Hasty Briefsbeta

Bilingual

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

3 hours ago
  • The Popa botnet, linked to NetNut (Alarum Technologies), uses millions of Android TV boxes as residential proxies for advertising fraud, account takeovers, and data scraping.
  • Popa is a plugin for the Vo1d botnet, targeting unofficial Android TV boxes that come pre-installed with proxy software, often without user consent.
  • Qurium and Synthient investigations link Popa to NetNut through domain registrations, SDK analysis, and founder Moishi Kramer's involvement with Ninjatech.
  • Despite NetNut's claims of consent mechanisms, researchers found most Popa variants and publishers do not ask for user consent, and KYC procedures are minimal.
  • Popa operates 1.5–2.5 million IPs daily, with widespread resale across multiple proxy services, amplifying its danger.
  • Residential proxies are heavily used for AI data scraping, causing service disruptions for libraries, nonprofits, and academic repositories.
  • Samsung and LG smart TVs have thousands of apps with proxy SDKs, turning devices into proxy nodes, often without meaningful user consent.
  • Infoblox reports 65% of corporate customers query residential proxy domains, posing security and reputational risks.
  • Legal actions (e.g., Google, HUMAN Security) have disrupted related botnets, but Popa domains were quickly re-registered.