The Popa botnet, linked to Alarum Technologies’ NetNut service, has compromised millions of Android-based TV boxes to facilitate large-scale data scraping, advertising fraud, and unauthorized network access.
Key Points
- Security researchers identified Popa as a plugin component within the Vo1d botnet, which targets unofficial Android streaming devices.
- The botnet maintains between 1.5 million and 2.5 million active IP addresses daily, routing traffic for various commercial and malicious purposes.
- Analysis by firms including Synthient and Nokia Deepfield links Popa’s outbound traffic directly to the residential proxy infrastructure of NetNut.
- Alarum Technologies denies that its SDKs constitute a botnet, asserting that its services maintain strict compliance and user consent protocols.
- Proxy-tracking firm Spur reports that many residential proxy providers lack meaningful "know your customer" checks, allowing anonymous users to purchase access to home networks.