FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-05T07:23:26Z204721b8b8e4343df6cb380f29e37fc9d7ea6cb9b95e278357f4b27915803e43
AWS GovCloudAlarum TechnologiesAndroid TVCISADDoSFBI domain seizureGitHub leakKimwolfMeta AI abuse','social engineeringMicrosoft vulnerabilitiesNetNutPatch TuesdayPopaScattered SpiderThe Gentlemenaccount takeoveradvertising fraudarrestsbotnetcredential leakdomain seizurelaw enforcementpublic exploit coderansomwareresidential proxy

What happened

A series of high-impact cyber incidents reported by KrebsOnSecurity in May–July 2026: the FBI seized hundreds of domains tied to NetNut after researchers linked the company (Alarum Technologies) to the Popa Android-based residential-proxy botnet that enslaved millions of devices for ad fraud, scraping and account takeovers; law enforcement in multiple countries arrested alleged botmasters (Kimwolf) and hosting co-owners who aided Russian operations while Dutch authorities seized ~800 servers; two UK defendants from Scattered Spider pleaded guilty; a growing ransomware cartel (“The Gentlemen”)/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
204721b8b8e4343df6cb380f29e37fc9d7ea6cb9b95e278357f4b27915803e43
Enrichment time
2026-07-05T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish