Researchers say a sprawling Android TV box botnet called Popa has been turning millions of consumer streaming devices into residential proxies that relay malicious traffic. KrebsOnSecurity, citing Qurium and earlier XLAB findings, says Popa is associated with the Vo1d malware ecosystem and has been used for advertising fraud, account-takeover activity, and mass data scraping; newly analyzed command-and-control domains including ninjatech[.]io are linked to NetNut, a proxy provider owned by Alarum Technologies.
Ionut Ilascu
2026.07.03
95% relevant
This updates the same underlying NetNut/Popa residential proxy network story with a coordinated takedown: Google says the botnet controlled at least 2 million infected Android devices, the FBI seized a domain used by NetNut, Google disabled related C2 infrastructure, and Play Protect warnings and app disabling were used to protect affected users.
2026.07.03
84% relevant
This updates the same underlying NetNut residential proxy ecosystem story by reporting a coordinated disruption by Google, the FBI, Lumen, and Shadowserver, adding that investigators believe NetNut had at least 2 million enrolled devices and that many reseller proxy brands may depend on the same network.
Ionut Arghire
2026.07.03
97% relevant
This article updates the same underlying NetNut/Popa event with new details that Google, the FBI, and partners took coordinated action to disrupt the proxy network, disabled Google accounts and command-and-control services, used Play Protect to block infected apps, and observed 316 threat clusters abusing NetNut in June.
BrianKrebs
2026.07.02
98% relevant
This article is a direct update on the same underlying event: the Popa botnet and its linkage to NetNut. It adds that the FBI, with partners including Google, seized hundreds of NetNut-related domains, replaced the homepage with a seizure banner, and disrupted both the botnet and the proxy network built on top of it.
SecurityWeek News
2026.06.19
62% relevant
It briefly notes the same Popa Android TV botnet story and the claimed linkage to an Israeli firm, adding only summary-level context rather than substantive new facts.
BrianKrebs
2026.06.18
100% relevant
This article establishes a distinct story by adding a concrete attribution link between the long-running Popa/Vo1d consumer-device botnet and NetNut/Alarum infrastructure, rather than merely describing generic residential proxy abuse.