Security researchers have identified a large-scale Android botnet, dubbed “Popa,” that is actively turning millions of consumer streaming devices into residential proxy nodes used for advertising fraud, data scraping, and unauthorized network access. According to reports released this week by multiple cybersecurity firms, including Qurium and Synthient, the botnet is linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd, a publicly-traded company listed on the NASDAQ under the ticker symbol ALAR.
The Popa botnet operates by leveraging software development kits (SDKs) pre-installed on unofficial Android TV boxes—devices often marketed for one-time fees to access subscription video content. Once these devices are connected to a local network, the Popa plugin creates a persistent, encrypted communication tunnel. This configuration allows third parties to route internet traffic through the user’s home network, effectively masking the true origin of their web activity. While traditional botnets often focus on destructive tasks like distributed denial-of-service (DDoS) attacks, Popa is primarily designed to facilitate a massive, distributed communications layer for high-volume data scraping and commercial proxy services.
Malicious streaming devices sold online that enroll the user’s home Internet address in a residential proxy service. Image: HUMAN Security.
The Connection to NetNut and Alarum Technologies
The link between the Popa botnet and NetNut emerged following investigations into large-scale data scraping events. The security firm Qurium reported that it identified several control domains associated with Popa, such as gmslb[.]net and ninjatech[.]io, while investigating scraping activity that spanned more than 1.4 million distinct internet addresses in May 2026. According to the report, the domain ninjatech[.]io is historically associated with Moishi Kramer, who serves as the vice president of research and development at NetNut. Kramer, in email correspondence, stated that Ninjatech ceased operations approximately five years ago and that the Popa SDK was sold to third parties, adding that he has no control over how those entities currently deploy the software.
Despite these claims, the proxy-tracking firm Synthient released research today asserting that an analysis of the Popa SDK reveals outbound traffic routed directly to NetNut’s infrastructure. “The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” the firm stated in its report. This assessment suggests a direct, ongoing operational relationship between the botnet’s activity and the proxy services provided by the Israeli firm.
Synthient’s platform receiving outbound traffic from Popa. Image: Synthient.com.

Alarum Technologies has formally rejected the characterization of its technology as a botnet. In a statement provided to researchers, the company described the reports as containing “demonstrably inaccurate assertions and flawed deductions.” Alarum emphasized that its SDKs are intended for legitimate bandwidth-sharing and that the company maintains “policies, procedures, and technological measures” to ensure lawful use of its services, including “know your customer” (KYC) checks for its clients.
However, this assertion is contested by other industry analysts. On June 8, the proxy tracking service Spur published findings alleging that NetNut does not require meaningful corporate verification before allowing customers to purchase access to its proxy pool. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies,” Spur reported, noting that users can often obtain access through resellers using little more than a burner email address and cryptocurrency payments.
Prevalence and Risks to Corporate Networks
The scale of the Popa botnet is significant. Chris Formosa, a senior lead information security engineer at Lumen Technologies’ Black Lotus Labs, estimates that the botnet maintains between 1.5 million and 2.5 million distinct IP addresses on any given day. Formosa noted that the danger lies in the ubiquity of NetNut’s infrastructure, which is widely resold across the ecosystem, amplifying the reach of the hijacked residential IP addresses.
Jérôme Meyer, a security researcher at Nokia Deepfield, suggests the actual number of participating devices may be even higher. Based on monitoring a subset of 26 relay nodes, Meyer estimated that each node handles between 35,000 and 60,000 clients simultaneously, totaling 750,000 unique sources over a 24-hour period. These residential proxies are increasingly used by AI companies to scrape data, as cloud-based data centers are frequently throttled or blocked by websites attempting to prevent automated harvesting.
The risks extend beyond the home user. Infoblox, a network security firm, reported earlier this month that approximately 65% of its customer base—including banking, government, and pharmaceutical entities—had queried residential proxy-related domains. This indicates that employee devices, such as smart TVs or mobile apps containing these SDKs, are frequently brought into corporate environments. Researchers Nick Sundvall and David Brunsdon warned that this creates significant legal and reputational exposure, as a company’s IP space can be used as a conduit for malicious activity, leading third-party security systems to identify the organization as the source of an attack.
Image: F6S.com.

Consent and the Future of Smart TV Security
A primary concern for security experts is the lack of meaningful user consent. While recent builds of the Popa SDK allegedly include an opt-in mechanism, analysts at Synthient observed that none of the more than 20 publishers they examined actually requested user consent during installation. This is particularly problematic on smart TVs, where user interfaces are not designed for reviewing complex privacy policies or managing granular permission settings.
Spur’s research highlights that the problem is not limited to “no-name” streaming boxes. After auditing the LG and Samsung app stores, the firm found that approximately 42% of apps on LG’s webOS and over 25% of apps on Samsung’s Tizen operating system contained SDKs capable of turning the device into an always-on residential proxy node. “Privacy-policy disclosure is the wrong control surface for a TV,” noted researchers at Include Security, emphasizing that in-app consent dialogs often fail to explain that a third party will be routing traffic through the user’s home network.
Piracy related apps pushing proxy SDKs onto unconsenting users. Image: Synthient.

As industry scrutiny increases, some platforms have begun to take action. Amazon and Roku have reportedly updated their policies to bar developers from using proxy SDKs and have initiated the removal of apps found to be bundling such software. Industry observers expect further regulatory attention as the intersection of unauthorized data scraping, AI training models, and the misuse of residential IP addresses continues to disrupt digital infrastructure.
NetNut and other proxy services have recast themselves as critical infrastructure for the AI scraping economy. Image: Synthient.com.

The next major developments in this area are expected to emerge from ongoing investigations by international regulatory bodies into the data-scraping practices of AI firms and the subsequent legal challenges regarding copyright infringement. Readers are encouraged to monitor updates from the FBI’s Internet Crime Complaint Center (IC3) and major cybersecurity research outlets for further guidance on securing home and corporate networks against unauthorized proxy enrollment. Please share your thoughts or experiences with these devices in the comments below.
Related reading