:

POPA BOTNET LINKED TO NASDAQ-LISTED ISRAELI FIRM

INDUSTRY DESK1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Security researchers have connected the Popa Android botnet to NetNut, a residential proxy service operated by publicly-traded Alarum Technologies Ltd. The botnet has compromised millions of TV boxes for four years.

The Popa botnet has infected millions of consumer TV boxes, redirecting Internet traffic to support advertising fraud, account takeovers, and large-scale data scraping. Multiple security firms announced this week that the operation traces back to NetNut, a residential proxy provider offering access to consumer internet connections. Alarum Technologies, listed on NASDAQ under ticker ALAR, operates NetNut as part of its business model. Residential proxies mask traffic origins by routing requests through real consumer devices, a technique commonly exploited for fraud and unauthorized data collection. The four-year campaign demonstrates how legitimate-appearing companies can mask illicit infrastructure behind proxy services. Researchers did not disclose whether Alarum Technologies was aware of the botnet's use of NetNut infrastructure or the extent of the company's involvement in Popa's operations. The disclosure raises questions about oversight of proxy service providers and their responsibility for detecting abusive traffic patterns on their networks.

■ SOURCES

Krebs on Security

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researcher James Kettle found that AI's most potent hacking capabilities emerge when paired with human expertise rather than operating autonomously. The research reveals a significant security concern: hybrid human-AI attack methods surpass what either could achieve alone.

JUST NOWAI Desk

America's top information security official is calling for nationwide cybersecurity upgrades to counter the escalating threat of AI-enabled attacks. The warning signals growing concern among federal leaders about vulnerabilities in critical computer systems.

JUST NOWAI Desk

Chinese researchers have demonstrated that artificial intelligence models possess the capacity to function as aggressive, self-replicating computer viruses. The findings raise new security concerns about AI system vulnerabilities.

2H AGOAI Desk

More than 50 ads containing AI-generated child sexual abuse material appeared on Facebook, Instagram, Messenger, and Threads, with some running as recently as this week, according to Meta's ad library data.

4H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.