Actor Profile

NetNut is a residential proxy service operated by Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Multiple security researchers have linked NetNut to the Popa Android botnet, which has compromised millions of consumer TV boxes over a four-year period. The actor's motivation appears to be monetization through residential proxy services, leveraging compromised devices to provide anonymized network access for clients while facilitating advertising fraud, account takeovers, and data scraping operations. The commercial nature of the operation, operating under a legitimate corporate structure, distinguishes this actor from traditional APT groups or purely criminal enterprises.

TTPs (Tactics, Techniques, Procedures)

The Popa botnet operation demonstrates TTPs focused on large-scale device compromise and proxy infrastructure abuse. Key techniques include: Initial Access via compromise of consumer Android TV boxes (likely T1195.002 - Compromise Software Supply Chain or T1078 - Valid Accounts for device access); Persistence mechanisms to maintain long-term control over millions of devices; Command and Control through botnet infrastructure managing compromised endpoints as residential proxy nodes; and Resource Hijacking (T1496) to monetize victim bandwidth and IP addresses. The operation enables downstream fraud activities including advertising fraud, credential stuffing for account takeovers (T1110 - Brute Force), and automated data collection (T1213 - Data from Information Repositories). The four-year operational timeline indicates sophisticated OPSEC and infrastructure management.

Targets & Patterns

The primary targets are consumer-grade Android TV boxes, representing a large attack surface of IoT devices with typically weak security controls. The targeting pattern focuses on devices that provide residential IP addresses valuable for proxy services, rather than traditional espionage or financial targets. The selection of TV boxes is strategic: these devices often have always-on internet connectivity, residential network positioning, and minimal security monitoring by end users. The compromised infrastructure serves dual purposes - direct monetization through proxy service sales and enabling third-party fraud operations. Geographic distribution likely spans multiple countries to provide diverse residential IP pools, though the operating company is based in Israel. The victims are primarily individual consumers unaware their devices are participating in a botnet, while downstream impacts affect organizations targeted by fraud campaigns using the proxy network.

Historical Context

The Popa botnet has operated for approximately four years, indicating a sustained and successful campaign that evaded significant detection or disruption. This timeline suggests the operation predates recent increased scrutiny of residential proxy services and their abuse potential. The linkage to a publicly-traded company (Alarum Technologies Ltd, NASDAQ: ALAR) operating under the NetNut brand represents an evolution in proxy service business models, where legitimate commercial entities may leverage compromised infrastructure. This case parallels previous investigations into residential proxy services that obscured their use of compromised devices, including scrutiny of services like Luminati (now Bright Data) and other proxy providers. The multi-year operation and scale of millions of compromised devices positions Popa among the larger Android botnets documented, comparable to operations like HummingBad or Triada in scope, though focused on proxy monetization rather than ad fraud alone.

Defensive Recommendations

  • Monitor outbound network connections from IoT and Android TV devices for suspicious proxy or C2 traffic patterns, particularly persistent connections to known residential proxy service infrastructure
  • Implement network segmentation to isolate IoT devices from critical network segments and monitor for unusual bandwidth consumption or connection patterns indicative of proxy abuse
  • Deploy endpoint detection on Android devices where feasible to identify persistence mechanisms, unauthorized applications, or system modifications associated with botnet malware
  • Conduct threat intelligence correlation against known residential proxy service IP ranges and ASNs associated with NetNut/Alarum Technologies to identify potential compromised devices in your environment
  • Establish baseline behavioral profiles for IoT devices and alert on deviations such as connections to multiple external destinations, unusual traffic volumes, or access patterns inconsistent with legitimate TV box functionality

---

# Geopolitical Context

Geopolitical Context

The reported linkage between NetNut, a residential proxy service operated by Israeli-listed Alarum Technologies, and the Popa Android botnet represents a case study in the commercialization of compromised infrastructure. Residential proxy networks occupy a gray zone in the cybersecurity ecosystem: while marketed for legitimate data intelligence and web scraping, they may rely on devices enrolled without informed consent or through malware. The involvement of a publicly-traded entity (NASDAQ: ALAR) raises questions about corporate governance, regulatory oversight, and the boundaries between lawful proxy services and cybercrime-as-a-service. Israel's advanced technology sector and permissive regulatory environment for cyber firms have historically enabled both offensive cyber capabilities and dual-use commercial services. This incident may prompt scrutiny from U.S. securities regulators and international law enforcement regarding the sourcing practices of residential proxy providers.

State Actor Alignment

No state actor involvement is indicated in the available data. This appears to be a commercial operation by a private Israeli firm. However, the case highlights regulatory gaps in oversight of dual-use cyber services offered by companies in allied jurisdictions. Israeli authorities have historically maintained a light-touch regulatory posture toward cyber firms, balancing economic growth in the technology sector against international pressure for export controls and corporate accountability. U.S. listing on NASDAQ may expose Alarum Technologies to Securities and Exchange Commission disclosure requirements and potential enforcement action if material misrepresentations regarding business practices are identified. The incident does not appear to involve state-sponsored cyber operations, sanctions evasion, or geopolitical targeting.

Business Impacty pro region

For Europe, this case underscores enforcement challenges under the General Data Protection Regulation (GDPR) and the Network and Information Security (NIS2) Directive when compromised devices are monetized by third-party services. European consumer devices enrolled in botnets without consent represent potential violations of data protection and cybersecurity frameworks, yet enforcement against offshore proxy providers remains limited. The incident may accelerate regulatory discussions within the EU regarding transparency requirements for residential proxy networks and liability for downstream abuse. Globally, the Popa botnet's scale—millions of compromised consumer devices over four years—illustrates the persistence of insecure IoT ecosystems, particularly in consumer electronics markets across Asia, Latin America, and emerging economies. The use of compromised infrastructure for advertising fraud, credential stuffing, and data scraping affects digital advertising integrity, e-commerce platforms, and online services worldwide, with economic externalities borne by businesses and consumers rather than the proxy service operators.

Forecast

If regulatory or law enforcement action is initiated against Alarum Technologies or NetNut, it is likely to focus on U.S. securities compliance and potential coordination with Israeli authorities rather than criminal prosecution, given the ambiguity surrounding consent and device enrollment practices. Should evidence emerge of deliberate malware distribution or knowing use of compromised devices, international law enforcement cooperation—potentially involving FBI, Europol, and Israeli National Cyber Directorate—may intensify. In the near term, increased scrutiny of residential proxy providers is probable, with potential impacts on business models reliant on opaque device sourcing. If no enforcement follows, the incident may reinforce perceptions of regulatory arbitrage favoring cyber firms in permissive jurisdictions, potentially prompting unilateral measures by affected states or platform providers to block known proxy networks. The broader IoT security challenge is unlikely to abate without coordinated international standards for device security and supply chain accountability.