Popa is an Android-focused proxyware malware family and botnet component that enrolls consumer devices into a residential proxy network and relays third-party traffic through victims’ internet connections. It has been documented on Android TV boxes, streaming devices, phones, and tablets, and has also appeared as an embedded SDK or plugin in modified or compromised applications such as streaming, IPTV, VPN, utility, and torrent software. Popa is widely described as a communications and tunneling layer rather than a full-featured destructive payload, maintaining encrypted connections to backend infrastructure, registering devices, receiving relay assignments, and opening on-demand tunnels for arbitrary traffic forwarding.
Popa has been closely associated with the Vo1d ecosystem and has been observed as a plugin component on unofficial Android-based TV hardware and related apps. Multiple investigations also identified technical overlap between Popa infrastructure and the commercial residential proxy service NetNut, including shared backend patterns, relay architecture, and controlled observations showing traffic from Popa-enrolled devices exiting through NetNut-linked proxy infrastructure. Public reporting has further linked the broader ecosystem to NetNut’s parent company, Alarum Technologies, although Alarum and NetNut have disputed characterizations of the network as a botnet and denied operating unauthorized malware infrastructure.
Operationally, Popa registers infected or enrolled devices with load-balancing controllers, receives lists of relay servers, and uses a proprietary tunnel protocol to proxy traffic bidirectionally. Researchers have reported that the framework can support persistent named tunnels and forward traffic to arbitrary public destinations. Several analyses found weak or absent safeguards around destination filtering and authentication, increasing the risk that enrolled devices could be abused not only for web scraping and fraud operations but also for access into local or adjacent networks.
Popa has been used at very large scale. Estimates in 2026 placed the network at roughly 1.5 million to more than 2 million compromised or enrolled devices, with daily visibility ranging up to about 2.5 million IPs. Victim devices have been used as residential exit nodes for advertising fraud, account takeover activity, password spraying, credential abuse, and mass data scraping, and the infrastructure has also been used by cybercriminal and espionage-linked actors seeking to conceal origin through residential IP space. The ecosystem has shown resilience through reseller relationships, replacement infrastructure, and multiple related SDK variants, including Moneytiser, Loopop, and Neupop.
Delivery has occurred through preinstalled components on unofficial Android TV boxes, bundled SDKs in consumer applications, and compromised or backdoored apps that activate proxying with little or no meaningful user consent. Some later builds reportedly added optional consent-prompt functionality, but researchers found that publishers commonly did not invoke it. Coordinated disruption actions by law enforcement and industry in 2025 and 2026 targeted associated infrastructure and significantly degraded capacity, but the broader residential-proxy ecosystem around Popa has been assessed as adaptable and capable of partial reconstitution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The domains are used to tunnel traffic towards 300+ backend servers hosted in OVH, Hetzner and Akamai.
Many victims unknowingly installed applications that promised payment for “unused bandwidth” or “sharing your internet,” a common lure for these networks.
a customer who tunnels to a node's own 0.0.0.0:5555 reaches the exit device's ADB daemon and recruits it into whatever the operator is building
The binary contains the Popa SDK neonative.dll that is bundled as part of MediaGet... During our review we reviewed dozens of pirate streaming applications that as Flixoid contains the Popa neunative bundle... Smart Tube... versions between 28.56 through 30.51 contained a residential proxy SDK.
The library also contains a fallback mechanism to find new domains using Google Drive.
For each peer server, the SDK opens a TLS connection on port 6000 and speaks a proprietary binary protocol.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Each OpenTunnel spawns a dedicated worker thread... The worker resolves the server-supplied target hostname with getaddrinfo, connects, and relays bytes bidirectionally between the peer server and the target.
The library provides control to the backend server to operate “named tunnels” as persistent communication pathways. Inside this tunnels, a TLV (Type-Length-Value) metadata is injected directly into the data packets.
NetNut est identifié comme l’infrastructure commerciale reposant sur le botnet Popa , un réseau d’au moins deux millions d’appareils compromis ... transformés en nœuds de proxy résidentiels permanents sans consentement des victimes ... T1496 — Resource Hijacking (Impact)
93 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet de proxies résidentiels à grande échelle avec infrastructure distribuée de serveurs C2 et gateways, perturbé mais explicitement documenté comme composant majeur de l’écosystème.
Popa is described as an Android proxyware SDK and communications/tunneling layer that turns phones, tablets, and streaming boxes into residential proxy nodes, providing rentable residential egress capacity used to conceal and route abusive or malicious traffic.
A large Android/IoT botnet used as a residential proxy network. It covertly enrolls consumer devices such as smart TVs and streaming boxes as proxy relays so cybercriminals and espionage-linked actors can route activity through residential IP addresses and hide their origin.
A large residential proxy botnet that hijacked consumer devices, especially Android-based smart TVs, streaming boxes, and apps via compromised SDKs, and used them as residential proxy exit nodes to route malicious traffic for abuse such as password spraying, credential stuffing, ad fraud, and data scraping.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.