Cyber — 2026-06-19
Popa Botnet Linked to Israeli Firm Alarum Technologies Forces Millions of Devices Into Proxy Network
BLUFConverging forensic evidence tying a multimillion-device proxy botnet to a NASDAQ-listed firm creates acute securities-disclosure exposure, though a formal US or Israeli regulatory inquiry within 90 days of the June 18 publication remains unlikely.
Four coordinated reports published June 18 by Qurium, Synthient, Nokia Deepfield, and KrebsOnSecurity linked the Popa Android proxy botnet to NetNut, operated by publicly-traded Alarum Technologies (NASDAQ: ALAR) 1234. Lumen's Black Lotus Labs estimates the active pool at 1.5 to 2.5 million IP addresses daily; Nokia Deepfield, monitoring 26 of at least 359 relay nodes, recorded 750,000 unique sources in 24 hours and assessed the total population may be far higher 14. In a June 17 controlled test, Synthient captured outbound Popa traffic egressing through NetNut's commercial gateway and found none of more than 20 analyzed publisher apps invoking the SDK's consent prompt before enrolling devices 2. Qurium traced the ninjatech.io C2 domain to Moshe Yehuda Kramer, publicly identified as NetNut's SVP of R&D; Kramer denied operating the infrastructure, and Alarum called the botnet characterization "demonstrably inaccurate" 13.
AnalysisThe NASDAQ listing makes the disclosure a securities compliance question: counsel must assess whether converging independent forensics constitute material information requiring a public filing. A formal FTC or Israeli regulatory inquiry within 90 days is
unlikely. Both agencies have operated on multi-year timescales in prior residential-proxy cases, and Alarum's SDK-licensing defense imposes an evidentiary burden regulators must clear before opening a docket. Moderate confidence reflects a convergent forensic record but no named complainant or open docket. NetNut's SDK may have been licensed to resellers who embedded Popa without corporate sanction, leaving controlled-test egress attributable to downstream customers. If an inquiry opens, enterprise teams routing workloads through NetNut face immediate vendor-risk remediation; if the 90-day window closes without action, procurement risk stays reputational.
4 sources
- Popa Botnet Linked to Publicly-Traded Israeli Firm - Krebs on Security
- Popa: From Sourcing to Distribution - Synthient
- Finding "Popa": When Your Smart TV Stops Being Yours - Qurium Media Foundation
- RoboVPN and Neunative: Linking Alarum/NetNut Infrastructure to the Popa Ecosystem - Nokia Deepfield
View in full brief →