FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-03T13:23:29Z•09cc343dcd51d8c8af7decb8c1a57f40a592f84271ddf7f55ed0d4d8d358ef11
AWS GovCloud leakAlarum TechnologiesCISAFBI domain seizureGitHub exposed credentialsInstagram account takeoverIoT botnetKimwolfMeta AI abuseMicrosoft Patch TuesdayNetNutNetherlands server seizurePopaScattered SpiderThe Gentlemenaccount takeoveradvertising fraudbotnetransomwareresidential proxy
What happened
KrebsOnSecurity items describe multiple high-impact disruption and compromise events: the FBI, working with industry partners, seized hundreds of domains linked to NetNut — a residential-proxy provider run by Alarum Technologies — after research connected NetNut to the Android/TV-box Popa botnet (≈2 million compromised devices) used for advertising fraud, account takeovers and mass scraping. Separately, law enforcement actions and arrests included Netherlands seizures of ~800 servers tied to Russian operations and the arrest of an alleged Kimwolf botnet operator in Canada; two Scattered Spider
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 09cc343dcd51d8c8af7decb8c1a57f40a592f84271ddf7f55ed0d4d8d358ef11
- Enrichment time
- 2026-07-03T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.