FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-08T07:23:27Z•18856817ac9d1073fa9eb011c362e757f68871a3cb9ab101928a3c9cc21b88ab
AI-support-botAWS GovCloudAlarum TechnologiesAndroidCISAFBI seizureInstagram compromise','Scattered Spider','ransomware','The GentlMetaMicrosoft Patch TuesdayNetNutPopaTV-boxesaccount-takeoveradvertising-fraudbotnetcredentialscritical-vulnerabilitiesdata-leakdata-scrapinglaw-enforcementmalwarepublic-exploitresidential-proxytakdown
What happened
Multiple high-impact cyber incidents reported by KrebsOnSecurity in mid-2026: the FBI, working with industry, seized hundreds of domains tied to NetNut — a residential-proxy service operated by Alarum Technologies — after research linked NetNut to the Popa Android/TV-box botnet that enslaved millions of consumer devices for advertising fraud, account takeovers and large-scale scraping. Separately, law enforcement actions and arrests targeted other infrastructure and botnets (Kimwolf, hosting providers in the Netherlands tied to Russian operations). A CISA contractor leaked highly privilegedAWS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 18856817ac9d1073fa9eb011c362e757f68871a3cb9ab101928a3c9cc21b88ab
- Enrichment time
- 2026-07-08T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.