‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
A sprawling Android botnet called Popa, used for advertising fraud, account takeovers, and data scraping, has been linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd. Researchers discovered a connection through multiple security firms, including XLAB and Qurium, who traced the botnet’s activity and identified key domains. The investigation revealed that NetNut’s vice president of R&D, Moishi Kramer, was involved in the development of the Popa SDK, but claims no current involvement in its operation. This highlights the potential for commercially available tools to be repurposed for malicious activities and underscores the risks associated with compromised streaming devices.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
