CTIPilot

Popa residential-proxy botnet

campaign · campaign:popa-vo1d-residential-proxy-botnet

Residential-proxy botnet built on a Vo1d plugin, tied to Alarum/NetNut by Krebs and Qurium reporting.

Aliases: NetNut, Popa

Coverage timeline
1
first 2026-06-21 → last 2026-06-21
Peak priority
notable
1 notable
Sources cited
6
5 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Command and Control TA0011

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

T1090.003Proxy: Multi-hop Proxy×1

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

Impact TA0040

T1496Resource Hijacking×1

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-06-21/krebs-and-qurium-tie-the-popa-android-tv-residential-proxy-b · ATT&CK page ↗

Story timeline

  1. 2026-06-21Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor
    research

Where this entity is cited

  • research1

Source distribution

  • attack.mitre.org2 (33%)
  • bleepingcomputer.com1 (17%)
  • cloud.google.com1 (17%)
  • krebsonsecurity.com1 (17%)
  • qurium.org1 (17%)

explore in graph

Entries about Popa residential-proxy botnet (1)

2026-06-21 · view entry permalink →

NOTABLEupdated

Krebs and Qurium tie the "Popa" Android-TV residential-proxy botnet to a NASDAQ-listed proxy vendor

Krebs on Security and the Qurium Media Foundation jointly documented Popa, a residential-proxy botnet that has run on millions of Android-based consumer TV boxes for roughly four years, operating as a plugin component of the larger Vo1d botnet (Krebs on Security, 2026-06-18). The botnet monetises infected devices by relaying advertising fraud, account-takeover traffic and AI data-scraping through residential IP space so the traffic appears to originate from ordinary home users. Qurium's forensic tracing of several dozen control domains found infrastructure operated in lockstep with NetNut, a "residential proxy" service tied to publicly-traded Alarum Technologies (NASDAQ: ALAR), via the NinjaTech entity and a shared neonative library (Qurium, 2026-06-18). Propagation is through thousands of malware-laced pirated streaming and torrent apps reaching unofficial Android TV hardware. Per the fake-news guard, this is the researchers' documented corporate-infrastructure linkage; Alarum has not been charged with any offence, and the legal characterisation of the proxy traffic is unresolved; attribute the connection to Krebs/Qurium rather than asserting it as adjudicated fact.

Why it matters to us: Residential-proxy traffic is hard to block without collateral damage, and it inverts a common SOC assumption; an authentication attempt arriving from a "residential" ASN may be proxy-relayed attack traffic, not a geographic-targeting signal. Practical posture for a public-sector SOC: flag authentication events from residential ASNs that are anomalous for your user population, watch for consumer Android-TV IP ranges touching sensitive portals (those devices have no business authenticating to corporate services), and treat residential-proxy provider ranges as a credential-stuffing source against citizen-facing portals. Maps to T1090.002 Proxy: External Proxy and T1496 Resource Hijacking.

Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world.

In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.

Google Threat Intelligence Group 2026-07-02
Updaterun 2026-07-04T0009Z-intelactionsentitiesevidencesourcestagsbody

Google's Threat Intelligence Group, coordinating with the FBI, Lumen Technologies and The Shadowserver Foundation, has disrupted the residential-proxy botnet previously tracked here as Popa (Google refers to it as NetNut) which GTIG estimates controls at least 2 million infected devices worldwide, predominantly Android-based smart TVs and streaming/set-top boxes compromised via trojanized apps carrying the Badbox 2.0 malware family (Google Threat Intelligence Group, 2026-07-02). Google disabled the Google accounts and infrastructure used for NetNut command-and-control, shared technical intelligence with ecosystem partners, and used Google Play Protect to block apps bundling NetNut SDKs, while the FBI separately seized the netnut.com domain (BleepingComputer, 2026-07-03).

The delta since June is the scale of shared abuse the disruption exposes: GTIG reports that in a single week in June 2026 it observed 316 distinct threat clusters (spanning both cybercriminal and espionage actors) routing traffic through suspected NetNut exit nodes to hide malicious activity behind residential IP space (T1090.003 Multi-hop Proxy), confirming this proxy layer as shared criminal/state infrastructure rather than a single-group tool. Google cautions that the action reduced the operator's available device pool "by millions" but that individual proxy operators can appear resilient and rival operators may absorb displaced capacity.

research21 Jun 04:55Zmulti-sourceOpen finding ↗