Security researchers have attributed the Popa botnet to NetNut, a residential proxy service operated by Nasdaq-listed Israeli firm Alarum Technologies. The botnet has compromised millions of Android-based consumer TV boxes over the past four years, forcing infected devices to relay traffic for advertising fraud, account takeovers, and large-scale data scraping operations.

Residential proxies mask user activity by routing traffic through legitimate consumer devices, a technique commonly exploited for credential stuffing, ad fraud, and bypassing security controls. NetNut's infrastructure appears to have enabled these attacks at scale by leveraging the Popa botnet's compromised device network.

The scale of the operation reflects a persistent threat in connected device ecosystems. TV boxes running Android represent an attractive target because they sit on home networks with persistent internet connectivity and often lack robust security updates. Once infected, these devices become unwitting proxies for attackers conducting account takeovers against e-commerce platforms, financial services, and content providers.

Alarum Technologies' public listing amplifies the reputational and legal exposure. The company faces potential regulatory scrutiny from securities authorities, law enforcement agencies, and civil liability from victims of fraud campaigns powered by Popa-compromised devices. Multiple security firms naming the connection suggests coordinated disclosure efforts aimed at forcing disclosure and remediation.

The investigation adds Popa to a documented pattern of residential proxy services facilitating fraud. Unlike traditional data centers that flag suspicious behavior, residential proxies appear legitimate because traffic originates from real consumer connections. This legitimacy allows fraudsters to defeat rate-limiting defenses, credential-stuffing protections, and geographic restrictions.

Organizations relying on IP reputation systems should re-evaluate threat intelligence feeds to identify NetNut infrastructure. Financial institutions and e-commerce platforms should strengthen account security around patterns consistent with residential proxy abuse. Device manufacturers must accelerate security patch delivery for Android TV