DilmipaintCorrespondents · Reports · Analysis
CORRESPONDENT REPORTAI & ML

Uncovering the Popa Botnet: The Silent Threat Behind Your Android TV Box

Published
Jun 18, 2026
Desk
AI & ML
Views
897

The Popa botnet leverages Android TV boxes for continuous data exploitation, raising cybersecurity alarms over user privacy and malicious proxy services.

Uncovering the Popa Botnet: The Silent Threat Behind Your Android TV Box

Unraveling the Popa Botnet

Popa, a vast botnet rooted in Android technology, has been wreaking havoc unnoticed for four years. This system has effectively turned millions of consumer-grade TV boxes into unwitting accomplices in a scam-laden world of advertising fraud, account takeovers, and relentless data scraping. Recent investigations by security researchers have established a connection between Popa and NetNut, a residential proxy service managed by Alarum Technologies Ltd, an Israeli firm listed on NASDAQ. The recent findings transform the narrative around Popa from mere speculation to a concrete threat. Rather than following the typical destructive patterns of conventional botnets—think DDoS attacks or data theft—Popa's strategy is more calculated. It's designed primarily for communication, providing a sustained encrypted link between devices and a network that can be activated on demand. The implications here are significant: instead of a once-off theft of data, Popa enables continuous exploitation. It's worth digging deeper into how Popa fits into a larger ecosystem of malware and illicit activities. Experts now suspect that Popa functions as an auxiliary to the larger Vo1d botnet, targeting various unofficial Android-based TV boxes available for purchase at e-commerce giants. These devices, often presented under a variety of obscure brands, claim to offer seamless streaming for a one-time payment—an enticing offer that often hides malice. Unfortunately, the FBI and cybersecurity specialists have raised privacy alarms about these streaming boxes, which often come pre-loaded with software that effectively turns users’ devices into residential proxies. This feature allows third parties to route their Internet traffic through the unsuspecting owner's connection as long as the box is powered on and linked to a local network. Alarmingly, many of these proxy services lack the safeguards needed to stop malicious actors from exploiting the owner’s network. The origin story of Popa traces back to an intriguing report by XLAB from 2025, which flagged multiple domain names associated with its activities. Fast forward to 2026, a report from Qurium reveals a troubling connection between the botnet and a series of disruptive data scraping incidents. Qurium’s findings indicate a system operating at scale, with Popa controlling millions of IP addresses through a tangled web of domains that were reassigned or created after previous crackdowns. Some of these domains, like gmslb[.]net, have found their way into numerous pirated content streaming apps, further embedding Popa into the loamy underground of illicit media streaming. In the wake of interventions by security corporations such as Google and HUMAN Security, which dismantled several domains associated with Popa in July 2025, new domains quickly sprung up. Notably, one domain—ninjatech.io—remained a constant. Its registration reveals ties to Moishi Kramer, the former vice president of research and development at NetNut. When questioned, Kramer claimed that his company had folded operations years prior, asserting that responsibility for the current activities lies with third-party modifications beyond his control or oversight. However, Synthient, a proxy-tracking firm, contradicts Kramer's assertions, alleging recent analyses show direct associations between NetNut and the traffic forwarded by Popa-controlled devices. Synthient's analysis asserts with high confidence that the botnet is a key player in NetNut's operations, interlocking it further into the fabric of illicit proxy networks. Alarum Technologies has firmly rebuffed these claims, labeling them as “inaccurate assertions,” and maintains that their SDKs focus on bandwidth-sharing—and do not compromise user devices. They highlight due diligence, stating they monitor for misuse and actively promote lawful use. Yet, reports from proxy tracking services like Spur paint a different picture, alleging that NetNut's verification processes for its customers are nominal at best. In a world where access is often as simple as a few clicks and a small payment, scrutiny seems not just lacking but ineffective. The situation is dire. Synthient's findings suggest that while newer versions of Popa may seek user consent before installation, many existing ones do not. Even looking at the population of devices associated with Popa—between 1.5 to 2.5 million distinct IP addresses per day—raises serious questions about the scale and scope of its influence in today's digital economy. If you're in this field, the implications of Popa's operations should cause you to rethink how malware is evolving. The botnet underscores a chilling reality: the lines between benign proxy use and malicious activities are growing increasingly blurred. It's a reminder that behind every gadget is a potential gatekeeper for crime—and one that too many remain unaware of.

Consent at a Cost: The Unseen Risk of Proxy SDKs

The conversation surrounding proxy SDKs in TV apps reveals significant ethical concerns, especially regarding informed user consent. Experts are skeptical that users truly understand the implications of connecting their devices to a persistent residential proxy—especially when app installations can be as simple as downloading a game. This lack of awareness is alarming, as it opens the door for everyone in a household, including children, to unwittingly expose their home network to potentially harmful activities. Sean Simmons, the head of research at Spur, succinctly points out that most people lack a clear understanding of what it means to sell access to their residential IP address, regardless of device. "On a TV," he noted, "the gap is even wider." When a user is prompted with a vague agreement during setup—especially when navigating via a clunky remote—it's easy for them to forget the consequences, allowing the app to monetize their connection long after consent was given. In light of these concerns, Simmons argues that companies like LG and Samsung should take a stand against residential proxy providers. Currently, they lag behind competitors like Amazon, which has implemented strict policies against third-party proxy services. Following suit could help carve a safer environment for users and their networks, especially given that Roku has already banned such practices among its app developers.

The Broader Implications

But the reality extends beyond smart TVs. Infoblox's recent report highlights prevalence in mobile applications, where developers embed proxy SDKs to monetize their software. It’s alarming to think that devices are often turned into proxy nodes without their owners' consent due to seemingly innocuous apps like free VPNs or productivity tools. This has serious implications, particularly in workplaces where personal devices are brought into professional environments. The statistics tell a troubling tale. Infoblox has observed that 65% of its customers have queried residential proxy domains, with over 500 billion queries recorded each month—not an insignificant figure by any stretch. The proliferation of these proxies not only introduces security risks but also complicates the incident response process. As researchers Nick Sundvall and David Brunsdon caution, if cyber threats exploit residential proxies originating from a business’s network, untangling that mess could lead to reputational and legal hurdles. So, here's a thought: If you're navigating this space, it’s essential to reevaluate the built-in assumptions about user consent and network safety. The rise of residential proxies necessitates a more vigilant stance on privacy and security—not just for end-users but for organizations too. As the digital landscape shifts, greater awareness and proactive measures will be crucial in protecting all stakeholders involved.
Source: BrianKrebs · krebsonsecurity.com

Discussion

Sign in to join the discussion.