news.mlab.sh
Back to the feed
threat-intel

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

High
Image: Krebs on Security
Summary

A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovered a connection through multiple security firms, including XLAB and Qurium, who traced the botnet’s activity and identified key domains. The investigation revealed that NetNut’s vice president of R&D, Moishi Kramer, was involved in the development of the Popa SDK, but claims no current involvement in its operation. This highlights the potential for commercially available tools to be repurposed for malicious activities and underscores the risks associated with compromised streaming devices.

Read the full article at Krebs on Security

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.