As cited
Copy frozen at (site build).
threat intel
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.
Why it matters: Organizations and individuals whose networks are being actively harvested by botnet-compromised devices face data scraping threats and lateral network attacks; security teams should audit unauthorized proxy traffic and TV box deployments on corporate and home networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
The Popa Android botnet has compromised millions of consumer TV boxes over four years, forcing them to serve as residential proxies for advertising fraud, account takeovers, and data scraping. Researchers from multiple security firms have linked Popa to NetNut, a residential proxy provider operated by publicly-traded Israeli firm Alarum Technologies, with evidence connecting a Popa control domain (ninjatech.io) to NetNut's vice president of research and development.
Why it matters: Organizations and individuals whose networks are being actively harvested by botnet-compromised devices face data scraping threats and lateral network attacks; security teams should audit unauthorized proxy traffic and TV box deployments on corporate and home networks.
- Source published
- First seen by Cybersecurity Tracker