Researchers link Popa Android TV box botnet and residential proxy network to NetNut and Alarum Technologies

Researchers say a sprawling Android TV box botnet called Popa has been turning millions of consumer streaming devices into residential proxies that relay malicious traffic. KrebsOnSecurity, citing Qurium and earlier XLAB findings, says Popa is associated with the Vo1d malware ecosystem and has been used for advertising fraud, account-takeover activity, and mass data scraping; newly analyzed command-and-control domains including ninjatech[.]io are linked to NetNut, a proxy provider owned by Alarum Technologies.
Why it matters: People who bought unofficial streaming boxes may have unknowingly exposed their home internet connections and possibly local networks to abuse by third parties. Consumers should disconnect suspect devices, replace them with trusted hardware, and monitor accounts and network activity; defenders should block known Popa infrastructure and scrutinize traffic from Android-based set-top boxes and residential proxy sources.

Sources

NetNut proxy network disrupted, 2 million infected devices cut off
Ionut Ilascu 2026.07.03 95% relevant
This updates the same underlying NetNut/Popa residential proxy network story with a coordinated takedown: Google says the botnet controlled at least 2 million infected Android devices, the FBI seized a domain used by NetNut, Google disabled related C2 infrastructure, and Play Protect warnings and app disabling were used to protect affected users.
NetNut cracked as Google and FBI target 2 million-device botnet
2026.07.03 84% relevant
This updates the same underlying NetNut residential proxy ecosystem story by reporting a coordinated disruption by Google, the FBI, Lumen, and Shadowserver, adding that investigators believe NetNut had at least 2 million enrolled devices and that many reseller proxy brands may depend on the same network.
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
Ionut Arghire 2026.07.03 97% relevant
This article updates the same underlying NetNut/Popa event with new details that Google, the FBI, and partners took coordinated action to disrupt the proxy network, disabled Google accounts and command-and-control services, used Play Protect to block infected apps, and observed 316 threat clusters abusing NetNut in June.
FBI Seizes NetNut Proxy Platform, Popa Botnet
BrianKrebs 2026.07.02 98% relevant
This article is a direct update on the same underlying event: the Popa botnet and its linkage to NetNut. It adds that the FBI, with partners including Google, seized hundreds of NetNut-related domains, replaced the homepage with a seizure banner, and disrupted both the botnet and the proxy network built on top of it.
In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek News 2026.06.19 62% relevant
It briefly notes the same Popa Android TV botnet story and the claimed linkage to an Israeli firm, adding only summary-level context rather than substantive new facts.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
BrianKrebs 2026.06.18 100% relevant
This article establishes a distinct story by adding a concrete attribution link between the long-running Popa/Vo1d consumer-device botnet and NetNut/Alarum infrastructure, rather than merely describing generic residential proxy abuse.
← Back to all stories