Popa is an Android-focused proxyware malware family and botnet component that covertly enrolls consumer devices into a residential proxy network. It has been observed on Android TV boxes, streaming devices, smart TVs, phones, tablets, and in some cases desktop systems through bundled SDK components in third-party software. Rather than acting primarily as a destructive payload, Popa functions as a communications and tunneling layer that registers infected or enrolled devices with backend infrastructure, maintains encrypted sessions, and relays third-party traffic through the victim’s residential connection on demand.
Popa is widely described as a plugin or networking module associated with the Vo1d ecosystem and has also been linked to the broader Badbox-related device compromise landscape. Related labels and variants reported by researchers include Moneytiser, Loopop, Neupop, and Neunative, which appear to represent closely related SDK or client implementations sharing backend infrastructure and protocol design. The malware has also been referred to as part of a larger operational ecosystem sometimes called Popanet.
Its core behavior is to transform a victim device into a proxy exit node. After registration, the backend can instruct the device to open tunnels to arbitrary external destinations and forward bidirectional traffic. Reported protocol features include device registration, keepalive messaging, tunnel creation, message forwarding, and tunnel teardown. Multiple analyses describe a proprietary tunnel protocol and relay architecture designed to scale a large residential proxy service using compromised or deceptively enrolled consumer devices.
Infection and deployment vectors include preloaded compromise on unofficial Android-based TV boxes, malicious or trojanized streaming and IPTV applications, compromised smart-TV applications, modified consumer software, and bundled SDKs inside products such as VPN or torrent-related applications. Researchers have repeatedly found that affected applications often did not present meaningful consent to users before enabling bandwidth sharing or proxy functionality, even where the SDK family included optional consent-related code paths.
Popa-enabled infrastructure has been associated with advertising fraud, account takeover activity, password spraying, large-scale web scraping, credential abuse, and concealment of cybercriminal and espionage operations behind legitimate residential IP space. Researchers have also warned that weak destination filtering in related client implementations could expose local or adjacent network services, increasing the risk that enrolled devices become stepping stones for further compromise.
The malware has operated at very large scale, with public estimates placing the population in the millions of devices globally. It has been observed across hundreds of countries and has been tied to extensive relay infrastructure and widespread abuse by criminal and state-linked users of residential proxy services.
Multiple independent investigations have linked Popa technically and operationally to the commercial residential proxy service NetNut and to infrastructure associated with Alarum Technologies, primarily through shared backend patterns, overlapping domains and relay architecture, common SDK lineage, and controlled observations of traffic exiting through NetNut-linked proxy infrastructure. Public reporting also noted historical associations involving NinjaTech. NetNut and Alarum have disputed characterizations that describe the ecosystem as a botnet or unauthorized malware operation, but the technical reporting consistently supports a close relationship between Popa-enrolled devices and commercial residential proxy services built on the same backend.
In 2025 and 2026, industry and law-enforcement actions disrupted portions of the infrastructure associated with Popa and the related NetNut ecosystem. Those operations reportedly degraded the network significantly by sinkholing or seizing infrastructure, disabling associated services and applications, and reducing the available pool of enrolled devices. Even so, researchers have cautioned that reseller models and successor infrastructure may allow similar residential proxy capacity to re-emerge.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The domains are used to tunnel traffic towards 300+ backend servers hosted in OVH, Hetzner and Akamai.
Many victims unknowingly installed applications that promised payment for “unused bandwidth” or “sharing your internet,” a common lure for these networks.
a customer who tunnels to a node's own 0.0.0.0:5555 reaches the exit device's ADB daemon and recruits it into whatever the operator is building
The binary contains the Popa SDK neonative.dll that is bundled as part of MediaGet... During our review we reviewed dozens of pirate streaming applications that as Flixoid contains the Popa neunative bundle... Smart Tube... versions between 28.56 through 30.51 contained a residential proxy SDK.
The library also contains a fallback mechanism to find new domains using Google Drive.
For each peer server, the SDK opens a TLS connection on port 6000 and speaks a proprietary binary protocol.
Popa is an Android residential proxy SDK that turns host devices into residential proxy nodes... the SDK began relaying third-party traffic at host-app launch without displaying an informed-consent prompt.
Bundled in the same installer, registered as a NuGet dependency, and activated whenever the VPN is not connected, is Neunative: a residential-proxy SDK that turns the user's machine into an exit node for third-party traffic.
The hostnames in peer_servers are rotating front domains. For a single fleet the director returns both sN.viki-play[.]com:6000 and sN.star-layer[.]com:6000 ... The sN identifier and IP are the stable node identity. The domain is disposable.
Each OpenTunnel spawns a dedicated worker thread... The worker resolves the server-supplied target hostname with getaddrinfo, connects, and relays bytes bidirectionally between the peer server and the target.
The library provides control to the backend server to operate “named tunnels” as persistent communication pathways. Inside this tunnels, a TLV (Type-Length-Value) metadata is injected directly into the data packets.
NetNut est identifié comme l’infrastructure commerciale reposant sur le botnet Popa , un réseau d’au moins deux millions d’appareils compromis ... transformés en nœuds de proxy résidentiels permanents sans consentement des victimes ... T1496 — Resource Hijacking (Impact)
88 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Popa is described as an Android proxyware SDK and communications/tunneling layer that turns phones, tablets, and streaming boxes into residential proxy nodes, providing rentable residential egress capacity used to conceal and route abusive or malicious traffic.
A large Android/IoT botnet used as a residential proxy network. It covertly enrolls consumer devices such as smart TVs and streaming boxes as proxy relays so cybercriminals and espionage-linked actors can route activity through residential IP addresses and hide their origin.
A large residential proxy botnet that hijacked consumer devices, especially Android-based smart TVs, streaming boxes, and apps via compromised SDKs, and used them as residential proxy exit nodes to route malicious traffic for abuse such as password spraying, credential stuffing, ad fraud, and data scraping.
Botnet used to compromise smart TVs and Android streaming boxes and convert them into persistent residential proxy nodes that are rented out for scraping, ad fraud, account takeover, password spraying, and origin obfuscation for malicious actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.