the-invisible-conduit-how-the-popa-botnet-and-residential-proxies-fuel-the-global-ai-scraping-economy

Executive Overview

For the past four years, a sprawling Android-based botnet known as Popa has silently co-opted millions of consumer streaming television boxes. Operating in the background, this pervasive infrastructure routes unauthorized internet traffic linked to advertising fraud, account takeovers, and large-scale data-scraping operations. This week, a collaborative wave of research from prominent security firms—including Qurium, Synthient, and Nokia Deepfield—has formally connected the Popa botnet to NetNut, a commercial "residential proxy" provider operated by the publicly traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR).

Unlike traditional botnets designed to mount destructive Distributed Denial-of-Service (DDoS) campaigns or deploy ransomware payloads, Popa serves a specialized, structural purpose: it maintains a persistent, encrypted communications layer. This layer registers compromised devices, sustains long-lived command channels, and opens on-demand communication tunnels. Experts identify Popa as a critical plugin component associated with the Vo1d botnet—a massive malware campaign targeting uncertified Android-based TV boxes.

While these devices are marketed globally through mainstream e-commerce channels under thousands of generic brand names promising "free lifetime streaming," they frequently bundle hidden software. This code transforms the host television into an always-on residential proxy node. Consequently, third parties can route their own internet traffic through an unsuspecting consumer’s home network for as long as the device remains powered on and connected to the local area network (LAN).

The implications extend far beyond individual privacy. As artificial intelligence companies engage in relentless mass-scraping to gather text, images, and video for training Large Language Models (LLMs), residential proxies have become the essential infrastructure for bypassing enterprise security controls. Cloud-based scraping protections—enforced by platforms such as Cloudflare, DataDome, and HUMAN Security—routinely throttle or block traffic originating from known data center blocks. By leveraging networks like Popa, scraping traffic originates instead from legitimate residential IP addresses belonging to Comcast, T-Mobile, and global telecom subscribers.


Detailed Chronology & Technical Anatomy

The anatomy of the Popa botnet represents a sophisticated evolution in the monetization of edge computing hardware. The first concrete clues regarding Popa’s origins emerged in a 2025 investigative report from Chinese security firm XLAB, which flagged at least nine domains orchestrating the activities of compromised consumer devices.

In June 2026, the investigation expanded dramatically. Qurium published a forensic breakdown detailing how it stumbled upon these same control domains while investigating a series of disruptive, high-cost data scraping campaigns targeting hosted organizations. The malicious scraping traffic was distributed evenly across more than 1.4 million unique internet addresses. Qurium discovered several dozen control domains hosted synchronously across multiple IP blocks, including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io. Deeper packet analysis revealed that gmslb[.]net was embedded within dozens of pirated and modified streaming applications, such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, and HD/OceanStreams.

A significant pivot point occurred in July 2025, when a coalition comprising Google, HUMAN Security, and Trend Micro successfully dismantled Badbox 2.0, a botnet closely intertwined with Vo1d. Following the seizure and disruption of these primary control domains, dozens of new controller addresses were rapidly registered for Popa. Notably, however, ninjatech[.]io remained active from its established infrastructure.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Public records link Ninjatech to Moishi Kramer, whose LinkedIn profile identifies him as the Vice President of Research and Development at NetNut. Kramer’s resume highlights his role in building NetNut from the ground up, engineering its system architecture, and scaling the network prior to its acquisition by Alarum Technologies. Furthermore, documentation on the tech job board F6S lists Kramer as the sole owner of the Ninjatech domain.

When queried about these findings, Kramer maintained that Ninjatech ceased active operations approximately five years ago upon licensing a software development kit (SDK) known as Popa. According to Kramer, the SDK was intentionally designed to consume minimal device bandwidth and execute only after host applications obtained explicit user consent.

"That code was sold and licensed to third parties including resellers years ago," Kramer stated via email. "Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it."

Kramer denied building, operating, or maintaining the infrastructure attributed to Popa, stating he possesses no control over or visibility into the June 2025 domain registrations.

Despite these assertions, independent telemetry from proxy-tracking firm Synthient directly contradicted this defense. Analyzing outbound packet captures from the Popa SDK, Synthient researchers identified persistent, verifiable traffic flows routing directly to NetNut clients.

"The research team assesses with high confidence that devices running Popa forward traffic from NetNut clients," Synthient noted in its technical brief. "This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool."


Supporting Context, Metrics, & Industry Scale

The sheer scale of the Popa infrastructure has alarmed network defenders across the global telecommunications backbone. Chris Formosa, Senior Lead Information Security Engineer for Black Lotus Labs at Lumen Technologies, emphasized the systemic risk introduced by NetNut’s business model.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing," Formosa explained. "Many other proxy services simply resell NetNut proxies rather than building out their own far-flung proxy networks. So these Popa IPs appear in tons of different services all over the ecosystem, making it one of the most problematic and dangerous proxy botnets on the market currently."

According to Lumen telemetry, the Popa botnet sustains an average daily footprint of 1.5 million to 2.5 million distinct IP addresses, orchestrated by a core command infrastructure of 250 to 300 control addresses.

Other security researchers suggest these figures represent a conservative baseline. Jérôme Meyer, a security researcher at Nokia Deepfield, reported that Nokia is monitoring just 26 out of at least 359 known relay nodes for the botnet. According to Meyer’s analysis, each individual relay node simultaneously handles between 35,000 and 60,000 clients.

