For the past four years, a vast Android-based botnet known as Popa has been weaponizing millions of consumer TV boxes to facilitate advertising fraud, account takeovers, and extensive data-scraping operations. Recent investigations by multiple cybersecurity firms have conclusively linked the Popa botnet to NetNut, a residential proxy provider operated by the publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR).

Popa distinguishes itself from conventional botnets, which are typically used for disruptive activities like distributed denial-of-service (DDoS) attacks. Instead, its primary function is to establish a persistent communication layer, enabling compromised devices to register, maintain encrypted connections, and open communication tunnels on demand. Security experts identify Popa as a plugin component of the Vo1d botnet, a large-scale malware campaign that specifically targets unofficial Android-based TV boxes. These devices, widely available on major e-commerce platforms and marketed under countless brand names, promise access to numerous subscription video services for a one-time fee. However, as consistently warned by the FBI and cybersecurity professionals, these streaming boxes often come pre-installed with software that transforms the user’s TV into a "residential proxy." This allows third parties to route their internet traffic through the compromised device, as long as it remains connected to power and a network. Alarmingly, some of these proxy networks do little to prevent malicious users from interacting with or even compromising systems on the victim’s local network.

Initial insights into Popa’s origins emerged in a 2025 report by Chinese security firm XLAB, which identified at least nine domain names used for registering and controlling compromised devices. Today, security firm Qurium published a report detailing how it encountered some of these same domains while investigating disruptive and costly data-scraping incidents targeting its hosted organizations in May 2026. The scraping activity was notably distributed across more than 1.4 million IP addresses. Qurium discovered several dozen domains used to control Popa, all consistently hosted across multiple IP addresses over time, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Further investigation by Qurium revealed that gmslb[.]net was referenced in numerous pirated or modified video streaming applications such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Qurium’s report also highlights that many of the domains long used to control the Popa botnet were seized or dismantled in July 2025. This action followed a collaborative effort by Google, HUMAN Security, and Trend Micro to disrupt Badbox 2.0, a botnet closely associated with Vo1d. Immediately after this disruption, dozens of new domains were registered to manage the Popa botnet. Notably, one of these new control domains, ninjatech[.]io, was not new. Ninjatech was founded by Moishi Kramer, whose LinkedIn profile indicates he is the vice president of research and development at NetNut. Kramer’s resume credits him with significant contributions to NetNut’s development, including designing its architecture and scaling its operations prior to its acquisition by Alarum Technologies. A self-created listing on the job board F6S identifies Kramer as the sole owner of the Ninjatech domain.

In an email response, Kramer stated that Ninjatech ceased operations approximately five years ago, having sold a software development kit (SDK) named Popa. He explained that this SDK was designed to utilize a small portion of a device’s bandwidth and only run after the host application obtained user consent. "That code was sold and licensed to third parties including resellers years ago," Kramer said. "Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it." Kramer asserted that neither he nor NetNut builds, operates, or maintains the infrastructure associated with Popa, nor does he control the Ninjatech domain. "I didn’t register the June 2025 domains you mention, and I don’t know who did," he continued. "I have no control over, or visibility into, that infrastructure. I can only tell you it isn’t operated by me or by NetNut."

However, in a separate Popa research report released today, proxy-tracking company Synthient stated that a recent analysis of the Popa SDK revealed outbound traffic directly associated with NetNut. "The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients," Synthient wrote. "This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool."

Alarum Technologies, NetNut’s parent company based in Tel Aviv, dismissed the reports from Synthient and Qurium as containing "demonstrably inaccurate assertions and flawed deductions rather than verified facts." Alarum issued a statement rejecting the characterization of the SDKs and technologies as a "botnet." The statement read, "The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate. Netnut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services." Alarum further claimed that NetNut emphasizes "appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity." They also detailed internal procedures, KYC checks, and technological measures to identify and address suspected misuse.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Contradicting these claims, a report released on June 8 by the proxy tracking service Spur asserted that NetNut does not require corporate verification or meaningful "know your customer" (KYC) procedures before allowing customers to purchase proxy access. "An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in," Spur wrote. "The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies." Spur added, "Nor is NetNut the only front door. A number of downstream white labelers and resellers repackage the same ISP proxy pool under their own brands. These outlets typically perform no KYC at all, less scrutiny than NetNut itself, who at the very least might assign an account manager to potential users. Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto."

Synthient’s analysis found that while more recent builds of the Popa SDK (as of three months ago) include the ability to request user consent before installing proxy components, not all variants or older versions possess this functionality. "Of the over 20 genuine Popa publishers analyzed, none of them were observed asking for user consent," Synthient reported.

