeered millions of consumer television boxes to funnel Internet traffic for purposes including advertising fraud, credential theft, and large-scale data harvesting. This week, security researchers across multiple firms determined that Popa connects to NetNut, a residential proxy service managed by the publicly-traded Israeli corporation Alarum Technologies Ltd [NASDAQ: ALAR].

Unlike conventional botnets that orchestrate destructive operations such as distributed denial-of-service campaigns, Popa operates with a narrower objective: establishing a persistent communications infrastructure capable of device registration, sustaining encrypted sessions, and initiating tunnels on demand.

Researchers characterize Popa as a plugin module tied to the Vo1d botnet, a widespread malware initiative concentrating on non-official Android television boxes. These devices, sold under countless brand names and model numbers across major e-commerce platforms, promise access to hundreds of subscription video services for a single upfront payment.

As the FBI and security professionals have cautioned, these streaming devices frequently include or arrive with software that converts the television into a residential proxy—enabling anyone to route their Internet activity through that device as long as it remains powered and networked. Adding to the concern, certain proxy networks lack safeguards preventing malicious users from reaching and potentially compromising systems on the device owner's local network.

Initial leads regarding Popa emerged from a 2025 report by Chinese security firm XLAB, which identified at least nine domain names managing compromised device registration and control. Qurium, a security organization, released findings today detailing how it uncovered several of these same domains while examining costly data scraping incidents targeting its hosted clients in May 2026, with scraping dispersed across more than 1.4 million IP addresses.

Qurium discovered multiple dozen Popa control domains hosted across various Internet addresses in coordinated fashion over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Investigation revealed gmslb[.]net appearing in numerous unauthorized or modified video streaming applications, among them CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob and HD/OceanStreams.

According to Qurium's analysis, most Popa control domains were seized or shut down in July 2025 following a coordinated effort by Google, HUMAN Security and Trend Micro to dismantle Badbox 2.0, a botnet closely linked to Vo1d. Following that action, Qurium noted that numerous replacement domains were registered for Popa command and control, though one control domain was not newly created: ninjatech[.]io.

Ninjatech was established by Moishi Kramer, whose LinkedIn profile identifies him as vice president of research and development at NetNut. His professional history credits him with building NetNut from inception, designing its architecture, and scaling operations before Alarum Technologies acquired the firm. A self-posted profile on the job board F6S lists Kramer as the exclusive owner of the Ninjatech domain.

Image: F6S.com.

In an email response, Kramer stated that Ninjatech halted operations roughly five years ago upon selling an SDK named Popa, engineered to consume minimal device bandwidth and activate only after the user application received explicit user authorization.

That code was sold and licensed to third parties including resellers years ago. Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.

Moishi Kramer

Kramer asserted that neither he nor NetNut develops, runs or sustains the infrastructure identified as Popa, and that he does not govern the Ninjatech domain.

I didn't register the June 2025 domains you mention, and I don't know who did. I have no control over, or visibility into, that infrastructure. I can only tell you it isn't operated by me or by NetNut.

Moishi Kramer

However, Synthient, a proxy-tracking organization, released a separate Popa analysis today indicating that examination of the Popa SDK uncovered outbound communications plainly tied to NetNut.

The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients. This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.

Synthient

Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies, NetNut's Tel Aviv headquarters, responded that the Synthient and Qurium reports contained "demonstrably inaccurate assertions and flawed deductions rather than verified facts." The company rejected characterizing the SDKs and technologies discussed as a botnet.

The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate. Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services.

Alarum Technologies

Alarum emphasized that NetNut prioritizes notification and consent mechanisms, performs customer verification, monitors for misuse, and implements detection and mitigation procedures for suspicious activity.

This method of operation is supported both by internal procedures and policies, including performing KYC checks and additional due diligence of NetNut's customers, as well as employing various technological measures, designed to assist in identifying and addressing suspected misuse of the network.

Alarum Technologies

Yet on June 8, proxy tracking service Spur released a report asserting that NetNut does not mandate corporate verification or rigorous know-your-customer procedures before granting proxy access.

An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in. The 'verified corporations only' claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.

Spur

Spur further noted that NetNut is not the sole entry point, as numerous downstream resellers and white-label operators repackage the same ISP proxy pool under different brands, typically conducting minimal or no customer verification.

A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto.

Spur

Synthient observed that while recent Popa builds from three months ago introduced user consent requests before proxy installation, not all variants or earlier versions include this capability.

Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent.

Synthient

THE PREVALENCE OF POPA

Chris Formosa, senior lead information security engineer at Black Lotus Labs (part of Internet backbone operator Lumen Technologies), emphasized what makes Popa particularly dangerous.

What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing. So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.

Chris Formosa

According to Formosa, Popa operates with an average of 1.5 million to 2.5 million distinct IP addresses daily, utilizing between 250 and 300 Internet addresses for directing its operations.

That's why Popa is so dangerous. It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified.

Chris Formosa

While Popa ranks among larger botnets currently active, its scale falls short of IPIDEA, a China-based proxy provider that previously managed a daily pool of nearly 10 million devices for resale. In January 2026, Synthient published research demonstrating that multiple emerging large DDoS botnets had expanded rapidly by tunneling through IPIDEA proxies into unsuspecting TV box owners' local networks and compromising other Android devices behind their firewalls.

