logo

'Popa' Botnet Linked to Publicly-Traded Israeli Firm

ID: e374e17b-03d9-5c5b-bd60-c666c3817327

STIX ID: report--e374e17b-03d9-5c5b-bd60-c666c3817327

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

...
...

The Popa botnet is a large-scale Android malware operation that has enslaved millions of consumer streaming and smart TV boxes over multiple years, turning them into an anonymous residential proxy network used for advertising fraud, credential stuffing/account takeovers, and large-scale web scraping; researchers attribute the botnet backend to a publicly-traded Israeli technology company and the investigation remains ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.