logo

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

ID: fa435aef-59fe-5995-8a70-c0378ad7b3c3

STIX ID: report--fa435aef-59fe-5995-8a70-c0378ad7b3c3

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: BrianKrebs

...
...

Popa is an Android-based botnet component (distributed via SDKs embedded in pirated streaming apps and TV apps) that turns consumer TV boxes and smart TVs into long-lived residential proxy nodes; researchers from multiple firms link its infrastructure and domains to NetNut/Alarum Technologies. The botnet is used for advertising fraud, account takeovers and large-scale web scraping that has overwhelmed target sites, affects millions of IPs daily, and is actively controlled through rotating domains and relay nodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.