ctipilot.ch

Popa residential-proxy botnet

campaign · campaign:popa-vo1d-residential-proxy-botnet

Residential-proxy botnet built on a Vo1d plugin, tied to Alarum/NetNut by Krebs and Qurium reporting.

Aliases: NetNut, Popa

Coverage timeline
3
first 2026-06-21 → last 2026-07-05
Peak priority
notable
3 notable
Sources cited
7
5 hosts
Sections touched
3
research, updates, weekly-incidents-recap
Co-occurring entities
1
see Related entities below
ATT&CK techniques
4
pinned v19.1 · see below
2026-06-213 appearances2026-07-05

ATT&CK techniques

4 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi · ATT&CK page ↗

Impact TA0040

T1496Resource Hijacking×1

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

Story timeline

  1. 2026-07-05Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews
    weekly-incidents-recapDisruption momentum this week — NetNut proxy botnet dismantled, StegoAd extensions killed, $10M bounty
  2. 2026-07-04Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet
    updatesGoogle/FBI-led action degrades NetNut (Popa) — ~2 million Badbox 2.0-infected TVs and streaming boxes cut off
  3. 2026-06-21Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor
    research

Where this entity is cited

  • research1
  • updates1
  • weekly-incidents-recap1

Source distribution

  • attack.mitre.org2 (29%)
  • krebsonsecurity.com2 (29%)
  • bleepingcomputer.com1 (14%)
  • cloud.google.com1 (14%)
  • qurium.org1 (14%)

Related entities

Entries about Popa residential-proxy botnet (3)

2026-07-05 · view entry permalink →

NOTABLE

Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews

Three disruption actions this week are worth consolidating not as wins to celebrate but for what each says about the durability of the abused technique.

NetNut (Popa) residential-proxy botnet dismantled. The FBI — with Google, Lumen and Shadowserver — seized NetNut/Popa infrastructure on 2026-07-02; Google disabled the Google accounts used for C2 and updated Play Protect to block apps bundling the malicious SDKs, while the FBI seized netnut.com (Google GTIG, 2026-07-02; Krebs on Security, 2026-07-02). The strategic figure GTIG surfaces is that in a single June week it observed 316 distinct threat clusters — criminal and suspected-espionage — routing traffic through suspected NetNut exit nodes to mask origin IPs during password-spray, credential-stuffing and infrastructure access. That confirms residential-proxy relay as shared criminal/state infrastructure, and Google's own caution is the key defender note: degraded operators buy capacity from rivals, so proxy-based anonymisation volumes shift providers rather than dropping (§ references, operational coverage 07-04).

StegoAd extension cluster. Microsoft disrupted StegoAd — 119 Edge extensions that hid payloads inside image and font files via steganography (campaign:stegoad-darkspectre-119-edge-extensions-steganography) — reinforcing browser-extension marketplaces as a recurring, disruptable delivery surface (this week's operational coverage, § references).

$10M bounty on Russia-nexus crews. The US added a $10M bounty on the Russia-nexus Signal/WhatsApp phishing crews and folded Signal Backup-Recovery-Key theft into the advisory (this week's operational coverage, § references).

Weekly takeaway: all three targets abuse infrastructure that is cheap to re-provision — residential proxies, browser extensions, messaging-app social engineering — so the correct posture for a SOC is to keep the behavioural detections (implausible residential-ASN auth sequences, extension-install governance, Signal backup-key hygiene for high-risk staff) running past the headlines, because the operators displaced this week reappear behind new providers. This week's Mustang Panda dead-drop-C2-via-Zoho-WorkDrive case (§ references) is the same lesson from the offensive side: abuse of legitimate, hard-to-block infrastructure is the through-line.

In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.

Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world.

Google Cloud (GTIG)

Builds on: 2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi · 2026-06-30/microsoft-disrupts-stegoad-119-edge-extensions-hid-payloads · 2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew · 2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe

incident05 Jul 23:33Zmulti-sourceOpen finding ↗

2026-07-04 · view entry permalink →

NOTABLEupdate

Google, FBI, Lumen and Shadowserver disrupt the NetNut (Popa) residential-proxy botnet

UPDATE · originally covered Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor (2026-06-21)

Google's Threat Intelligence Group, coordinating with the FBI, Lumen Technologies and The Shadowserver Foundation, has disrupted the residential-proxy botnet previously tracked here as Popa — Google refers to it as NetNut — which GTIG estimates controls at least 2 million infected devices worldwide, predominantly Android-based smart TVs and streaming/set-top boxes compromised via trojanized apps carrying the Badbox 2.0 malware family (Google Threat Intelligence Group, 2026-07-02). Google disabled the Google accounts and infrastructure used for NetNut command-and-control, shared technical intelligence with ecosystem partners, and used Google Play Protect to block apps bundling NetNut SDKs, while the FBI separately seized the netnut.com domain (BleepingComputer, 2026-07-03).

The delta since June is the scale of shared abuse the disruption exposes: GTIG reports that in a single week in June 2026 it observed 316 distinct threat clusters — spanning both cybercriminal and espionage actors — routing traffic through suspected NetNut exit nodes to hide malicious activity behind residential IP space (T1090.003 Multi-hop Proxy), confirming this proxy layer as shared criminal/state infrastructure rather than a single-group tool. Google cautions that the action reduced the operator's available device pool "by millions" but that individual proxy operators can appear resilient and rival operators may absorb displaced capacity.

Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world.

In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.

Google Threat Intelligence Group 2026-07-02
incident04 Jul 00:26Zmulti-sourceOpen finding ↗

2026-06-21 · view entry permalink →

NOTABLE

Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor

Krebs on Security and the Qurium Media Foundation jointly documented Popa, a residential-proxy botnet that has run on millions of Android-based consumer TV boxes for roughly four years, operating as a plugin component of the larger Vo1d botnet (Krebs on Security, 2026-06-18). The botnet monetises infected devices by relaying advertising fraud, account-takeover traffic and AI data-scraping through residential IP space so the traffic appears to originate from ordinary home users. Qurium's forensic tracing of several dozen control domains found infrastructure operated in lockstep with NetNut — a "residential proxy" service tied to publicly-traded Alarum Technologies (NASDAQ: ALAR) — via the NinjaTech entity and a shared neonative library (Qurium, 2026-06-18). Propagation is through thousands of malware-laced pirated streaming and torrent apps reaching unofficial Android TV hardware. Per the fake-news guard, this is the researchers' documented corporate-infrastructure linkage — Alarum has not been charged with any offence, and the legal characterisation of the proxy traffic is unresolved; attribute the connection to Krebs/Qurium rather than asserting it as adjudicated fact.

Why it matters to us: Residential-proxy traffic is hard to block without collateral damage, and it inverts a common SOC assumption — an authentication attempt arriving from a "residential" ASN may be proxy-relayed attack traffic, not a geographic-targeting signal. Practical posture for a public-sector SOC: flag authentication events from residential ASNs that are anomalous for your user population, watch for consumer Android-TV IP ranges touching sensitive portals (those devices have no business authenticating to corporate services), and treat residential-proxy provider ranges as a credential-stuffing source against citizen-facing portals. Maps to T1090.002 Proxy: External Proxy and T1496 Resource Hijacking.

research21 Jun 04:55Zmulti-sourceOpen finding ↗