‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
ID: e5adc08e-a51d-5ed4-95f7-e4b7c385783f
STIX ID: report--e5adc08e-a51d-5ed4-95f7-e4b7c385783f
Feed Name: Krebs on Security
Researchers report that the Popa SDK—distributed via pirated Android TV apps and no-name streaming boxes—enrolls consumer devices as long-lived residential proxies used by a large proxy ecosystem; multiple security firms link Popa control infrastructure and outbound traffic to NetNut/Alarum Technologies. The botnet-like deployment affects millions of IPs daily and is leveraged for mass web scraping, ad fraud, and other abusive activity, while vendors dispute the “botnet” label even as domains, traffic patterns, and SDK analysis provide evidence of active misuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