The Prevalance of Popa

Chris Formosa, senior lead information security engineer for Black Lotus Labs at Lumen Technologies, emphasized the danger posed by Popa’s widespread use for reselling and sharing. "What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing," Formosa explained, noting that many other proxy services resell NetNut proxies rather than developing their own extensive networks. "So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently." Formosa stated that the Popa botnet averages between 1.5 million to 2.5 million distinct IP addresses daily, utilizing between 250 and 300 IP addresses for its command and control infrastructure. "That’s why Popa is so dangerous," Formosa concluded. "It may not be the largest botnet we have seen, but it is spread all over the industry, making its power very amplified."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

While Popa is considered one of the larger botnets, its numbers are dwarfed by those previously operated by IPIDEA, a China-based proxy provider that until recently maintained a daily pool of nearly 10 million devices resold as proxies. In January 2026, Synthient published research detailing how multiple large DDoS botnets had rapidly grown by tunneling through IPIDEA proxies into the local networks of unsuspecting TV box owners, infecting other Android-based devices behind user firewalls. IPIDEA largely relied on SDKs used for viewing pirated streaming content on numerous TV devices. However, its operations diminished after Google and industry partners took legal action in January 2026 to seize domains used by IPIDEA for device control and proxy traffic.

Jérôme Meyer, a security researcher at Nokia Deepfield, suggested that the total number of devices participating in the Popa botnet could be significantly higher than Lumen’s estimates. Meyer informed KrebsOnSecurity that Nokia is monitoring 26 of at least 359 known relay nodes for the botnet, estimating that each relay node handles between 35,000 and 60,000 clients simultaneously. "On the relay node subset I am looking at (26 of them), 750,000 unique sources in 24 hours," Meyer stated. Nokia Deepfield also released a report on RoboVPN, a VPN app linked to the Vo1d botnet’s Popa plugin, which Qurium attributes to NetNut/Alarum Technologies.

The Symbiosis of Proxies and Data Scraping

Cybersecurity experts note that many prominent proxy providers have rebranded to emphasize their utility for AI training, positioning it as a primary use case for their residential proxies. This trend stems from AI services’ reliance on continuous, large-scale web scraping for text, images, and video content to train large language models (LLMs). "AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search," according to a report by Include Security. "But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This relentless content scraping has led to over 70 copyright infringement lawsuits against major tech companies that acknowledge large-scale data scraping as a significant source for training their AI models. Ironically, much of this scraping is facilitated by proxy services intimately linked to unofficial Android TV boxes and associated SDKs whose stated purpose is to stream pirated content. The intensity of this scraping activity often overwhelms targeted websites, making them inaccessible to legitimate users. Nonprofit organizations, libraries, and universities have reported constant struggles to maintain service availability against aggressive data-scraping firms operating behind residential proxy services. A survey by the Confederation of Open Access Repositories (COAR) found that while some scraping bots are benign, "others are sufficiently aggressive that they are increasingly causing service disruptions in repositories and other scholarly communications infrastructures." Over 90% of respondents reported encountering aggressive bots weekly, leading to slowdowns and outages. Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), noted that while automated web scraping is not new, the current investor-driven AI startup boom has resulted in thousands of well-funded companies developing and deploying their own scraping tools for AI model training.

Don’t Touch That Dial!

While communities in the United States are pushing back against new data centers supporting AI, the general public remains largely unaware that using unsanctioned Android TV boxes effectively turns their smart TVs into tools for training modern AI models, consuming significant bandwidth. Even households without these devices can have their smart TVs converted into residential proxy nodes by downloading apps from Samsung and LG smart TV app stores. Spur found that over 42% of apps available on LG’s webOS operating system and over a quarter of apps for Samsung’s Tizen operating system include SDKs that transform the television into an always-on residential proxy node.

Experts question the meaningfulness of consent obtained from TV app users for installing always-on proxy connections, especially when children can inadvertently opt the family TV into a residential proxy network by installing a simple game or app. "Privacy-policy disclosure is the wrong control surface for a TV," Include Security stated. "It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet." Sean Simmons, Spur’s head of research, noted that most people lack a clear understanding of what selling access to their residential IP address entails, and this disconnect is even wider on a TV. He highlighted that a one-time prompt on a TV can be easily missed during setup, allowing the app to continue monetizing the connection long after the user forgets their consent. Simmons urged LG and Samsung to follow the lead of platforms like Amazon, which prohibits apps facilitating third-party proxy services, and Roku, which reportedly bars proxy SDKs and has removed apps that bundled them.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Apps that convert devices into residential proxy nodes are not exclusive to smart TVs and generic streaming boxes. Infoblox reported that mobile app developers can embed SDKs from residential proxy networks into their products to monetize their software, receiving a small payment per installation. This often results in devices being enrolled without the owner’s knowledge, typically through free applications like VPNs, streaming apps, screensavers, and "productivity" apps. Infoblox discovered that a significant 65% of its customer base was querying one or more residential proxy-related domains, with a 25% increase in such queries in 2025, exceeding 500 billion per month. Notably, over 90% of pharmaceutical and food & beverage customers, and over 60% of government and banking customers, have queried residential proxy indicators. Infoblox researchers Nick Sundvall and David Brunsdon warned that the presence of residential proxies in corporate environments grants external access to an organization’s IP space. They cautioned that if threat actors abuse residential proxies to attack third parties, the incident response would correctly identify the organization’s residential proxy as the source, leading to significant time expenditure, legal exposure, and reputational damage. The widespread prevalence of these services within customer environments, they concluded, warrants attention from network defenders and policymakers regarding their impact on security posture.