Logo
News Ababil
Explore
Global Intel (English)
Global Intel (English)VOICE
Bengali (বাংলা)
Spanish (Español)VOICE
French (Français)VOICE
German (Deutsch)
Arabic (العربية)
Hindi (हिन्दी)VOICE
Chinese (中文)
Japanese (日本語)
Russian (Русский)
SYS_NODE: ONLINE // Cyber Security

Popa Botnet Tied to Israeli Proxy Firm NetNut Raises Global Cybersecurity Alarm

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-06-21 T 09:09:07 Z | [ 2 MIN READ ]
Popa Botnet Tied to Israeli Proxy Firm NetNut Raises Global Cybersecurity Alarm
2 Min Read
Share

Popa Botnet and NetNut Connection

A four‑year investigation has linked the Android‑based Popa botnet to NetNut, the residential‑proxy service owned by publicly‑traded Alarum Technologies (NASDAQ:ALAR). Researchers from Qurium, Synthient and other firms say the botnet hijacks cheap streaming boxes sold on major e‑commerce sites, turning them into always‑on proxies. Millions of households unknowingly route ad fraud, account takeovers and massive web‑scraping traffic through their home broadband. The first clues emerged in a 2025 XLAB report that listed nine suspicious domains. Today, Qurium identified dozens more, including gmslb.net and ninjatech.io, which appear in pirated video apps such as CRICFy and Flixoid.

“The code was sold and licensed to third parties years ago,” said Moishi Kramer, former VP of R&D at NetNut.

Kramer insists he no longer controls the domains or infrastructure. Yet Synthient’s traffic analysis shows outbound streams that match NetNut’s proxy pools, leading them to conclude the botnet is actively used by the firm. Alarum’s public statements describe the SDK as a “bandwidth‑sharing” tool, not a botnet, and claim robust KYC procedures. Independent research from Spur contradicts that, noting anyone can purchase proxy access with a burner email and a few dollars of crypto. ↑ 2.1M IP addresses have been observed in the botnet’s daily pool, while ↓ 5% of NetNut‑claimed “verified corporate” accounts actually undergo rigorous checks. Chris Formosa, senior engineer at Lumen’s Black Lotus Labs, warns that the botnet’s reach across dozens of reseller services amplifies its impact. Reuters has highlighted similar proxy‑driven threats to AI training pipelines. The surge in AI‑focused scraping has turned residential proxies into critical infrastructure, a shift noted by Include Security. Even after the pandemic era, corporate networks remain vulnerable as employees install unvetted TV apps that embed proxy SDKs. Experts urge platforms like LG and Samsung to ban such components, following Amazon’s and Roku’s recent policies.

Dispatch from: Nova Stirling
Aerospace & Space Tech Correspondent
Global Data Feed

More from this Intel

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Vectra AI Unveils Ascent to Counter AI-Driven Attacks

Sep 20, 2026
Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a Massive Supply‑Chain Attack

Google Infiltrated TeamPCP: Inside the Undercover Operation that Stopped a...

Sep 20, 2026
Gyazo data breach leaks 23.6 million accounts – massive server flaw exposed

Gyazo data breach leaks 23.6 million accounts – massive server...

Sep 19, 2026
Microsoft security patches shatter record with 974 fixes in September

Microsoft security patches shatter record with 974 fixes in September

Sep 19, 2026
Linux kernel exploit exposes four local‑root flaws, patches urged

Linux kernel exploit exposes four local‑root flaws, patches urged

Sep 18, 2026
Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Microsoft patches bug behind ‘Defender Antivirus turned off alerts’

Sep 18, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.