IPIDEA's foundation rests on SDKs enabling access to pirated streaming content across numerous TV box devices, though its device count has declined since January when Google and partners pursued legal action to seize IPIDEA's control domains.

Jérôme Meyer, security researcher at Nokia Deepfield, suggested the actual Popa device population may substantially exceed Lumen's calculations. Meyer indicated that Nokia monitors 26 of at least 359 identified relay nodes, with estimates suggesting each relay node manages between 35,000 and 60,000 simultaneous clients.

On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours.

Jérôme Meyer

Nokia Deepfield released its own report today examining RoboVPN, a VPN application connected to the Vo1d botnet's Popa plugin that Qurium attributes to NetNut/Alarum Technologies.

THE SYMBIOSIS OF PROXIES AND DATA SCRAPING

Major proxy providers have increasingly rebranded their services to emphasize utility for artificial intelligence training, suggesting this represents a primary application for residential proxies. This reflects the reality that AI platforms depend on continuous mass-harvesting of Internet material—text, images, video—for training large language models.

NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search. But the modern web isn't scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber's connection arrives at the target site from an IP that belongs to a paying residential customer.

Include Security

The relentless content harvesting has triggered more than 70 copyright infringement lawsuits against major technology firms that have publicly acknowledged large-scale data scraping as central to their commercial AI systems. Paradoxically, much of this harvesting benefits from proxy services intimately connected to unofficial Android television boxes and associated SDKs designed for distributing pirated content.

The scraping has intensified to the point where targeted websites frequently become unreachable for legitimate users. Nonprofit institutions, libraries and academic centers have reported persistent struggles maintaining service availability against relentless scraping operations concealed behind residential proxy networks.

A prior-year survey by the Confederation of Open Access Repositories (COAR) determined that while certain scraping bots operate benignly, "others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures." Over 90 percent of respondents reported their repository encounters aggressive bots, frequently multiple times weekly, often producing slowdowns and outages.

Automated web scraping is nothing new, and has been the key technology underlying search engines such as Google for over 30 years. However, the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.

Brendan O'Connell, Directory of Open Access Journals

DON'T TOUCH THAT DIAL!

Throughout the United States, local communities are resisting the expansion of data centers primarily designed to enhance artificial intelligence capabilities. Yet security professionals note that the broader public remains unaware that purchasing one of these unofficial Android television boxes means their television almost certainly consumes substantial monthly bandwidth assisting in AI model training.

Even households without these questionable boxes risk having their smart televisions converted into residential proxy nodes simply by downloading one of thousands of applications available on Samsung and LG smart television platforms. Spur recently examined the LG and Samsung app stores, discovering each offered approximately 3,000 downloadable applications, many being simple games or utilities that disclose in their terms that the user's Internet connection will facilitate data transfer with opt-out availability.

Spur determined that over 42 percent of applications available through LG's webOS operating system incorporate SDKs transforming televisions into always-active residential proxy nodes. More than one quarter of Samsung Tizen applications contained comparable residential proxy functionality.

Image: Spur.us.

Security experts question whether television applications with proxy SDKs can obtain genuine user authorization for establishing always-on proxy connections, particularly when any household member—including minors—can effectively enroll the family television into a residential proxy network by installing a basic game or utility.

Privacy-policy disclosure is the wrong control surface for a TV. It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn't convey that a paying customer is about to route their scraping traffic through the user's home internet.

Include Security

Sean Simmons, Spur's research director, told KrebsOnSecurity that most individuals lack a clear understanding of what selling residential IP address access entails, regardless of device type.

And on a TV, the gap is even wider. A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted.

Sean Simmons

Simmons suggested that LG and Samsung should adopt policies already implemented by other television platforms that have restricted residential proxy providers, referencing Amazon's prohibition on applications facilitating proxy services for external parties. Similarly, streaming device manufacturer Roku has reportedly begun blocking developers from utilizing proxy SDKs and has eliminated applications bundling them.

Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

Applications converting devices into residential proxy nodes extend beyond smart televisions and unbranded streaming equipment. As security firm Infoblox has noted, mobile application creators can integrate SDKs from residential proxy networks into their products for monetization, earning modest amounts per installation.

Consequently, devices frequently become enrolled without owner awareness, typically through complimentary applications including VPNs, streaming services, screensavers and productivity tools such as PDF applications and break notification software.

Frequently, these proxy services transmit data from employee devices brought into corporate environments, Infoblox discovered. In a recent blog post, Infoblox reported discovering that 65 percent of its customer base was querying one or more residential proxy-related domains.

We saw steady growth in these queries in 2025, with a 25% increase over the year to over 500 billion per month. Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators. Perhaps even more concerning is that over 60% of government and banking customers have as well.

Infoblox

Infoblox researchers Nick Sundvall and David Brunsdon cautioned that residential proxies operating in corporate settings grant external parties access to organizational IP space.

If threat actors were to abuse the residential proxy to attack a third party, the third party's incident response would, correctly, identify your residential proxy as the source. Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation. The stunning prevalence of these services within customer environments warrants attention from both network defenders and policy makers who should consider how the risks posed by residential proxies could be impacting their security posture.

Nick Sundvall and David Brunsdon, Infoblox

Source: Krebs on Security