5 min read

Popa botnet tied to Israeli proxy firm NetNut

Security researchers say the Popa botnet behind millions of Android TV boxes is linked to NetNut, owned by Alarum Technologies.

Image: Krebs on Security

For four years, an Android-based botnet called Popa has quietly turned millions of consumer TV boxes into relay points for internet traffic tied to ad fraud, account takeovers, and mass data scraping, according to KrebsOnSecurity and multiple security firms. This week, researchers from Qurium and Synthient said the operation is linked to NetNut, a residential proxy provider owned by the publicly traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR).

Unlike a classic botnet built for DDoS attacks, Popa appears designed to maintain persistent encrypted connections and open communication tunnels on demand. Researchers say it functions as a plugin tied to the Vo1d botnet, which targets unofficial Android TV boxes sold under countless brand names and widely marketed as one-time-payment alternatives to subscription streaming services.

Those devices have long drawn warnings from the FBI and security researchers because they often include software that turns the owner’s connection into a residential proxy. That lets outside customers route traffic through the device as long as it stays plugged in and online. Researchers say some proxy networks also fail to stop customers from probing or compromising systems on the same local network.

The first public clues surfaced in a 2025 report from Chinese security company XLAB, which identified at least nine domains used to register and manage infected devices. In a report released this week, Qurium said it encountered some of the same infrastructure while investigating disruptive scraping attacks in May 2026 that were spread across more than 1.4 million internet addresses.

Qurium said domains used to control Popa included gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. It also found gmslb[.]net referenced in pirated or modified streaming apps including CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams.

Recommended reading

Hugging Face hit by AI agents, then blocked by LLM guardrails

After Google, HUMAN Security, and Trend Micro disrupted Badbox 2.0 in July 2025, most long-used Popa control domains were seized or dismantled, Qurium said. New control domains quickly appeared, but one remained: ninjatech[.]io.

That domain points to Ninjatech, a company founded by Moishi Kramer, whose LinkedIn profile says he is vice president of research and development at NetNut. His profile says he helped build NetNut from the ground up before the company was acquired by Alarum. A self-created F6S listing identified Kramer as the sole owner of the Ninjatech domain.

Kramer told KrebsOnSecurity by email that Ninjatech stopped operating about five years ago after selling an SDK called Popa that used a small amount of device bandwidth and was supposed to run only after user consent.

“That code was sold and licensed to third parties including resellers years ago. Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it.”

Moishi Kramer

Kramer said neither he nor NetNut builds, operates, or maintains the infrastructure now described as Popa, and said he does not control the Ninjatech domain.

But Synthient, in a separate report released the same day, said recent analysis of the Popa SDK showed outbound traffic clearly associated with NetNut.

“The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients. This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Synthient

Alarum Technologies, NetNut’s parent company in Tel Aviv, rejected the reports, calling them full of “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” The company said the SDKs in question are designed for bandwidth sharing, not malware control, and said NetNut uses policies, due diligence, monitoring, and KYC checks to promote lawful use.

That claim is disputed by Spur, which said in a June 8 report that NetNut does not require meaningful corporate verification before selling proxy access. Spur said buyers can obtain access through resellers with little more than a burner email and $5 in crypto.

Synthient also said that while recent Popa builds from three months ago can ask for user consent before installing proxy components, older and other variants did not. Of more than 20 genuine Popa publishers it analyzed, the company said none asked users for consent.

How large Popa appears to be

Chris Formosa, senior lead information security engineer at Black Lotus Labs within Lumen Technologies, said Popa averages between 1.5 million and 2.5 million distinct IP addresses each day and uses 250 to 300 internet addresses to direct activity.

“What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing.”

Chris Formosa, Black Lotus Labs

He said that makes Popa especially hard to contain because many proxy providers simply resell NetNut access instead of building their own networks.

Jérôme Meyer of Nokia Deepfield told KrebsOnSecurity the real device count may be much higher. He said Nokia is monitoring 26 of at least 359 known relay nodes, with each relay handling roughly 35,000 to 60,000 clients at the same time. On the 26-node subset alone, he said Nokia observed 750,000 unique sources in 24 hours. Nokia Deepfield also released a report tying RoboVPN, a VPN app linked to the Vo1d botnet’s Popa plugin, to NetNut/Alarum Technologies.

The broader backdrop is the booming market for residential proxies used in mass scraping. Researchers say proxy providers increasingly market themselves as infrastructure for AI training, because major scraping campaigns are often blocked when they originate from cloud providers. Routing traffic through home internet connections helps those requests blend in.

That demand has contributed to a surge in aggressive scraping that can knock smaller sites offline, especially nonprofits, libraries, universities, and open-access repositories. A survey last year by the Confederation of Open Access Repositories found that more than 90 percent of respondents were dealing with aggressive bots, often more than once a week, frequently causing slowdowns and outages.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Krebs on Security

// Keep reading