• A 50TB hug to Kloop Media: Forensic analysis of the DDoS attack targeting Kloop.kg

    A 50TB hug to Kloop Media: Forensic analysis of the DDoS attack targeting Kloop.kg

    The independent Kyrgyz news outlet Kloop.kg suffered a a high volume multi-vector DDoS attack aiming to bring the site down on August 31st. During the seven-hour attack, the attack generated roughly 50 TB of traffic in total — equivalent to around 15 years of the website’s normal traffic volume.

    Read more

  • Following the money (II). The Consultancy Trap – Twenty Years of Immigration Consultancy Abuse

    Following the money (II). The Consultancy Trap – Twenty Years of Immigration Consultancy Abuse

    Last week we published the first investigation in the series “Follow the Money”, where a single receipt from a victim of an immigration scam in Australia, exposed a global corporate network of scammers. This investigation digs deeper and identifies four groups of fraudulent companies based and operating from Israel since twenty years back.

    Read more

  • Following the money I

    Following the money I

    Our investigation began in May (2026) when an Australian investigative journalist contacted Qurium seeking assistance in tracing a fraudulent investment operation estimated to have defrauded Australian victims millions of dollars. The scammers promoted fake investment platforms through Facebook advertisements featuring AI-generated images impersonating well-known ABC journalists and Australian politicians. The methods immediately looked familiar, and soon we could link the scam to the “Scam Empire” investigation.

    Read more

  • #Op NutCracker: FBI Seizes Domains Used by Netnut’s Residential Proxy Network

    #Op NutCracker: FBI Seizes Domains Used by Netnut’s Residential Proxy Network

    Yesterday, the FBI seized key domains of NetNut’s residential proxy network where millions of malicious Popa bots operate, marking a major disruption of one of the largest known residential proxy botnets affecting Smart TVs and other Android connected devices. The take-down operation represents an important milestone in the international effort to identify those responsible and

    Read more

  • The uncomfortable truth behind 10 million Popa proxy requests

    The uncomfortable truth behind 10 million Popa proxy requests

    Executive Summary During our investigation into Android TV and streaming applications, Qurium identified dozens of Android (APK) packages containing a software component that transformed a diverse collection of IPTV players, streaming applications, and media-related Android software into residential proxies. At first glance, the applications appeared to just offer television streaming, IPTV playback, media consumption, and

    Read more

  • Finding “Popa”: When Your Smart TV Stops Being Yours

    Finding “Popa”: When Your Smart TV Stops Being Yours

    Less than a month after the release of Opaque Scrapers, Qurium, working with independent threat intelligence researchers including the Nokia Deepfield Emergency Response Team and Synthient, releases new findings that identify the underlying infrastructure of the scraping event to “Popa”: a residential proxy software family that turns consumer devices into Internet relay nodes.

    Read more

  • How a Sneaker-Proxy Business Entered the Scraping Industry

    How a Sneaker-Proxy Business Entered the Scraping Industry

    From Chi Proxies to NetNut Limited-edition sneaker drops are highly anticipated, restricted releases from top brands like Nike, Adidas, and New Balance, often featuring collaborations with prominent athletes, artists, or fashion houses. These exclusive launches leverage intentional scarcity to drive massive cultural demand and secondary market resale value. The phenomena “Limited-edition sneaker drops” has created

    Read more

  • Opaque Scrapers Hiding in the Crowd

    Opaque Scrapers Hiding in the Crowd

    On May 14th, the English-language website of Arab Reporters for Investigative Journalism (ARIJ) was targeted by a large-scale scraping event which generated a massive volume of automated traffic. The traffic came from approx. 1.35 million unique IP addresses, spread across more than 7,300 AS and 223 country codes. This investigation targets opaque scraping services that threatens an open Internet.

    Read more

  • The Future and Past of Residential Proxies

    The Future and Past of Residential Proxies

    Residential proxies is the largest security challenge we are currently facing. Dozens of attacks against our infrastructure have been originated in residential proxy providers including volumetric application layers attacks, heavy pen tests, intrusion attempts or non-consented scraping. When we manage to back-trace the attacks to residential providers we obtained similar response to our reporting: “thanks for reporting, we are ethical providers, leave us alone”.

    Read more

  • Statement on the November 18, 2025 Court Decision in Quezon City

    Statement on the November 18, 2025 Court Decision in Quezon City

    In June 2022, in the Philippines, the National Security Adviser Hermogenes Esperon requested that the National Telecommunications Commission direct all internet service providers to block access to several independent news websites. This request resulted in a memorandum sent to the ISPs, which led to the blocking of Bulatlat and Pinoy Weekly, both of which were

    Read more