Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
Summary
Hide ▲
Show ▼
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand to route traffic through residential IPs. The activity has persisted for four years and has been used for advertising fraud, account takeovers, and mass data scraping, with recent reporting tying the broader NetNut proxy network to abuse by at least 316 threat clusters in June 2026. Google and the FBI moved against the infrastructure on July 2-3, 2026, disabling accounts, warning Android users, and disrupting apps and domains linked to the proxy network. The disruption reduced the available pool of devices and degraded the operator’s proxy business, while leaving room for attribution confusion around the network’s commercial branding and domain structure.
Related Happenings
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
How related:
In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementHow related: In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”
About this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
How related:
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementHow related: The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].
About this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
AryStinger legacy-router reconnaissance and proxy network
Malware Activity
H score61
First: 22.06.2026 09:57
Last: 22.06.2026 09:57
Sources 1
About this happening:
The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
AryStinger legacy-router reconnaissance and proxy network
Malware ActivityAbout this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
How related:
Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignHow related: Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.
About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Timeline
-
03.07.2026 12:35 2 articles · 12d ago
Google and FBI move against NetNut proxy infrastructure
Mitigation Patch UpdateGoogle disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Show sources
- FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors — www.infosecurity-magazine.com — 03.07.2026 12:35
- FBI Seizes NetNut Proxy Platform, Popa Botnet — krebsonsecurity.com — 02.07.2026 22:27
-
18.06.2026 20:37 2 articles · 27d ago
Popa botnet forcing consumer TV boxes to relay traffic
Initial DisclosureThe activity began as a persistent Android botnet layer on consumer TV boxes and developed into a large relay network for fraud and scraping. Its core function is to register devices, maintain encrypted connectivity, and open tunnels on demand.
Show sources
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm — krebsonsecurity.com — 18.06.2026 20:37
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm — krebsonsecurity.com — 18.06.2026 20:37