The Invisible Botnet: How Millions of "Smart" Devices Are Powering a Global Proxy Economy

For the past four years, a sophisticated, sprawling Android-based botnet known as Popa has been operating in the shadows of the internet. By hijacking millions of consumer TV streaming boxes, this infrastructure has quietly transformed household devices into high-performance relays for advertising fraud, massive-scale data scraping, and surreptitious account takeovers.

This week, a coalition of cybersecurity researchers released findings linking Popa to NetNut, a residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. The investigation reveals a troubling symbiosis between the thriving market for "pirated" streaming hardware and the burgeoning, multi-billion-dollar AI industry, which relies on these residential IP addresses to bypass security filters and scrape the web at an unprecedented scale.


The Anatomy of the Popa Botnet

Unlike the botnets of the past—which were designed for destructive, high-visibility actions like distributed denial-of-service (DDoS) attacks—Popa is a model of quiet efficiency. It acts as a persistent communication layer, designed to register devices, maintain long-lived encrypted connections, and open communication tunnels on demand.

Popa is identified by security experts as a core plugin component of the Vo1d botnet, a large-scale malware campaign specifically targeting unofficial, "no-name" Android-based TV boxes. These devices are ubiquitous on major e-commerce platforms, marketed as low-cost alternatives to premium streaming hardware that promise "free access" to thousands of subscription-based channels.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

The reality, however, is that these devices serve as Trojan horses. They come pre-installed with software that turns the user’s TV into a "residential proxy." Once connected to a wall socket and a local network, these devices allow third parties to route internet traffic through the user’s home IP address, effectively masking the true origin of the traffic.


Chronology of Discovery: From Fraud to Attribution

The trail leading to the discovery of Popa began in 2025, when the Chinese security firm XLAB first flagged nine domains associated with malicious activity on Android TV boxes. However, the connection to the broader proxy ecosystem was solidified in May 2026, when the security firm Qurium investigated a series of massive data-scraping events that targeted its hosted clients.

Qurium discovered that this scraping traffic was distributed with surgical precision across more than 1.4 million unique internet addresses. By tracing the control domains—including gmslb.net, safernetwork.io, and ninjatech.io—researchers found that these domains were hard-coded into dozens of popular, modded streaming apps like DooFlix, CyberFlix, and Rapid Streamz.

The turning point occurred in July 2025, when a coalition including Google, HUMAN Security, and Trend Micro dismantled Badbox 2.0, a botnet closely linked to Vo1d. While many of the associated control domains were seized, the infrastructure proved resilient. New domains, including ninjatech.io, emerged to fill the void.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Ninjatech was founded by Moishi Kramer, whose professional background lists him as the Vice President of Research and Development at NetNut. While Kramer has publicly denied current involvement with the botnet, asserting that the Ninjatech domain and the associated SDK (Software Development Kit) were sold to third parties years ago, independent researchers remain skeptical.

In a damning report released this week, the proxy-tracking firm Synthient stated that a forensic analysis of the Popa SDK revealed outbound traffic patterns that are exclusively associated with NetNut. "The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients," the report stated. "This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool."


The AI Scraping Economy: Why Your TV Matters

The explosion of interest in artificial intelligence has created a desperate need for vast quantities of "human-like" internet traffic. AI companies require massive datasets to train their Large Language Models (LLMs), but major platforms—including Google, Meta, and Cloudflare—have implemented aggressive defenses to block traffic from known data centers.

This has created a lucrative market for "residential" IP addresses. When a scraping job is routed through a standard Comcast or T-Mobile home connection, it appears to target websites as a legitimate user rather than a bot. Consequently, the streaming box in a consumer’s living room has become a hot commodity.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Include Security, a firm that tracks proxy SDKs, noted in a recent report: "The modern web isn’t scrapeable from a datacenter. The workaround is residential proxies. A scraping job routed through a subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer."

This demand has led to a ripple effect where nonprofit organizations, libraries, and universities have reported frequent service disruptions. According to a survey by the Confederation of Open Access Repositories (COAR), more than 90% of respondents indicated their repositories are being hit by aggressive bots, leading to increased server loads and, in many cases, total outages.


Official Responses and Industry Defense

Alarum Technologies has strongly refuted the claims made by researchers, labeling the reports as "demonstrably inaccurate." In an official statement, the company argued that its SDKs are designed purely for legitimate bandwidth-sharing and that the term "botnet" is a mischaracterization.

"NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of our services," Alarum stated. They emphasized that they perform "Know Your Customer" (KYC) checks to ensure that only legitimate entities gain access to their network.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

However, this "verified corporations only" claim is being challenged by industry watchdogs. Spur, a proxy tracking service, released a report on June 8 alleging that NetNut’s verification procedures are effectively non-existent. According to Spur, "anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto."


The Broader Implications for Network Security

The threat posed by Popa is not limited to cheap streaming boxes. The practice of embedding proxy SDKs into consumer applications—ranging from screensavers and PDF viewers to games and "productivity" tools—is becoming standard practice for developers looking to monetize free software.

The implications for enterprise security are profound. Infoblox, a leading network security firm, recently discovered that 65% of its corporate clients were querying domains linked to residential proxies. This suggests that employee-owned devices, brought into the workplace and connected to corporate Wi-Fi, are inadvertently turning secure business environments into nodes for external proxy networks.

"If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source," warned Infoblox researchers Nick Sundvall and David Brunsdon. "Untangling that… costs time, creates legal exposure, and can damage your reputation."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Conclusion: A Call for Transparency

The Popa incident highlights a systemic failure in how modern internet-connected devices are governed. From the lack of transparency in app stores—where users are rarely informed that their bandwidth is being commoditized—to the failure of hardware manufacturers like LG and Samsung to police their app ecosystems, the current environment is heavily skewed toward monetization over user security.

While companies like Amazon and Roku have begun to bar developers from using proxy SDKs on their platforms, the problem remains widespread. For the average consumer, the message is clear: if a device promises free premium streaming for a one-time fee, the "cost" is likely your network’s privacy and security. As long as the AI industry’s demand for human-like traffic continues to outpace regulatory oversight, the millions of devices trapped in the Popa botnet will continue to serve as the silent, involuntary engine of the modern scraping economy.

By Nana Wu