Popa: From Sourcing to Distribution

June 19, 2026, 9:43 a.m.

Description

An Android proxyware SDK named Popa enrolls consumer devices including phones, tablets, and streaming boxes into a commercial residential proxy network. Operating since at least 2020, Popa and its variants (Loopop, Neupop, and Moneytiser) are distributed inside consumer streaming, IPTV, and utility applications. The SDK begins relaying third-party traffic at host-app launch without displaying informed-consent prompts in analyzed samples. Multiple variants communicate directly with NetNut SDK endpoints, sharing operational infrastructure and telemetry. Controlled testing showed traffic from Popa-enrolled devices egressing through NetNut's commercial gateway. The SDK uses encrypted Google Drive files to resolve relay servers in later versions. Analysis of over 20 publishers revealed significant links to piracy-related applications, with none observed requesting user consent despite later builds including this capability.

Date

  • Created: June 18, 2026, 7:31 p.m.
  • Published: June 18, 2026, 7:31 p.m.
  • Modified: June 19, 2026, 9:43 a.m.

Indicators

  • bf0b36dcbbc60dbf83ecac7c56534271e53a16817909306ecc6f15f7b6106730
  • bbcc1a208b4bd0a9ffe8799158cd994d82e125acb30b630e774b242f11dd6985
  • 0b4c112c98993f01ed761e72c2f82827aa49876034df461c1762e95281876c6b
  • 2e04dc8bee038a5771373fc4dbaa4e45f653cd649928199e9ce8098c8b27d64e
  • a29cdca72822c1f236c53c181d03f0c45907a45f2ef3c4c2da3ef839bfd3b7a6
  • 68022c244a6cc150395ad3bc6648c30de7c1fa7837498ac101a1824e227efa3a
  • 51ead7f0490bfe6b432120bbbd63b807277d016911664fb264640bb8b007d756
  • 2a6f0837007726a1863f2180a9a84a89284dc57e7557857e2a3d1896a69fe6c7
  • a806cece4a4fbbe502e6d76035681702d9adde1c6f74c9e1c0547d37d30ddfcf
  • ca5fd64932a82d3e24a19fe94d8b7636847f4335b8fd8795a63cfa0107e67048
  • d06b86da3777be0e2156c35f031f503d280a17ee3a1cc531f4c5fb806c0f749b
  • 69f524815eeb3b2069ff41a8a12cae0537de8ad9bd856d694fa21bb2af8fada8
  • 22c860931f2ed22897b81ef8da16980fc24b2573ec884a153b3ff5df9e0f8cff
  • 79aec671ceb205db1769da6898c9659c7c8297b13929e593050523438c09a44f
  • 254568375315d86121b74db2eb8bfd8ac6bf192768c6ab5d05ca7e66b8990102
  • af93524fd0aac0a790734a0747fcf844ba5f0652b11a0f4a59bbe5aeace0fa75
  • b8b8d41a8a7eccda90b366fb5a3d2c0f692504984429aaa19b0af0dcd81dec03
  • 1a92cf241f86584361097d5735948a8170007206db56fe88739c9048767ab862
  • 186.190.215.121
  • 15.235.233.16
  • 67.220.74.119
  • 139.162.174.86
  • 157.90.4.34
  • 38.99.82.188
  • 134.195.198.2
