Find notable cyber news and cases, enriched with sources, timelines, and signals.

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
First reported
Last updated
Happening score
H score 88
2 unique sources, 2 articles

Summary

Hide ▲

NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residential proxy exit nodes. A Google report said at least 316 distinct threat clusters used the infrastructure in June 2026 for password-spraying, credential stuffing, advertising fraud, and sensitive data scraping. Google and the FBI moved to disrupt the network with account disables, Play Protect warnings, app blocks, and domain action, and Google said the measures caused significant degradation to the proxy network and business operations.

Related Happenings

FBI seizure of NetNut proxy domains

Law Enforcement
H score33 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

How related: In response to the seizure of certain domains associated with NetNut by the FBI, Alarum Technologies issued the following statement: “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”

About this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...

FBI seizes NetNut and Popa botnet domains

Law Enforcement
H score34 First: 02.07.2026 22:27 Last: 02.07.2026 22:27 Sources 1

About this happening: The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. Th...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

AryStinger legacy-router and QNAP NAS reconnaissance campaign

Campaign
H score72 First: 22.06.2026 09:57 Last: 22.06.2026 09:57 Sources 1

About this happening: The AryStinger campaign is turning legacy routers and QNAP NAS boxes into a distributed reconnaissance and proxy network, creating a stealth relay layer for intrus...

Popa botnet forcing consumer TV boxes to relay traffic

Malware Activity
H score76 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

How related: At the heart of the NetNut residential proxy service was the Popa botnet, an engineered stealth communications layer.

About this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...

Latest development: 03.07.2026 12:35

Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.

Timeline

  1. 03.07.2026 12:35 1 articles · 12d ago

    Google and FBI disrupt NetNut proxy infrastructure

    Mitigation Patch Update

    Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

    Show sources
  2. 18.06.2026 03:00 2 articles · 28d ago

    Researchers link the Popa Android botnet to NetNut

    Attribution Update

    Researchers linked the Popa Android botnet, a plugin component associated with Vo1d-style malware targeting unofficial Android-based TV boxes, to NetNut/Alarum Technologies and said the infrastructure has been used for advertising fraud, account takeovers, and mass data scraping. The analysis also pointed to control domains including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io, while Alarum Technologies disputed the characterization and said the SDKs are designed for bandwidth-sharing rather than malware control.

    Show sources