highMalware

Popa Botnet

First seen Jul 4, 2026 · Updated Jul 4, 2026

botnetandroidresidential-proxyad-fraudaccount-takeoverdata-scrapingiot

The Popa botnet is a large-scale Android-based malware network that has compromised millions of consumer TV boxes over the past four years, using them as unwitting relays for internet traffic. Security researchers have linked this infrastructure to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies Ltd (NASDAQ: ALAR), raising concerns about corporate involvement in facilitating malicious traffic relay networks.

Technical Analysis

Popa operates by infecting Android-based consumer TV boxes, likely through pre-installed malware, compromised firmware, or supply-chain infiltration during device manufacturing/distribution, turning them into nodes within a residential proxy network. The compromised devices relay traffic on behalf of paying customers, obscuring the true origin of requests and lending residential IP legitimacy to malicious activities including advertising fraud, credential stuffing, and account takeover attempts. The botnet's traffic has reportedly been routed through infrastructure associated with NetNut, suggesting monetization via commercial proxy resale. No specific CVEs have been publicly attributed to this campaign, indicating the infection vector may rely on supply-chain compromise or bundled malware rather than exploitation of a disclosed software vulnerability.

Affected Systems

Android-based consumer TV boxes (various OEM/white-label devices), IoT set-top box firmware, devices connected to residential ISP networks used as proxy exit nodes

Indicators of Compromise

  • Botnet name: Popa
  • Associated proxy service: NetNut
  • Associated entity: Alarum Technologies Ltd (NASDAQ: ALAR)
  • Note: Specific hashes, IPs, and domains not disclosed in source reporting

Remediation Steps

  1. 1

    Audit Android TV Box Firmware

    Inspect consumer and enterprise Android TV boxes for unauthorized proxy/relay software, unexpected outbound connections, or unsigned firmware modifications.

  2. 2

    Monitor Network Traffic for Proxy Relay Behavior

    Deploy network monitoring to detect unusual outbound traffic patterns consistent with residential proxy relay activity, especially persistent connections to known proxy provider infrastructure.

  3. 3

    Restrict Untrusted IoT Device Procurement

    Avoid purchasing unbranded or low-cost Android TV boxes from unverified vendors, as these are common vectors for pre-installed botnet malware.

  4. 4

    Segment IoT Devices from Critical Networks

    Place consumer IoT and streaming devices on isolated network segments/VLANs to limit their ability to be leveraged for lateral movement or credential-stuffing campaigns.

  5. 5

    Engage Threat Intelligence on Residential Proxy Abuse

    Incorporate known malicious residential proxy IP ranges (including those tied to NetNut/Popa) into threat intelligence feeds and blocklists for fraud detection and account takeover prevention systems.

  6. 6

    Firmware Reset and Reflashing

    For confirmed infected devices, perform a full factory reset and reflash with verified, vendor-signed firmware where possible.

Industries Most Exposed

Consumer ElectronicsAdvertising TechnologyFinancial ServicesE-commerceTelecommunicationsCybersecurity

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.