
The uncomfortable truth behind 10 million Popa proxy requests
Executive Summary During our investigation into Android TV and streaming applications, Qurium identified dozens of Android (APK) packages containing a software component that transformed a diverse collection of IPTV players, streaming applications, and media-related Android software into residential proxies. At first glance, the applications appeared to just offer television streaming, IPTV playback, media consumption, and […]

The Uncomfortable Truth Behind Ethical Web Scraping
Qurium has released the findings of a new technical investigation into the “Popa” residential proxy network, a system that transforms consumer devices into residential internet exit nodes and which our previous research linked to infrastructure associated with NetNut and Alarum Technologies. To better understand how the network operates in practice, Qurium joined the Popa network and voluntarily contributed bandwidth as a residential proxy node. Over the course of the investigation, our systems recorded and analyzed more than ten million proxy requests transiting the network.

Finding “Popa”: When Your Smart TV Stops Being Yours
Less than a month after the release of Opaque Scrapers, Qurium, working with independent threat intelligence researchers including the Nokia Deepfield Emergency Response Team and Synthient, releases new findings that identify the underlying infrastructure of the scraping event to “Popa”: a residential proxy software family that turns consumer devices into Internet relay nodes.

Qurium traced the global scraping campaign to Popa, a residential proxy network hidden inside consumer devices
Less than a month after documenting a global scraping campaign that drew on more than 1.4 million distributed IP addresses to target public-interest journalism, Qurium Media Foundation, working with independent threat intelligence researchers, including the Nokia Deepfield Emergency Response Team and Synthient, has traced the underlying infrastructure to “Popa”: a residential proxy software family that turns consumer devices into Internet relay nodes.

The Future and Past of Residential Proxies
Residential proxies is the largest security challenge we are currently facing. Dozens of attacks against our infrastructure have been originated in residential proxy providers including volumetric application layers attacks, heavy pen tests, intrusion attempts or non-consented scraping. When we manage to back-trace the attacks to residential providers we obtained similar response to our reporting: “thanks for reporting, we are ethical providers, leave us alone”.

Qurium exposes the residential proxy economy behind the next generation of botnets
Qurium publishes today a new investigation showing how residential proxy networks, Android supply-chain malware, and DDoS botnets are no longer separate problems. They are now part of the same abuse economy. Our research traces how compromised consumer devices, proxy SDKs, grey-market proxy providers, and botnet operators feed one another. KimWolf is not the story. KimWolf is the warning sign.

Proxy.vn’s hidden Tin-Roof datacenter fueling fake accounts behind the recent attack on iStories.media
Qurium has completed a forensic investigation into the DDoS attacks targeting the Russian investigative media iStories in early November 2025. The investigation links the attacks to Proxy.vn, a Vietnamese proxy network built to exploit residential and mobile internet infrastructure at national scale.

Proxy.vn’s hidden Tin-Roof datacenter fueling fake accounts and DDoS attack on iStories.media
The Russian investigative media iStories received a series of Denial of Service attacks in early November 2025. At peak the website was flooded by more than 30.000 IP addresses. Although the attack infrastructure was globally distributed, a large portion of the flooding botnet was geo-located in Vietnam. Follow us on a journey to the tin-roof data center industry in Vietnam.

Proxy provider connected to state sanctioned research center linked to attack against investigative media
Russian independent media outlets came under DDoS attack after publishing an investigation revealing how Russian oligarch and billionaire Oleg Deripaskaex been buying sex with minors.

Yet another proxy provider behind the iStories DoS attacks
iStories, independent Russian media outlet specializing in investigative journalism targeted by DDoS attack launched from proxy infrastructure. The very same proxy provider was involved in the DDoS attacks against Russian Meduza one year ago.
