CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 131

As cited

Copy frozen at (site build).

threat intel

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.

Why it matters: Organizations and individuals whose networks are being actively harvested by botnet-compromised devices face data scraping threats and lateral network attacks; security teams should audit unauthorized proxy traffic and TV box deployments on corporate and home networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.

Why it matters: Organizations and individuals whose networks are being actively harvested by botnet-compromised devices face data scraping threats and lateral network attacks; security teams should audit unauthorized proxy traffic and TV box deployments on corporate and home networks.

VendorsGoogleAdobeTrend Micro
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary