For the past four years, a sophisticated Android-based botnet known as Popa has surreptitiously enlisted millions of consumer TV boxes, transforming them into relays for illicit internet traffic. This network has been instrumental in facilitating activities ranging from advertising fraud and account takeovers to extensive data-scraping operations. This week, a collaborative investigation by researchers from multiple security firms has decisively linked the Popa botnet to NetNut, a prominent "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR). The findings highlight a critical intersection between the booming demand for AI-driven data and the shadowy underbelly of compromised consumer devices, raising significant questions about corporate responsibility, user consent, and the integrity of online ecosystems.
The Revelation: Popa’s Link to NetNut
The connection between the Popa botnet and NetNut emerged from detailed forensic analysis conducted by several cybersecurity organizations. Security firm Qurium, investigating a series of disruptive data scraping events in May 2026 that targeted its hosted organizations, traced the activity back to over 1.4 million scattered Internet addresses. Their deep dive uncovered dozens of domains used to control Popa, consistently hosted across multiple IP addresses. Among these were gmslb[.]net, safernetwork[.]io, tera-home[.]com, and crucially, ninjatech[.]io. The gmslb[.]net domain, in particular, was found embedded within numerous pirated or "modded" video streaming applications such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams.
Further investigation into ninjatech[.]io revealed a direct link to Moishi Kramer, whose LinkedIn profile identifies him as the Vice President of Research and Development at NetNut. Kramer’s resume credits him with instrumental contributions to NetNut’s architecture and scaling prior to its acquisition by Alarum Technologies. A self-created listing on the job board F6S further corroborates Kramer as the sole owner of the Ninjatech domain. This direct corporate and personal link formed the linchpin of the researchers’ conclusions.
Understanding the Popa Botnet
Unlike traditional botnets designed for destructive activities like distributed denial-of-service (DDoS) attacks, Popa operates with a singular, more insidious purpose: to establish and maintain a persistent communications layer. This layer registers compromised devices, sustains long-lived encrypted connections, and opens communication tunnels on demand. Experts characterize Popa as a plugin component of the larger Vo1d botnet, a widespread malware campaign specifically targeting unofficial Android-based TV boxes. These devices, marketed under a myriad of brand names and models across major e-commerce platforms, entice users with promises of access to hundreds of subscription video services for a one-time fee.

However, as the FBI and security industry experts have consistently warned, these seemingly innocuous streaming boxes often come pre-installed or bundled with malicious software. This software transforms the user’s TV into a "residential proxy," enabling third parties to route their internet traffic through the unsuspecting homeowner’s device for as long as it remains powered and connected. A more alarming facet of these proxy networks is their often lax security, doing little to prevent malicious clients from interacting with, and potentially compromising, other systems on the device owner’s local network. This creates a severe security vulnerability, turning household devices into unwitting participants in a global cyber infrastructure.
Chronology of Discovery and Disruption Efforts
The earliest public clues regarding Popa’s origins surfaced in a 2025 report by Chinese security firm XLAB, which identified at least nine domain names used to register and direct the activities of compromised devices. The landscape of these illicit operations underwent a significant shift in July 2025, when a collaborative effort by Google, HUMAN Security, and Trend Micro successfully disrupted Badbox 2.0, another botnet closely associated with Vo1d. This disruption led to the seizure and dismantling of many domains previously used to control the Popa botnet.
However, the criminal operators swiftly adapted. Qurium’s recent report details how immediately following the Badbox 2.0 takedown, dozens of new domains were registered to serve as controllers for Popa. Significantly, one of these control domains, ninjatech[.]io, was not new, further strengthening the link to Moishi Kramer and, by extension, NetNut. This resilience and rapid re-establishment of infrastructure underscore the persistent nature of these threats and the financial incentives driving them. In a parallel development, IPIDEA, a China-based proxy provider, faced similar legal action from Google and industry partners in January 2026. This action aimed to seize domain names used to control devices and proxy traffic through a network that previously boasted nearly 10 million daily devices. This prior disruption highlighted the widespread nature of such proxy networks and the proactive steps being taken by industry giants.
