Security researchers have connected the Popa Android botnet to NetNut, a residential proxy service operated by publicly-traded Alarum Technologies Ltd. The botnet has compromised millions of TV boxes for four years.
The Popa botnet has infected millions of consumer TV boxes, redirecting Internet traffic to support advertising fraud, account takeovers, and large-scale data scraping. Multiple security firms announced this week that the operation traces back to NetNut, a residential proxy provider offering access to consumer internet connections.
Alarum Technologies, listed on NASDAQ under ticker ALAR, operates NetNut as part of its business model. Residential proxies mask traffic origins by routing requests through real consumer devices, a technique commonly exploited for fraud and unauthorized data collection.
The four-year campaign demonstrates how legitimate-appearing companies can mask illicit infrastructure behind proxy services. Researchers did not disclose whether Alarum Technologies was aware of the botnet's use of NetNut infrastructure or the extent of the company's involvement in Popa's operations.
The disclosure raises questions about oversight of proxy service providers and their responsibility for detecting abusive traffic patterns on their networks.
The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.
OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.
Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.
Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.