The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy
Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

Call Popa a botnet and you'll start an argument. Call it a residential proxy and you'll start a different one.
For about four years, an Android-based network dubbed Popa has been quietly turning millions of cheap streaming boxes into traffic relays. Not the kind of botnet that DDoSes a bank. The kind that hangs around, keeps an encrypted tunnel open, and waits for someone to route traffic through your living room.
This week, two separate research outfits — Synthient and Qurium — published findings tying Popa's infrastructure to NetNut, the residential proxy provider owned by Israel's Alarum Technologies (NASDAQ: ALAR).
The attack surface here isn't novel. It's the same story the FBI has been telling about off-brand Android TV boxes for years: devices sold under thousands of model numbers, pitched as one-time-payment streaming miracles, shipping with SDKs that enroll the buyer's home IP into a proxy pool. Vo1d is the umbrella malware campaign. Popa is the persistence-and-tunneling component bolted to it.
Think of it as a SOCKS proxy with extra steps and worse consent flows.
The trail starts with a 2025 writeup from Chinese firm XLAB flagging nine controller domains. Qurium picked up the thread after investigating a scraping incident in May 2026 that hit hosted clients from more than 1.4 million IPs. Several control domains — gmslb[.]net, safernetwork[.]io, tera-home[.]com, ninjatech[.]io — were hosted in lockstep. The first appeared baked into pirated streaming apps with names like CRICFy, DooFlix, RTS Tv and CyberFlix.
Most Popa controllers got knocked over in July 2025 during the Google/HUMAN/Trend Micro operation against Badbox 2.0. New domains popped up almost immediately. One didn't need to be new: ninjatech[.]io.
Ninjatech was founded by Moishi Kramer, currently VP of R&D at NetNut. His own résumé credits him with designing NetNut's architecture from the ground up before the Alarum acquisition.
Kramer told researchers that Ninjatech wound down roughly five years ago, that the Popa SDK was sold and licensed to third parties, and that he doesn't operate the current infrastructure or control the domain. "I didn't register the June 2025 domains you mention, and I don't know who did," he said.
Synthient is less convinced. Its analysis of the current Popa SDK shows outbound traffic going to NetNut endpoints, which the team says proves the devices are still forwarding traffic for NetNut customers today.
Alarum rejects the botnet label outright. The SDKs, the company says, are bandwidth-sharing tools with consent prompts, KYC checks, and misuse monitoring.
Proxy-tracking firm Spur, in a June 8 report, argued the KYC story doesn't survive contact with a credit card. Per Spur, anyone can sign up, route traffic, and downstream white-label resellers will sell the same pool for "$5 in crypto" and a burner email.
Which is the real tension in residential proxy land: the legal product and the abuse channel run on the same pipe. The consent prompt on a $40 TV box doesn't fix that.