  • 141.95.98.173
  • 172.99.189.20
  • 38.99.82.9
  • 141.95.33.143
  • 135.181.116.42
  • 57.129.39.247
  • 57.128.97.134
  • 158.51.121.39
  • 158.51.121.83
  • 141.95.33.108
  • 141.94.199.151
  • 51.89.11.179
  • 67.220.94.39
  • 162.19.139.106
  • 67.220.70.43
  • 15.235.12.25
  • 38.110.1.157
  • 172.105.19.27
  • 172.99.189.88
  • 65.109.28.33
  • 157.90.4.97
  • 57.129.52.203
  • 158.51.121.30
  • 141.95.98.159
  • 15.235.224.157
  • 141.95.35.97
  • 38.86.135.91
  • 141.95.33.100
  • 134.195.196.245
  • 158.51.121.121
  • 67.220.70.69
  • 51.89.11.246
  • 15.235.85.238
  • 85.90.247.42
  • 57.128.231.167
  • 198.244.165.186
  • 148.113.190.175
  • 38.111.114.193
  • 148.113.220.152
  • 141.94.29.105
  • 146.59.84.15
  • 146.59.81.182
  • 198.244.212.119
  • 67.220.70.142
  • 15.235.85.237
  • 38.22.17.218
  • 141.95.98.158
  • 51.161.86.9
  • 57.128.192.112
  • 51.195.24.3
  • 134.195.198.52
  • 15.235.222.55
  • 57.128.231.196
  • 167.88.61.114
  • 57.129.49.77
  • 141.95.98.176
  • 57.128.125.81
  • 15.235.86.140
  • 51.195.24.6
  • 65.108.9.68
  • 134.195.196.184
  • 198.57.27.30
  • 135.181.61.24
  • 65.21.226.195
  • 67.220.66.55
  • 57.129.96.136
  • 15.235.9.81
  • 216.106.189.33
  • 146.59.81.145
  • 158.51.120.61
  • 141.94.199.152
  • 67.220.94.47
  • 146.59.81.179
  • 15.235.224.224
  • 141.95.98.71
  • 15.235.53.67
  • 135.125.160.44
  • 141.95.98.174
  • 172.99.189.67
  • 37.27.55.79
  • 38.89.70.214
  • 146.59.47.171
  • 162.19.88.205
  • 15.235.82.174
  • 38.114.120.72
  • 141.95.35.96
  • 51.89.11.192
  • 54.38.13.215
  • 194.195.125.168
  • 51.195.24.60
  • 141.95.98.156
  • 141.95.98.175
  • 158.51.121.126
  • 38.22.17.181
  • 51.195.24.11
  • 141.95.98.177
  • 51.195.24.58
  • 67.220.70.91
  • 172.99.188.236
  • 141.95.33.112
  • 216.106.189.146
  • 38.114.120.146
  • 38.114.120.238
  • 57.129.54.85
  • 51.77.190.206
  • 167.17.64.20
  • 141.94.73.20
  • 135.181.18.95
  • 65.109.27.93
  • 38.114.120.39
  • 66.163.117.114
  • 38.22.17.205
  • 66.163.117.132
  • 15.235.228.121
  • 134.195.196.85
  • 148.113.162.52
  • 135.181.61.18
  • 51.222.248.165
  • 15.235.65.97
  • 57.129.39.245
  • 148.113.222.71
  • 135.181.75.30
  • 51.195.24.59
  • 91.134.20.114
  • 141.95.98.164
  • 162.19.88.213
  • 15.235.233.20
  • 146.59.85.8
  • 141.95.33.117
  • 146.59.54.8
  • 162.19.72.85
  • 15.235.85.93
  • 15.235.65.66
  • 57.129.64.89
  • 141.95.126.97
  • 135.181.57.111
  • 149.56.29.107
  • 146.59.54.55
  • 66.228.34.25
  • http://gw.netnut.net:9595

