
Kloop Media hit by 50TB multi-vector DDoS attack
On 31 August, independent Kyrgyz news outlet Kloop.kg was targeted by a massive seven-hour DDoS attack that generated an estimated 50TB of malicious traffic — equivalent to roughly 15 years of the website’s normal traffic volume. Qurium can confirm that the attack was conducted by the Aisuru botnet.

Twenty Years of Immigration Consultancy Abuse
Last week we published the first investigation in the series “Follow the Money”, where a single receipt from a victim of an immigration scam in Australia, exposed a global corporate network of scammers. Today’s follow up investigation digs deeper into the same “modus operandi” and identifies four groups all based in Israel operating since twenty years ago.

Following The Money
What began as the investigation of a single immigration scam targeting vulnerable people with false promises of legal pathways to Canada and the United States evolved into the discovery of an extensive network of fraudulent immigration businesses, shell companies, and suspected money-laundering operations in Israel, South Africa, US and Spain.

#Op NutCracker: FBI Seizes Domains Used by Netnut’s Residential Proxy Network
Yesterday, the FBI seized key domains of NetNut’s residential proxy network where millions of malicious Popa bots operate, marking a major disruption of one of the largest known residential proxy botnets affecting Smart TVs and other Android connected devices. The take-down operation represents an important milestone in the international effort to identify those responsible and […]

The Uncomfortable Truth Behind Ethical Web Scraping
Qurium has released the findings of a new technical investigation into the “Popa” residential proxy network, a system that transforms consumer devices into residential internet exit nodes and which our previous research linked to infrastructure associated with NetNut and Alarum Technologies. To better understand how the network operates in practice, Qurium joined the Popa network and voluntarily contributed bandwidth as a residential proxy node. Over the course of the investigation, our systems recorded and analyzed more than ten million proxy requests transiting the network.

Qurium traced the global scraping campaign to Popa, a residential proxy network hidden inside consumer devices
Less than a month after documenting a global scraping campaign that drew on more than 1.4 million distributed IP addresses to target public-interest journalism, Qurium Media Foundation, working with independent threat intelligence researchers, including the Nokia Deepfield Emergency Response Team and Synthient, has traced the underlying infrastructure to “Popa”: a residential proxy software family that turns consumer devices into Internet relay nodes.

Exposing Opaque Scraping Infrastructure Targeting Public-Interest Journalism
The investigation documents a large-scale scraping event against the English-language website of Arab Reporters for Investigative Journalism (ARIJ) targeting its library of public-interest investigations and generated a massive volume of automated traffic against the site which received traffic from approx. 1.35 million unique IP addresses, spread across more than 7,300 AS and 223 country codes.

Qurium exposes the residential proxy economy behind the next generation of botnets
Qurium publishes today a new investigation showing how residential proxy networks, Android supply-chain malware, and DDoS botnets are no longer separate problems. They are now part of the same abuse economy. Our research traces how compromised consumer devices, proxy SDKs, grey-market proxy providers, and botnet operators feed one another. KimWolf is not the story. KimWolf is the warning sign.

The show must go on, not!
Last week Europol announced a major international operation that dismantled a cryptocurrency fraud and money-laundering network responsible for laundering more than EUR 700 million. The coordinated action exposed the use of fake investment platforms, social-engineering call centers, cross-border crypto-laundering structures, and, critically, affiliate-marketing systems designed to target victims through deceptive advertising and impersonation of reputable outlets. The operation confirmed that affiliate-marketing infrastructure formed a key pillar of the criminal ecosystem.

Proxy.vn’s hidden Tin-Roof datacenter fueling fake accounts behind the recent attack on iStories.media
Qurium has completed a forensic investigation into the DDoS attacks targeting the Russian investigative media iStories in early November 2025. The investigation links the attacks to Proxy.vn, a Vietnamese proxy network built to exploit residential and mobile internet infrastructure at national scale.
