Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service
- [01] Millions of Android TV boxes have been compromised to facilitate account takeovers and mass scraping efforts.
- [02] Affected systems include various low-cost consumer Android TV boxes running the Popa malware agent.
- [03] Organizations must monitor for suspicious traffic from residential IP ranges and audit consumer hardware environments.
Overview of the Popa Botnet Operation
For over four years, a persistent and sprawling Android-based botnet identified as “Popa” has maintained a silent presence on millions of consumer devices globally. Primarily targeting low-cost Android TV boxes, the botnet functions as a massive relay network, according to Krebs on Security. These compromised devices are utilized to mask the origin of malicious traffic, facilitating advertising fraud, mass data-scraping, and unauthorized account takeovers.
The discovery highlights a growing trend where consumer-grade IoT devices are weaponized to build a C2 infrastructure that is difficult to distinguish from legitimate user activity. By routing traffic through home internet connections, attackers can bypass traditional security filters that typically block known data center IP ranges. This makes the identification of an IoC related to this botnet particularly challenging for a standard SOC.
Technical Analysis: The NetNut Connection
Investigation into the Popa botnet has revealed a direct link to NetNut, a residential proxy provider owned by Alarum Technologies Ltd, a publicly-traded Israeli firm. Researchers from multiple security firms have concluded that the malware installed on these TV boxes allows NetNut to sell the home IP addresses of unsuspecting consumers as part of its “residential proxy” service.
This infrastructure is not a result of a CVE in a specific protocol but rather the intentional installation of a hidden proxy agent. The malware often arrives pre-installed on off-brand devices or is delivered via malicious firmware updates. Once active, the device becomes a node in a global network. When a NetNut customer requests a residential IP, the traffic is tunneled through the Popa-infected device, making the request appear to originate from the consumer’s home network.
How to detect Popa botnet traffic
Security professionals can identify potential botnet activity by analyzing outbound traffic patterns from local networks. To effectively manage this threat, SIEM platforms should be configured to flag high-volume, repetitive HTTPS requests originating from non-traditional computing devices like TV boxes. Monitoring for unusual DNS queries to subdomains associated with known residential proxy providers is another effective method for identifying infected hardware. Defenders should map these activities against the MITRE ATT&CK framework, specifically focusing on the use of proxy techniques for defense evasion.
NetNut residential proxy security risks
The integration of botnets into legitimate business models presents significant NetNut residential proxy security risks for enterprises. Because these proxies provide a high degree of anonymity, they are frequently used for credential stuffing and large-scale scraping of sensitive pricing or user data.
When a threat actor, such as an APT or a financial crime group, utilizes a residential proxy, they effectively neutralize geo-fencing and rate-limiting protections. This allows them to conduct operations that look like legitimate localized traffic, complicating the job of automated fraud detection systems. The fact that this infrastructure is allegedly maintained by a publicly-traded entity underscores the ethical and legal complexities surrounding the residential proxy market.
Android TV box malware mitigation
Mitigating the threat posed by the Popa botnet requires a combination of network segmentation and hardware vetting. Organizations and consumers should implement Android TV box malware mitigation strategies by placing these devices on isolated guest networks. This prevents the botnet from being used for Lateral Movement within a corporate or home environment if the device is compromised.
Furthermore, IT departments should strictly control the procurement of Android-based peripherals. Devices should only be purchased from reputable manufacturers with transparent software supply chains. In cases where devices are already deployed, monitoring for unauthorized firmware updates and restricting outbound internet access to only necessary services can reduce the risk of a device being co-opted into a proxy network.
Advertisement