the feed MANY MINDED · THE BRIEF
CONNECTION · friction · impact 5/5 · 2026-07-31

Millions of cheap TV boxes were relaying strangers' traffic

Researchers tie the Popa botnet on Android streaming boxes to NetNut, a proxy provider owned by Nasdaq-listed Alarum.

For four years a botnet called Popa has run on millions of inexpensive Android TV boxes, quietly relaying other people's internet traffic — traffic linked to advertising fraud, account takeovers and mass data scraping. This week researchers at several security firms concluded that Popa feeds NetNut, a residential proxy provider owned by Alarum Technologies, listed on Nasdaq as ALAR.

The boxes are the ordinary kind sold on major e-commerce sites under thousands of brand names, advertising hundreds of streaming services for a single upfront fee. Popa is a component of the Vo1d campaign targeting them, and its job is narrow: register the device and keep an encrypted tunnel open on demand. Qurium traced dozens of control domains after scraping attacks in May 2026 spread evenly across more than 1.4 million internet addresses. One domain, ninjatech.io, predated the July 2025 takedown of the related Badbox 2.0 network by Google, HUMAN Security and Trend Micro, and belongs to a company founded by NetNut's vice president of research and development. Synthient says traffic from devices running the Popa SDK carries NetNut client markers.

The attribution is disputed. The engineer says his company ceased operations about five years ago after licensing a consent-gated bandwidth-sharing SDK to third parties, and that he neither runs nor can see the current infrastructure. Alarum rejects the botnet framing outright, describing the software as consented bandwidth sharing backed by KYC checks and misuse monitoring — though a separate report from Spur asserts NetNut requires no meaningful customer verification.

This is the hidden invoice on cheap hardware. The box is cheap because the buyer's home connection is the product, and an unvetted proxy network can put a stranger inside a household network.

Source: Krebs on Security