Popa Botnet: 1.4M Hacked Android TV Boxes Linked to Israeli Firm NetNut
Security researchers from Qurium, HUMAN Security, and XLAB have concluded that the massive Popa botnet is operated by NetNut, a residential proxy service run by publicly-traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR). Popa is not a traditional botnet designed for DDoS attacks or ransomware delivery; instead, it functions as a persistent communications layer that registers compromised devices, maintains long-lived encrypted connections, and opens tunnels on demand. Researchers describe Popa as a plugin component of the Vo1d botnet, which infects millions of low-cost Android-based TV boxes sold under thousands of brand names across major e-commerce platforms—devices that advertise free access to premium streaming services but secretly enroll the user's home IP address into a commercial proxy network.
The trail leading to Alarum began with a 2025 XLAB report flagging nine command-and-control domains, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Qurium's investigation, triggered by a wave of distributed data-scraping attacks in May 2026 targeting its hosted customers, revealed scraping traffic evenly distributed across roughly 1.4 million residential IP addresses. Qurium traced dozens of Popa control domains hosted in lockstep across multiple servers and discovered gmslb[.]net referenced inside pirated streaming applications such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams—the same apps used to install the malware on consumer TV boxes.
The implications extend well beyond advertising fraud. Because compromised devices sit inside home networks, attackers who rent access through NetNut can pivot from the proxy to other systems on the same local network, enabling account takeovers and internal reconnaissance against unsuspecting households. Users who suspect their streaming box may be enrolled in a residential proxy network should verify their setup with a VPN/proxy detector to see if outbound traffic from their IP is being routed through suspicious intermediaries. Security teams investigating the domains referenced in the Qurium report can cross-reference registration details using a WHOIS lookup to map the broader infrastructure, while individuals concerned about device-level tracking can run a browser fingerprint test to evaluate how identifiable their environment remains when traffic is relayed through proxy nodes like those operated by Popa.