Find notable cyber news and cases, enriched with sources, timelines, and signals.

Popa botnet forcing consumer TV boxes to relay traffic

Malware Activity
First reported
Last updated
Happening score
H score 76
2 unique sources, 3 articles

Summary

Hide ▲

Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on demand to route traffic through residential IPs. The activity has persisted for four years and has been used for advertising fraud, account takeovers, and mass data scraping, with recent reporting tying the broader NetNut proxy network to abuse by at least 316 threat clusters in June 2026. Google and the FBI moved against the infrastructure on July 2-3, 2026, disabling accounts, warning Android users, and disrupting apps and domains linked to the proxy network. The disruption reduced the available pool of devices and degraded the operator’s proxy business, while leaving room for attribution confusion around the network’s commercial branding and domain structure.

Related Happenings

FBI seizure of NetNut proxy domains

Law Enforcement
H score33 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

How related: In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”

About this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...

FBI seizes NetNut and Popa botnet domains

Law Enforcement
H score34 First: 02.07.2026 22:27 Last: 02.07.2026 22:27 Sources 1

How related: The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].

About this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

AryStinger legacy-router reconnaissance and proxy network

Malware Activity
H score61 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

About this happening: The AryStinger malware family is building a distributed reconnaissance and proxy network from legacy routers and NAS appliances, expanding a covert relay layer that helps...

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

How related: Experts say Popa is a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting unofficial Android-based TV boxes.

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

Timeline

  1. 03.07.2026 12:35 2 articles · 12d ago

    Google and FBI move against NetNut proxy infrastructure

    Mitigation Patch Update

    Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.

    Show sources
  2. 18.06.2026 20:37 2 articles · 27d ago

    Popa botnet forcing consumer TV boxes to relay traffic

    Initial Disclosure

    The activity began as a persistent Android botnet layer on consumer TV boxes and developed into a large relay network for fraud and scraping. Its core function is to register devices, maintain encrypted connectivity, and open tunnels on demand.

    Show sources