# Popa Botnet Linked to Public Israeli Firm

> The Popa botnet infecting millions of IoT devices is connected to a publicly-traded Israeli company, raising serious questions about corporate accountability in cybercrime.

**URL:** https://www.ciptadusa.com/blog/popa-botnet-linked-public-israeli-firm-20260619  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-06-19  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-06/daily-appsec-20260619-014643.jpg  

## Article

A botnet named Popa has been linked to a publicly-traded Israeli company. An investigation by Krebs on Security reveals an illegal residential proxy network exploiting consumer IoT devices without their owners' knowledge.

## Summary

The Popa botnet infecting millions of IoT devices is connected to a publicly-traded Israeli company, raising serious questions about corporate accountability in cybercrime.

## Challenge

Residential botnets are increasingly difficult to detect because their traffic resembles normal user activity. Popa, an evolution of the Vo1d botnet, infects smart TVs, set-top boxes, and cheap Android devices through firmware compromised at the factory level.

The most striking finding from this investigation is the involvement of Alarum Technologies Ltd, a public company operating through its subsidiary NetNut as a proxy service provider. This demonstrates that botnet infrastructure is not always operated by hidden criminal actors — sometimes corporate entities profit from it as well.

## Implications

This case has broad impact on the security ecosystem:

1. **IoT supply chain risk** — cheap devices from irresponsible manufacturers can become botnet nodes from day one
2. **Residential proxies as gray-area business** — the line between legal proxy services and botnet networks grows blurrier
3. **Regulation needs strengthening** — a public company involved in botnet infrastructure reveals significant regulatory gaps

For organizations in Indonesia, this serves as a reminder of the importance of IoT device auditing and strict network segmentation.

## CDS Perspective

PT Cipta Dua Saudara places application security as a top priority in every project. In developing Portal Desa Mekarharja, our team implements network segmentation and traffic monitoring to prevent compromised devices from accessing sensitive data. The Popa case reinforces our approach that security must start at the infrastructure level, not just the application layer.

## References

- [Krebs on Security: Popa Botnet Linked to Publicly-Traded Israeli Firm](https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/)
- [Lumen Black Lotus Labs Research](https://blog.lumen.com/black-lotus-labs/)
- [NIST IoT Security Guidelines](https://www.nist.gov/iot)

---

*Markdown version of https://www.ciptadusa.com/blog/popa-botnet-linked-public-israeli-firm-20260619 — generated for AI agents and LLM crawlers.*
