<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm]]></title><description><![CDATA[<p>New, from me: 'Popa' Botnet Linked to Publicly Traded Israeli Firm</p><p>"For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]."</p><p><a href="https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/" rel="nofollow noopener"><span>https://</span><span>krebsonsecurity.com/2026/06/po</span><span>pa-botnet-linked-to-publicly-traded-israeli-firm/</span></a></p><p>There is an incredible amount of interesting data and findings in the reports on Popa released this week. For example, the proxy detection service Spur told me they recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found.</p><p><a href="https://infosec.exchange/tags/proxy" rel="tag">#<span>proxy</span></a> <a href="https://infosec.exchange/tags/popa" rel="tag">#<span>popa</span></a> <a href="https://infosec.exchange/tags/botnet" rel="tag">#<span>botnet</span></a> <a href="https://infosec.exchange/tags/lg" rel="tag">#<span>lg</span></a> <a href="https://infosec.exchange/tags/samsung" rel="tag">#<span>samsung</span></a></p>]]></description><link>https://forum.fedi.dk/topic/988f849f-5c64-46a1-9ba5-92d3eef8cd44/new-from-me-popa-botnet-linked-to-publicly-traded-israeli-firm</link><generator>RSS for Node</generator><lastBuildDate>Mon, 22 Jun 2026 14:22:46 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/988f849f-5c64-46a1-9ba5-92d3eef8cd44.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 18 Jun 2026 17:51:48 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 22:33:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/magnesium%40infosec.exchange">@<span>magnesium</span></a></span> <span><a href="/user/aakl%40infosec.exchange">@<span>AAKL</span></a></span> <span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Is there a country where it does ? Jurisdiction farming isn't solely for the rich corporates</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/etchedpixels/statuses/116773486233615487</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/etchedpixels/statuses/116773486233615487</guid><dc:creator><![CDATA[etchedpixels@mastodon.social]]></dc:creator><pubDate>Thu, 18 Jun 2026 22:33:14 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 21:45:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> super-interesting, thanks. </p><p>What is the residential proxy network Popa used for explicitly? Like you mentioned; possible uses would be ad fraud, cryptography, ddos attacks etc.</p><p>Is Popa linked to IP Royal or another proxy site? This raises serious questions for the Data Protection Commissioner in Europe i'd imagine...</p><p>Is the open-proxy hijacking of your tv system clearly spelled out in the terms and conditions of these apps? What does their privacy policy say?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.ie/ap/users/116760152496243117/statuses/116773299045979030</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.ie/ap/users/116760152496243117/statuses/116773299045979030</guid><dc:creator><![CDATA[handi@mastodon.ie]]></dc:creator><pubDate>Thu, 18 Jun 2026 21:45:38 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 19:50:56 GMT]]></title><description><![CDATA[<p><span><a href="https://c.im/@GilQ">@<span>GilQ</span></a></span> thanks, Gil!</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/briankrebs/statuses/116772848010758174</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/briankrebs/statuses/116772848010758174</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 19:50:56 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 19:31:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span><br />Tired: The Chinese are spying on everybody via their TVs.<br />Wired: The Israelis are spying on everybody via the Chinese TVs.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/bontchev/statuses/116772772341731040</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/bontchev/statuses/116772772341731040</guid><dc:creator><![CDATA[bontchev@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 19:31:41 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 19:22:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/aakl%40infosec.exchange">@<span>AAKL</span></a></span> <span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> I wish case law supported suing for gross negligence in the IT hardware and Software space, but it clearly does not, and thus we have vulnerability backlogs in the thousands of known issues and hundreds of thousands of undocumented vulnerabilities awaiting discovery</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/magnesium/statuses/116772737260269942</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/magnesium/statuses/116772737260269942</guid><dc:creator><![CDATA[magnesium@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 19:22:46 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 19:09:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />Thank you.  I have posted your article into our Discord.  <a href="https://c.im/tags/iptv" rel="tag">#<span>iptv</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://c.im/users/GilQ/statuses/116772683195070997</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://c.im/users/GilQ/statuses/116772683195070997</guid><dc:creator><![CDATA[gilq@c.im]]></dc:creator><pubDate>Thu, 18 Jun 2026 19:09:01 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 19:04:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />I get lost in the weeds quickly when it comes to cyber security, but even I can grasp the gist of this. I think I'll unplug the living room TV that I almost never turn on. A woman's home is no longer her castle, she has to share it with spiders and other creepy crawlies. I already unplug the Bluetooth speaker when I'm no using it.</p>]]></description><link>https://forum.fedi.dk/post/https://sfba.social/users/Puck/statuses/116772663838137166</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://sfba.social/users/Puck/statuses/116772663838137166</guid><dc:creator><![CDATA[puck@sfba.social]]></dc:creator><pubDate>Thu, 18 Jun 2026 19:04:05 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 18:24:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Customers should probably sue Samsung and LG for this.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/AAKL/statuses/116772508614151234</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/AAKL/statuses/116772508614151234</guid><dc:creator><![CDATA[aakl@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 18:24:37 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 18:22:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/dirkhh%40hachyderm.io">@<span>dirkhh</span></a></span> if they're doing DoH and use some smart TLS-fronting strategies, it might be close to impossible to block while maintaining regular online functionality.</p><p>If...</p><p> <span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/eliasp/statuses/116772498585794133</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/eliasp/statuses/116772498585794133</guid><dc:creator><![CDATA[eliasp@mastodon.social]]></dc:creator><pubDate>Thu, 18 Jun 2026 18:22:04 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 18:17:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />Is it possible to shut these proxies down at a firewall or via DNS filtering?<br />My Tizen TV does a lot of network accesses when turned on (which is why I actually cut the power to it when not in use...) and I'm not sure what I would be looking for to see if somehow I got affected by this?</p>]]></description><link>https://forum.fedi.dk/post/https://hachyderm.io/users/dirkhh/statuses/116772479410827361</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://hachyderm.io/users/dirkhh/statuses/116772479410827361</guid><dc:creator><![CDATA[dirkhh@hachyderm.io]]></dc:creator><pubDate>Thu, 18 Jun 2026 18:17:11 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 18:16:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/aakl%40infosec.exchange">@<span>AAKL</span></a></span> certainly that is one aspect of it. It is how the proxy companies are all recasting themselves and trying to wash their reputation by association with scraping for AI stuff. Like they're now critical infrastructure or something. Anyway, there's an entire section of the story on this codependency.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/briankrebs/statuses/116772477277859553</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/briankrebs/statuses/116772477277859553</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 18:16:39 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 18:03:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> This might be off the mark, but I'm wondering if this is more about data scraping than anything else, given the recent trends and Android's prevalence in related regions.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/AAKL/statuses/116772424456336076</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/AAKL/statuses/116772424456336076</guid><dc:creator><![CDATA[aakl@infosec.exchange]]></dc:creator><pubDate>Thu, 18 Jun 2026 18:03:13 GMT</pubDate></item><item><title><![CDATA[Reply to New, from me: &#x27;Popa&#x27; Botnet Linked to Publicly Traded Israeli Firm on Thu, 18 Jun 2026 17:57:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Wow</p>]]></description><link>https://forum.fedi.dk/post/https://cyberplace.social/users/khleedril/statuses/116772401696925111</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://cyberplace.social/users/khleedril/statuses/116772401696925111</guid><dc:creator><![CDATA[khleedril@cyberplace.social]]></dc:creator><pubDate>Thu, 18 Jun 2026 17:57:25 GMT</pubDate></item></channel></rss>