Millions of inexpensive streaming boxes sold online under various brand names may be secretly hijacking home internet connections for cybercriminal activity, security researchers warn. The devices, often advertised as offering free movies, live sports, or premium channels for a one-time fee, have been linked to a sprawling Android-based botnet called Popa. This network reportedly forces compromised TV boxes to relay internet traffic tied to ad fraud, account takeovers, and mass data scraping, turning ordinary households into unwitting participants in digital crime.

The Popa botnet is part of a wider ecosystem of compromised Android devices known as Vo1d and BADBOX 2.0, according to reports from KrebsOnSecurity and Lumen's Black Lotus Labs. Unlike traditional botnets designed for quick attacks, Popa operates as a persistent tunneling system. It registers each infected device, maintains encrypted connections, and routes third-party traffic through the device when needed. This means that someone else's internet activity can appear to originate from a victim's home IP address, making it difficult for websites to distinguish legitimate traffic from malicious activity.

Residential proxy networks like the one Popa enables are highly valuable to cybercriminals because they mask the true source of traffic. Instead of coming from a suspicious server farm, requests appear to come from an ordinary household. This technique is used to hide mass web scraping, fake ad clicks, account takeover attempts, and other illicit operations. For the device owner, the consequences can be severe: their IP address could be flagged as the source of illegal activity, potentially leading to investigations or blacklisting by online services.

The scale of the problem is staggering. Lumen's Black Lotus Labs reported that Popa averages between 1.5 million and 2.5 million distinct IP addresses each day. Google previously stated that BADBOX 2.0 compromised more than 10 million uncertified devices running Android open-source software without Google's built-in security protections. These devices include not only TV streaming boxes but also digital projectors, digital picture frames, and other internet-connected gadgets. The FBI has warned that compromised devices can become part of residential proxy services used for criminal activity, urging consumers to be vigilant.

The Popa botnet has also sparked a dispute between security firms and the company accused of being linked to it. Security firms Qurium and Synthient claim that Popa is connected to NetNut, a residential proxy provider owned by Alarum Technologies, a publicly traded Israeli company. Synthient said its analysis found traffic associated with NetNut coming from devices running Popa. Alarum disputes these reports, stating that the claims contain flawed conclusions and rejecting the characterization of its technology as a botnet. The company says its software development kits are designed for bandwidth-sharing with notice, consent, and safeguards. Regardless of the dispute, the core risk for consumers remains: any device that can route someone else's traffic through a home connection without explicit awareness poses a security threat.

The issue extends beyond cheap Android TV boxes. Research from Spur, a proxy-tracking service, found that some smart TV apps include hidden tools that share home internet connections with outside companies. Spur reported that more than 42% of LG webOS apps it reviewed contained such components, and more than 25% of Samsung Tizen apps reviewed had similar features. In response, a Samsung spokesperson told CyberGuy that the third-party residential proxy SDKs recently reported in the media cannot access, collect, or store any personal information from the TV, such as account credentials, viewing history, or personal files. Samsung said it has already restricted new app registrations that include those proxy functions and is implementing strict platform-wide developer policies explicitly banning residential proxy SDKs. The company is also working to identify and remove all apps currently available in its store that contain these components.

For consumers, the safest approach is to be cautious about any streaming device that promises free access to paid content. The FBI lists several warning signs, including devices that require Google Play Protect to be disabled, apps from suspicious sources, or boxes advertised as «unlocked» or «fully loaded» with premium channels. Even seemingly harmless apps on smart TVs can come with permissions or fine print that most users skip. A TV remote makes it easy to click through prompts without reading much, but an app may be able to use a home internet connection in ways the owner never expected. The lesson is clear: the box under the TV may look harmless, but if it came preloaded with sketchy apps or promised too much for too little money, it could be putting the entire home network at risk.

Author

Editorial Writer

Austin Emerson covers public affairs, politics, business, culture and daily news for Boldest Voice. The role focuses on verification, context, and clear explanations for readers.