Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
Summary
Hide ▲
Show ▼
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residential proxy exit nodes. A Google report said at least 316 distinct threat clusters used the infrastructure in June 2026 for password-spraying, credential stuffing, advertising fraud, and sensitive data scraping. Google and the FBI moved to disrupt the network with account disables, Play Protect warnings, app blocks, and domain action, and Google said the measures caused significant degradation to the proxy network and business operations.
Related Happenings
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
How related:
In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementHow related: In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”
About this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizes NetNut and Popa botnet domains
Law Enforcement
H score34
First: 02.07.2026 22:27
Last: 02.07.2026 22:27
Sources 1
About this happening:
The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
FBI seizes NetNut and Popa botnet domains
Law EnforcementAbout this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
AryStinger legacy-router and QNAP NAS reconnaissance campaign
Campaign
H score72
First: 22.06.2026 09:57
Last: 22.06.2026 09:57
Sources 1
About this happening:
The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...
AryStinger legacy-router and QNAP NAS reconnaissance campaign
CampaignAbout this happening: The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
How related:
At the heart of the NetNut residential proxy service was the Popa botnet, an engineered stealth communications layer.
About this happening:
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityHow related: At the heart of the NetNut residential proxy service was the Popa botnet, an engineered stealth communications layer.
About this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Timeline
-
03.07.2026 12:35 1 articles · 12d ago
Google and FBI disrupt NetNut proxy infrastructure
Mitigation Patch UpdateGoogle disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Show sources
- FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors — www.infosecurity-magazine.com — 03.07.2026 12:35
-
18.06.2026 03:00 2 articles · 28d ago
Researchers link the Popa Android botnet to NetNut
Attribution UpdateResearchers linked the Popa Android botnet, a plugin component associated with Vo1d-style malware targeting unofficial Android-based TV boxes, to NetNut/Alarum Technologies and said the infrastructure has been used for advertising fraud, account takeovers, and mass data scraping. The analysis also pointed to control domains including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io, while Alarum Technologies disputed the characterization and said the SDKs are designed for bandwidth-sharing rather than malware control.
Show sources
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm — krebsonsecurity.com — 18.06.2026 20:37
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm — krebsonsecurity.com — 18.06.2026 20:37