:

POPA BOTNET LINKED TO NASDAQ-LISTED ISRAELI FIRM

INDUSTRY DESK■ 1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security researchers have connected the Popa Android botnet to NetNut, a residential proxy service operated by publicly-traded Alarum Technologies Ltd. The botnet has compromised millions of TV boxes for four years.

The Popa botnet has infected millions of consumer TV boxes, redirecting Internet traffic to support advertising fraud, account takeovers, and large-scale data scraping. Multiple security firms announced this week that the operation traces back to NetNut, a residential proxy provider offering access to consumer internet connections. Alarum Technologies, listed on NASDAQ under ticker ALAR, operates NetNut as part of its business model. Residential proxies mask traffic origins by routing requests through real consumer devices, a technique commonly exploited for fraud and unauthorized data collection. The four-year campaign demonstrates how legitimate-appearing companies can mask illicit infrastructure behind proxy services. Researchers did not disclose whether Alarum Technologies was aware of the botnet's use of NetNut infrastructure or the extent of the company's involvement in Popa's operations. The disclosure raises questions about oversight of proxy service providers and their responsibility for detecting abusive traffic patterns on their networks.

■ SOURCES

► Krebs on Security

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A $357 million hack of crypto exchange Bitget on Thursday is attributed to North Korean hackers, pushing the nation-state's digital-asset thefts past $1 billion this year, according to analytics firm Elliptic Enterprises.

3H AGO— Security Desk

A U.S. Army soldier was sentenced to 70 months in federal prison for hacking AT&T and Verizon and stealing call and text metadata from over 100 million customers. He was also ordered to pay nearly $300,000 in restitution.

4H AGO— Industry Desk

A cross-site request forgery (CSRF) vulnerability in the popular Elementor WordPress plugin could allow unauthenticated attackers to create administrator accounts on affected sites.

7H AGO— Industry Desk

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploits targeting critical vulnerabilities in SharePoint, WSO2, and Adobe Commerce. Attackers are actively leveraging these flaws in real-world attacks.

8H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.