The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy

Researchers tie a four-year-old Android TV box botnet to NetNut, the residential proxy arm of NASDAQ-listed Alarum Technologies. The company disputes the framing.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
The Popa Botnet: When Your $40 Streaming Box Moonlights as a Residential Proxy
Share

Key points

  • Popa has quietly turned millions of cheap Android TV boxes into traffic relays for roughly four years.
  • Researchers at Synthient and Qurium link Popa's infrastructure to NetNut, owned by NASDAQ-listed Alarum Technologies.
  • NetNut VP of R&D Moishi Kramer founded Ninjatech, the company behind the original Popa SDK, but denies controlling current infrastructure.
  • Synthient says current Popa SDK traffic flows to NetNut endpoints, directly connecting the two today.
  • Proxy-tracking firm Spur found NetNut's pool is accessible for five dollars in cryptocurrency and a burner email, regardless of stated KYC policies.

What exactly is Popa?

Popa is a plugin component bolted to Vo1d, a large-scale malware campaign targeting unofficial Android TV boxes. It does not launch denial-of-service attacks. Instead it registers a device, keeps an encrypted tunnel open, and waits for someone to route traffic through your living room, making your home IP address available to whoever is paying for the proxy pool.

The devices themselves are sold under thousands of brand names, pitched as one-time-payment streaming miracles, and broadly available at major e-commerce platforms. The FBI has warned about this category of hardware for years.

How did researchers connect Popa to NetNut?

The trail starts with a 2025 report from Chinese security firm XLAB, which flagged nine controller domains. Qurium picked it up after investigating a scraping incident in May 2026 that hit its hosted clients from more than 1.4 million IP addresses. Several control domains, including gmslb[.]net, safernetwork[.]io, tera-home[.]com and ninjatech[.]io, were hosted in lockstep. The first appeared baked into pirated streaming apps including CRICFy, DooFlix and CyberFlix.

Most Popa controllers were seized or dismantled in July 2025 during the Google, HUMAN Security and Trend Micro operation against Badbox 2.0. New domains appeared almost immediately. One did not need to be new: ninjatech[.]io.

Ninjatech was founded by Moishi Kramer, currently VP of R&D at NetNut. His LinkedIn profile credits him with building NetNut's architecture from the ground up before the Alarum acquisition.

What does Kramer say?

Kramer told researchers that Ninjatech shut down roughly five years ago, that the Popa SDK was sold and licensed to third parties, and that he no longer operates the infrastructure or controls the domain. "I didn't register the June 2025 domains you mention, and I don't know who did," he said.

Synthient is less convinced. Its analysis of the current Popa SDK found outbound traffic going to NetNut endpoints. "The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients," Synthient wrote.

Should you worry about the consent argument?

Alarum rejects the botnet label. The SDKs, the company says, are bandwidth-sharing tools with consent prompts and customer due diligence, including KYC checks and misuse monitoring.

Proxy-tracking firm Spur, in a June 8 report, argued that KYC story does not survive contact with a credit card. Anyone can sign up, and white-label resellers sell access to the same pool for five dollars in cryptocurrency and a burner email.

That is the real structural problem with residential proxy networks: the legal product and the abuse channel share the same pipe. A consent prompt on a forty-dollar TV box does not change what Spur can demonstrate in under five minutes.

We covered the residential proxy-as-botnet-infrastructure pattern as recently as 1 June 2026, when Dutch authorities seized command-and-control servers rented out for criminal operations through exactly this model. Popa is the same architecture, just with a publicly traded company's name attached to it. That is what makes this story worth defending.

© 2026 Threat Vectr