# The Popa Botnet's Surprising Pedigree: How a Publicly-Traded Israeli Firm Became Entangled in Android TV Fraud
Researchers link four-year-old malware campaign targeting millions of TV boxes to NetNut, a legitimate proxy service owned by NASDAQ-listed Alarum Technologies — raising uncomfortable questions about the line between proxies and botnets.
For nearly half a decade, a sprawling Android botnet called Popa has operated in the shadows, silently commandeering millions of consumer TV boxes to relay fraudulent traffic, harvest user data, and facilitate account takeovers. This week, security researchers from multiple firms—including the Stockholm-based Qurium—have provided what may be the clearest evidence yet of Popa's origins: a direct operational link to NetNut, a legitimate-appearing residential proxy service owned by the publicly-traded Israeli firm Alarum Technologies Ltd. (NASDAQ: ALAR).
The revelation cuts to the heart of a long-standing debate in cybersecurity about the blurred line between convenience and exploitation—and raises uncomfortable questions about how legitimate infrastructure companies can become entangled in criminal-scale abuse operations.
## The Threat: An Invisible Proxy Network
Popa is not a traditional botnet in the destructive sense. Rather than enslaving devices for distributed denial-of-service attacks or ransomware deployment, Popa serves a narrower but equally pernicious purpose: It operates as a persistent communications layer that turns ordinary home devices into anonymous proxy nodes.
Here's how it works in practice:
The consequences are tangible and expensive. According to Qurium's research, Popa-based infrastructure was used to orchestrate massive data scraping operations in May 2026 that targeted hosted organizations—with malicious traffic scattered evenly across more than 1.4 million distinct internet addresses. This distribution makes blocking nearly impossible for defenders.
## Background: The Android TV Box Ecosystem
The story of Popa cannot be separated from the booming market for unofficial Android TV boxes—low-cost devices that promise access to hundreds of premium streaming services through a single one-time payment (typically $50–$150).
For years, law enforcement agencies including the FBI have warned consumers that these devices are nearly always bundled with software designed to monetize the user's internet connection. What consumers often don't realize is that purchasing one of these boxes effectively donates their home network bandwidth to a third party—indefinitely.
The devices themselves run modified versions of Android and rely on pirated or modded streaming applications—apps like CRICFy, DooFlix, Sprozfy, RTS TV, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams. These applications are not mere convenience wrappers around legitimate streaming services; they are distribution mechanisms for malware.
Popa is understood to be a plugin component of the Vo1d botnet, a large-scale malware campaign specifically targeting these unofficial TV box ecosystems. The scale is staggering: millions of devices, each contributing its residential IP address to a criminal proxy network.
## Technical Details: Following the Infrastructure
The first public awareness of Popa's operations came in a 2025 report from Chinese security firm XLAB, which identified at least nine command-and-control domain names. However, the breakthrough came when Qurium investigators were analyzing the massive data scraping incidents affecting their hosted organizations.
By tracing back the scraping traffic, Qurium identified several dozen control domains all hosted in coordinated fashion across multiple internet addresses:
| Domain | Status | Notes |
|--------|--------|-------|
| gmslb[.]net | Seized | Referenced in dozens of pirated streaming apps |
| safernetwork[.]io | Seized | Control infrastructure for Popa |
| tera-home[.]com | Seized | Coordinated hosting pattern |
| ninjatech[.]io | Active | Reregistered after disruption; key finding |
In July 2025, major security firms—Google, HUMAN Security, and Trend Micro—coordinated a disruption of the Badbox 2.0 botnet, a closely associated operation. This effort resulted in the seizure of most Popa control domains.
However, within weeks, a new set of control domains were registered to keep the botnet operational. Critically, one domain stood out: ninjatech[.]io.
## The Connection: NetNut and Alarum Technologies
The key finding emerged from basic OSINT investigation. Ninjatech was registered by Moishi Kramer, whose LinkedIn profile identifies him as Vice President of Research and Development at NetNut. According to his professional history, Kramer was instrumental in helping NetNut build its infrastructure "from the ground up," designing the architecture and scaling the proxy network before NetNut was acquired by Alarum Technologies.
A job board listing on F6S further corroborates this connection, identifying Kramer as the sole owner of the Ninjatech domain registration.
This creates a direct operational link:
1. Ninjatech domain used to control Popa botnet
2. Ninjatech owned by NetNut VP of R&D
3. NetNut operates the "legitimate" residential proxy service
4. NetNut acquired by NASDAQ-listed Alarum Technologies
The implications are significant. While Alarum Technologies maintains that its operations are lawful, the evidence suggests that core personnel involved in building NetNut's proxy infrastructure are simultaneously operating command-and-control infrastructure for a botnet used in advertising fraud, data scraping, and account takeovers.
## Implications: Residential Proxies and the Trust Problem
This incident exposes a structural vulnerability in the internet's residential proxy ecosystem. Legitimate use cases for residential proxies do exist—security researchers use them, market researchers employ them, and companies use them for geographic load testing. However, the market is dominated by operators who make no meaningful effort to prevent abuse.
For consumers: The threat is acute. Owners of infected TV boxes are unwitting participants in fraud schemes, data theft, and other criminal activity—while bearing no responsibility or awareness of this fact. Their home networks become staging grounds for attacks against their own services.
For enterprises: Organizations targeted by Popa-based scraping, credential stuffing, or account takeover attacks face an unprecedented challenge. Traditional IP-based blocking is ineffective when attackers can distribute malicious traffic across millions of legitimate home addresses. Defenders must shift toward behavioral analysis and anomaly detection.
For regulators and law enforcement: The case raises difficult questions about the accountability of infrastructure companies. When a publicly-traded firm's technology is demonstrably used at scale for botnet operations, what regulatory or legal responsibility applies?
## Recommendations
Organizations should take the following immediate steps:
---
## HackWire Analysis
The Popa-NetNut connection represents a troubling inflection point in how cybersecurity incidents are prosecuted—or aren't. Unlike most botnet stories, this one doesn't end with arrests or facility takedowns. Instead, it implicates a publicly-traded company whose executives may have deliberately built infrastructure designed for legitimate proxy use but simultaneously optimized for botnet deployment.
The smoking gun is the reuse of ninjatech[.]io after the July 2025 disruption. This wasn't a compromised domain accidentally hijacked by criminals. This was a deliberate operational continuity decision—a domain registered and controlled by NetNut's own R&D leadership, immediately redeployed to keep Popa operational. That sequence suggests knowledge and intent.
What makes this case distinctive is how it inverts the typical attacker-defender relationship. NetNut isn't a fly-by-night proxy shop operating out of Russia or Eastern Europe. It's a firm funded by venture capital, acquired by a NASDAQ-listed parent company, and embedded in the broader AdTech ecosystem. Its executives have LinkedIn profiles and job board listings. This isn't anonymity; it's legitimacy that creates plausible deniability.
The broader pattern we're seeing is that "residential proxy services" have become a legal wrapper for botnet infrastructure. The companies operating them can claim they're providing legitimate geographic diversity for e-commerce price checking or security testing. Simultaneously, they deploy the same infrastructure for fraud, data theft, and account takeovers—knowing that the distributed nature of residential IP addresses makes remediation nearly impossible for defenders.
Until regulators treat residential proxy companies with the same scrutiny applied to traditional ISPs or hosting providers—demanding abuse controls, requiring customer verification, and holding them liable for malicious use—these services will continue to enable large-scale criminal operations. The Popa case suggests that this accountability gap isn't an accident. It's a feature, not a bug.
— HackWire Editorial
---
## Related Coverage