"On the relay node subset I am looking at [26 nodes], we observe 750,000 unique sources in a 24-hour window," Meyer stated. Nokia Deepfield published complementary research concerning RoboVPN, a commercial virtual private network application explicitly tied to the Vo1d botnet’s Popa plugin.

To contextualize Popa’s footprint, its active node count trails behind historical giants like IPIDEA, a China-based proxy provider that maintained a daily pool of nearly 10 million compromised devices until Google and industry partners executed legal actions to seize its infrastructure in January 2026. However, Popa’s deep integration into commercial resale networks ensures its operational capacity remains highly concentrated and potent.


Official Statements & Industry Pushback

Corporate entities linked to the infrastructure have mounted a robust defense against the findings. Alarum Technologies issued a formal corporate response dismissing the investigative reports from Synthient and Qurium as resting on "demonstrably inaccurate assertions and flawed deductions rather than verified facts."

The parent company categorically rejected the classification of its SDKs as a "botnet":

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems or otherwise compromise the devices on which they operate," Alarum’s statement read. "NetNut operates a commercial proxy network and maintains policies, procedures, and technological measures designed to promote lawful and responsible use of its services."

Alarum emphasized its adherence to Know Your Customer (KYC) protocols, customer due diligence, and ongoing automated network monitoring designed to mitigate unauthorized misuse.

However, competing security intelligence firms dispute the efficacy of these safeguards. In a June report, the proxy-tracking service Spur challenged the reality of these compliance barriers, stating that NetNut does not require meaningful corporate verification before granting proxy access.

"An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in," Spur researchers wrote. "The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies."

Furthermore, Spur highlighted the proliferation of downstream white-label resellers who repackage the NetNut ISP proxy pool with virtually zero regulatory scrutiny. "Anyone who knows where to look can buy access through a reseller with nothing more than a burner email address and $5 in crypto."

Compounding these compliance concerns, Synthient’s analysis of historical Popa builds revealed that while recent iterations incorporate user consent prompts, none of the over 20 genuine Popa publisher applications analyzed from earlier deployments requested or received explicit user permission before installing proxy modules.


The Symbiosis of Proxies and Data Scraping

The commercial intersection between residential proxies and the artificial intelligence sector represents a fundamental shift in web traffic dynamics. As enterprises race to train advanced LLMs, they require continuous, high-volume access to web content.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

As a recent brief from Include Security points out:

"AI companies depend on web-scraped content: for pre-training, for retrieval, for agent grounding, for search. But the modern web isn’t scrapeable from a datacenter. Cloudflare, DataDome, HUMAN, among others throttle or block requests from known cloud IPs. The workaround is residential proxies. A scraping job routed through a Comcast or T-Mobile subscriber’s connection arrives at the target site from an IP that belongs to a paying residential customer."

This aggressive harvesting has catalyzed legal friction, with more than 70 copyright infringement lawsuits filed against major technology firms over the unauthorized use of copyrighted works in AI model training. Simultaneously, public sector organizations, academic repositories, and non-profit digital libraries report severe operational degradation.

A survey conducted by the Confederation of Open Access Repositories (COAR) found that over 90% of participating open-access repositories experience aggressive scraping bot traffic multiple times a week, frequently leading to localized service outages and degraded performance for legitimate academic users. Brendan O’Connell, Platform Manager at the Directory of Open Access Journals (DOAJ), noted that the influx of well-funded AI startups has compounded a practice that was once confined to traditional search engine indexing.


Expanding Vectors: Smart TVs and Corporate Networks

While uncertified Android streaming boxes remain a primary vector, the threat model has expanded into mainstream consumer hardware. Spur’s analysis of application stores for major smart TV manufacturers revealed that approximately 42 percent of applications available on LG’s webOS platform and over 25 percent of apps on Samsung’s Tizen operating system incorporate SDKs capable of converting domestic televisions into always-on proxy nodes.

Security analysts emphasize that standard privacy policy disclosures and remote-controlled consent dialogues are inadequate security controls for shared household environments. Children or guests can easily clear setup prompts without comprehending that their home network is being monetized by commercial entities. Leading streaming platforms such as Amazon and Roku have adopted stringent policies explicitly barring third-party proxy SDKs and scrubbing non-compliant applications from their ecosystems, setting a precedent that LG and Samsung have yet to fully mirror.

The risk profile extends directly into the corporate enterprise. Research published by Infoblox revealed that 65 percent of its enterprise customer base—including sensitive pharmaceutical, food and beverage, government, and banking sectors—regularly queried domains associated with residential proxy networks. This telemetry often stems from employees bringing personal mobile devices, utilizing corporate VPNs, or installing productivity utilities containing hidden monetization SDKs into professional environments.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Infoblox threat researchers Nick Sundvall and David Brunsdon warned of the severe liability this introduces:

"If threat actors were to abuse the residential proxy to attack a third party, the third party’s incident response would, correctly, identify your residential proxy as the source. Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation."

Future Outlook

The convergence of cheap edge hardware, unverified proxy marketplaces, and the insatiable data demands of the artificial intelligence boom has created a systemic blind spot in modern network security. As long as commercial incentives reward the unregulated aggregation of residential IP addresses, botnets like Popa will continue to adapt, mutating through software rebranding, SDK reselling, and domain rotation. Mitigating this threat will require coordinated regulatory intervention, strict enforcement by platform app store operators, and the adoption of enterprise network defenses capable of isolating and neutralizing residential proxy traffic at the corporate perimeter.

Leave a Reply

Your email address will not be published. Required fields are marked *