Over the last four years, the Popa botnet has exploited millions of Android TV boxes, redirecting their internet traffic for purposes such as advertising fraud and data scraping. Recent investigations by cybersecurity experts have revealed a connection between Popa and NetNut, a residential proxy service owned by Alarum Technologies Ltd, a publicly traded Israeli company. Unlike conventional botnets that engage in destructive activities, Popa focuses on establishing a persistent communication layer, enabling long-term encrypted connections and on-demand communication tunnels. Experts associate Popa with the Vo1d botnet, which targets unofficial Android TV boxes that often come pre-installed with software that turns them into residential proxies. This allows malicious users to route their internet traffic through these devices, potentially compromising the owner's local network. Initial insights into Popa's origins emerged from a 2025 report by XLAB, which identified several domains linked to compromised devices. A recent report from Qurium highlighted the discovery of these domains during an investigation into data scraping incidents. Despite claims from Alarum Technologies that their SDKs do not create malware-controlled systems, concerns persist about the lack of stringent verification processes for proxy access, as noted by other research firms.
Popa Botnet Tied to Israeli Company
The Popa botnet, an extensive Android-based network, has been linked to the Israeli firm Alarum Technologies, raising concerns over its role in online fraud.
