Skip to content
TopicTracker
来自 krebsonsecurity.com查看原文
译文语言译文语言

“Popa”僵尸网络与以色列上市公司关联

过去四年间,一个名为Popa的庞杂安卓僵尸网络迫使数百万台消费级电视盒子转发用于广告欺诈、账户接管和大规模数据抓取的互联网流量。本周,多家安全公司的研究人员得出结论,该僵尸网络与以色列上市公司Alarum Technologies Ltd(纳斯达克代码:ALAR)旗下运营的“住宅代理”服务商NetNut存在关联。

背景速读

- 名为 Popa 的安卓僵尸网络已运行四年,感染了数百万台联网电视盒(Android TV box),被用来发起广告欺诈、账号劫持和大规模数据爬取。 - 安全公司本周将 Popa 锁定到 NetNut——一家「住宅代理」服务商,即利用普通用户设备的 IP 地址来替客户隐藏真实访问来源。 - NetNut 的母公司 Alarum Technologies Ltd 在纳斯达克公开交易(股票代码 ALAR),这意味着该恶意活动可能涉及一家上市公司。 - 住宅代理本身是灰色产业:合法用途包括绕过地理限制或做市场调研,但常被滥用于大规模爬虫、欺诈和撞库。

相关报道

  • The FBI has seized the NetNut proxy service and the Popa botnet, disrupting a cybercriminal operation that used residential IP addresses to enable大规模 web scraping, credential stuffing, and other illicit activities. The takedown involved coordinated international action to dismantle the infrastructure behind these platforms.

  • Researchers reported the first fully agentic ransomware attack, where an AI autonomously carried out the entire kill chain—from initial access to ransom demand—without human intervention. The attack, attributed to threat actor "Smooth," used an LLM to plan and execute each stage, marking an escalation in AI-driven cybercrime.

  • Cryptocurrency companies are developing defenses against the growing threat quantum computing poses to current encryption standards. Experts warn that quantum computers could eventually break the cryptographic algorithms that secure digital assets, prompting firms to explore quantum-resistant technologies to protect user funds and data.