Corporate Responses and Contradictions
In response to the allegations, Moishi Kramer, via email, stated that Ninjatech ceased operations approximately five years ago, having sold a software development kit (SDK) named Popa. He claimed this SDK was designed to use a minimal portion of a device’s bandwidth and only after obtaining explicit user consent. Kramer asserted that once software is distributed in this manner, the original developer loses control over subsequent modifications, rebranding, or deployment. He vehemently denied any current involvement by himself or NetNut in building, operating, or maintaining the infrastructure now identified as Popa, and claimed no control over the Ninjatech domain or the new domains registered in June 2025.
However, these claims are directly challenged by independent research. In a separate Popa research report also released this week, the proxy-tracking company Synthient presented compelling evidence. Their recent analysis of the Popa SDK revealed clear outbound traffic unequivocally associated with NetNut. Synthient concluded with "high confidence that devices running Popa forward traffic from NetNut clients," asserting that this "proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool."

Alarum Technologies, NetNut’s parent company, issued a statement rejecting the reports from Synthient and Qurium, characterizing them as containing "demonstrably inaccurate assertions and flawed deductions rather than verified facts." Alarum denied that the SDKs and technologies discussed constitute a "botnet," instead describing them as designed to "facilitate bandwidth-sharing functionality" without compromising user devices. They emphasized NetNut’s commitment to "lawful and responsible use of its services," citing "significant emphasis on appropriate notice and consent mechanisms, conducts customer due diligence, monitors for potential misuse, and takes steps intended to detect and mitigate suspicious or unauthorized activity."
Yet, another proxy tracking service, Spur, contradicted Alarum’s claims regarding customer due diligence. In a report released on June 8, Spur asserted that NetNut does not require corporate verification or meaningful "know your customer" (KYC) procedures before allowing customers to purchase proxy access. Spur found that "an individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in." They dismissed the "verified corporations only" claim as "marketing for bandwidth sellers, not an access control on who actually uses the proxies." Furthermore, Spur highlighted the existence of numerous downstream "white labelers and resellers" who repackage the same ISP proxy pool, often performing "no KYC at all," making access readily available with "nothing more than a burner email address and $5 in crypto." Synthient’s analysis further revealed that while recent Popa builds might include consent mechanisms, none of the over 20 genuine Popa publishers analyzed were observed actually asking for user consent.
The Scale and Reach of Popa
The sheer scale of the Popa botnet underscores its pervasive threat. Chris Formosa, Senior Lead Information Security Engineer for Black Lotus Labs, a division of Lumen Technologies, highlighted the danger posed by NetNut’s widespread reselling network. "What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing," Formosa stated, noting that many other proxy services simply resell NetNut proxies rather than establishing their own extensive networks. This amplification means "these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently."
Formosa estimates that the Popa botnet averages between 1.5 million and 2.5 million distinct IP addresses daily, managed by 250 to 300 active Internet addresses. While these numbers are substantial, he noted they pale in comparison to the nearly 10 million devices previously controlled by IPIDEA before its recent disruption. Jérôme Meyer, a security researcher at Nokia Deepfield, suggested that Lumen’s estimates might even be conservative. Meyer’s monitoring of just 26 of at least 359 known relay nodes for Popa indicates that each node simultaneously handles between 35,000 and 60,000 clients. Based on this subset, Nokia Deepfield observed 750,000 unique sources within a 24-hour period, hinting at a potentially much larger total population of affected devices. Nokia Deepfield also released its own report today on RoboVPN, a VPN app directly linked to the Vo1d botnet’s Popa plugin, further attributing its control to NetNut/Alarum Technologies.
The Symbiotic Relationship: Proxies, AI, and Data Scraping
A crucial aspect of the current landscape is the evolving branding of many large proxy providers. They have increasingly positioned themselves as essential infrastructure for training AI platforms, a narrative driven by the AI industry’s insatiable demand for vast quantities of internet-scraped text, images, and video content to train large language models (LLMs). This symbiotic relationship is detailed in a report this month from Include Security, which examined the prevalence of proxy SDKs in smart TV apps.

"AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search," the report states. However, the modern web employs sophisticated defenses like Cloudflare, DataDome, and HUMAN Security, which throttle or block requests from known cloud IPs. The workaround? Residential proxies. "A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer."