Attack Patterns

  • Popa
  • Hopanet
  • Loopop
  • Moneytiser
  • Neupop

Additional Informations

  • sdk.netnut.io
  • s1519.tera-home.com
  • s1523.swift-zip.com
  • s1320.gmslb.net
  • s1593.gmslb.net
  • s1380.swift-zip.com
  • s1878.nova-lan.com
  • s1863.gmslb.net
  • s1248.gmslb.net
  • s232.fast-mob.com
  • s01689.grid-push.com
  • s1573.pulse-vol.com
  • tera-home.com
  • vault-sentinel.com
  • s01687.gmslb.net
  • s206.sdkmob.org
  • swift-zip.com
  • s01692.tera-home.com
  • s1488.viki-play.com
  • mob-hit.com
  • novel-layer.com
  • s1480.byte-buff.com
  • s1507.worker-net.com
  • s228.nova-lan.com
  • fast-mob.com
  • s1244.gmslb.net
  • s1374.grid-push.com
  • s1491.worker-net.com
  • gw.rainproxy.io
  • sky-borders.com
  • shield-sky.com
  • s01693.gmslb.net
  • s1239.gmslb.net
  • digiproxy.cc
  • s1842.gmslb.net
  • s1312.gmslb.net
  • s1541.net-echo.com
  • s1.gmslb.net
  • s1278.gmslb.net
  • s1605.viki-play.com
  • s01691.novel-layer.com
  • s1865.gmslb.net
  • zync-stream.com
  • s251.pulse-vol.com
  • s1258.gmslb.net
  • enigmaproxy.net
  • s1549.gmslb.net
  • link-flux.com
  • s1840.gmslb.net
  • gw.netnut.net
  • s1599.gmslb.net
  • s1876.byte-buff.com
  • cool-horizon.com
  • s1246.gmslb.net
  • s1539.link-flux.com
  • s1368.byte-buff.com
  • s1838.net-echo.com
  • s2.net-echo.com
  • s01699.nova-lan.com
  • gw-flashproxy-eu.netnut.net
  • world2trust.com
  • s231.worker-net.com
  • voltix-net.com
  • proxy.iprocket.io
  • litics-net.com
  • s1322.gmslb.net
  • s242.link-flux.com
  • star-layer.com
  • s1772.nova-lan.com
  • s1664.link-flux.com
  • s1595.nova-lan.com
  • s1489.nova-lan.com
  • s1861.gmslb.net
  • s01700.novel-layer.com
  • s212.nova-lan.com
  • s01683.flexible-networks.com
  • s1483.grid-push.com
  • s1235.gmslb.net
  • s1250.gmslb.net
  • nice-protect.com
  • s1252.gmslb.net
  • s1372.nice-protect.com
  • earth2trust.com
  • s1587.viki-play.com
  • house-spirit.com
  • s1517.viki-play.com
  • flexible-networks.com
  • s01698.gmslb.net
  • s1850.gmslb.net
  • s1868.gmslb.net
  • residential.digiproxy.cc
  • s246.sdkmob.org
  • s1860.gmslb.net
  • s1862.gmslb.net
  • s1880.net-echo.com
  • s1874.gmslb.net
  • s1238.gmslb.net
  • s1382.sdkmob.org
  • s1487.noverland.com
  • s1836.gmslb.net
  • net-echo.com
  • s1848.gmslb.net
  • s1870.gmslb.net
  • yoursfind.com
  • resi-digiproxy.netnut.net
  • s1884.gmslb.net
  • worker-net.com
  • s1846.gmslb.net
  • gw-xunjie-ca.netnut.net
  • pulse-vol.com
  • s1872.gmslb.net
  • s1692.litics-net.com
  • s1529.nova-lan.com
  • s1240.gmslb.net
  • org.speedcheck.sclibrary.support
  • s1318.noverland.com
  • byte-armor.com
  • s1386.sdkmob.org
  • s34.flexible-networks.com
  • s1820.net-echo.com
  • s1822.pulse-vol.com
  • s205.link-flux.com
  • zen-tava.com
  • s1866.gmslb.net
  • s1515.link-flux.com
  • s1597.nova-lan.com
  • s1314.sdkmob.org
  • s1591.gmslb.net
  • s1690.nova-lan.com
  • s1266.gmslb.net
  • rainproxy.io
  • s1688.tera-home.com
  • s1589.gmslb.net
  • viki-play.com
  • s1296.net-echo.com
  • presi-eu.enigmaproxy.net
  • s1858.gmslb.net
  • s88.fast-mob.com
  • s1503.nice-protect.com
  • s1236.gmslb.net
  • s217.fast-mob.com
  • s1511.net-echo.com
  • s72.byte-buff.com
  • s1607.link-flux.com
  • s1262.gmslb.net
  • iprocket.io
  • s1330.sdkmob.org
  • gmslb.net
  • s269.sdkmob.org
  • s7.nova-lan.com
  • flix.com.vision
  • s1834.link-flux.com
  • axe-net.com
  • s256.sky-borders.com
  • s1854.gmslb.net
  • sdkmob.org
  • s1316.fast-mob.com
  • s01679.gmslb.net
  • s1851.gmslb.net
  • flashproxy.com
  • byte-buff.com
  • s01697.gmslb.net
  • s1601.grid-push.com
  • s100.gmslb.net
  • s1237.gmslb.net
  • s247.fast-mob.com
  • s1254.gmslb.net
  • s1272.gmslb.net
  • s01696.noverland.com
  • s1856.gmslb.net
  • s1234.gmslb.net
  • s1484.novel-layer.com
  • s1314.noverland.com
  • s1328.gmslb.net
  • s1830.net-echo.com
  • s1310.gmslb.net
  • nova-lan.com
  • s1324.gmslb.net
  • s01695.grid-push.com
  • s209.worker-net.com
  • s1326.gmslb.net
  • grid-push.com
  • s1256.gmslb.net
  • s1852.gmslb.net
  • noverland.com
  • s1844.nova-lan.com
  • s1864.gmslb.net
  • s1832.link-flux.com