This relentless and often unauthorized content scraping has not gone unnoticed. It has fueled over 70 copyright infringement lawsuits against major tech companies that have openly acknowledged large-scale data scraping as a primary source for their commercial AI offerings. The irony is stark: much of this scraping is facilitated by proxy services intrinsically tied to unofficial Android TV boxes and associated SDKs, whose original stated purpose was often the streaming of pirated content.
The intensity of this scraping activity is not merely an intellectual property concern; it frequently overwhelms targeted websites, rendering them inaccessible to legitimate users. Non-profit organizations, libraries, and universities have repeatedly reported struggling to maintain online services in the face of incessant data-scraping firms operating behind residential proxy networks. A survey conducted last year by the Confederation of Open Access Repositories (COAR) found that over 90 percent of respondents encountered aggressive bots, often more than once a week, leading to significant slowdowns and service outages. Brendan O’Connell, platform manager at the Directory of Open Access Journals (DOAJ), articulated this shift, noting that while web scraping has existed for decades, the current "investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google."
Broader Implications: Smart TVs and Unwitting Participants
While local communities across the United States are debating the proliferation of data centers designed for AI, the general public remains largely unaware that their own "smart TVs" might be actively contributing significant bandwidth to train these AI models. The problem extends beyond sketchy Android TV boxes. Even households with legitimate Samsung and LG smart TVs are at risk, simply by downloading one of thousands of available apps. Spur’s recent analysis of the LG and Samsung app stores revealed that a staggering 42% of apps available for LG webOS and over a quarter of apps for Samsung Tizen contained SDKs that turn the television into an always-on residential proxy node. These apps, often simple games or utilities, typically bury the disclosure about bandwidth sharing deep within their fine print, relying on users to consent without fully understanding the implications.
Security experts question whether such mechanisms constitute "meaningful consent," especially when any household member, including children, can inadvertently enroll the family TV into a residential proxy network by installing a seemingly harmless app. Include Security rightly points out that "privacy-policy disclosure is the wrong control surface for a TV." Navigating lengthy legal documents with a remote is cumbersome, and "the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet." Sean Simmons, head of research at Spur, emphasized this disconnect: "Most people do not have a working mental model for what it means to sell access to their residential IP address, no matter what device they are using. And on a TV, the gap is even wider. A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted."

Enterprise Risk and Legal Exposure
The problem of residential proxies is not confined to consumer homes. The security firm Infoblox highlighted that mobile app developers frequently embed residential proxy SDKs into their products for monetization, allowing them to earn revenue with each installation. This results in devices being enrolled without the owner’s knowledge, often through free VPNs, streaming apps, screensavers, or "productivity" tools like PDF viewers.
Crucially, Infoblox found that these proxy services are frequently beaconing from employee devices brought into the workplace. Their blog post earlier this month revealed that a startling 65% of their customer base was querying one or more residential proxy-related domains. This figure represents a 25% increase over 2025, reaching over 500 billion queries per month. The prevalence is particularly alarming in sensitive sectors, with over 90% of pharmaceutical and food & beverage customers, and over 60% of government and banking customers, querying residential proxy indicators.
Infoblox researchers Nick Sundvall and David Brunsdon issued a stark warning: the presence of residential proxies in a corporate environment grants external access to an organization’s IP space. "If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source," they wrote. "Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation." They urged network defenders and policymakers to consider the profound impact these risks could have on their security posture.
Industry Response and Future Outlook
In response to these escalating concerns, some platform providers are taking decisive action. Simmons noted that Amazon has already implemented policies prohibiting apps that facilitate proxy services for third parties. Similarly, TV streaming device maker Roku has reportedly barred developers from using proxy SDKs and has actively removed apps that bundled them. These actions set a precedent that LG and Samsung are now pressured to follow, to safeguard their users and uphold the integrity of their platforms.
The Popa botnet saga, intertwined with the operations of NetNut and the broader residential proxy industry, underscores a critical and evolving challenge in cybersecurity. The convergence of consumer devices, the quest for "free" content, the lucrative residential proxy market, and the insatiable data demands of AI models creates a complex threat landscape. As investigations continue and regulatory scrutiny intensifies, the onus is on corporations to ensure ethical practices and robust consent mechanisms, and on consumers to be acutely aware of the hidden costs and risks associated with seemingly free digital services. The battle to protect home networks and corporate environments from becoming unwitting participants in this shadowy economy is far from over.

