FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-07T07:23:29Z•306f6d8d9adc862cee34b1d640b7cf584c886375a2ec77f4936d1f0616705cb6
account takeoveradvertising fraudalarum technologiesaws govcloudbotnetcisa leakcredential exposuredata scrapingexploit codefbi seizureinstagram account takeoveriot botnetkimwolflaw enforcementmeta ai abusemicrosoft patch tuesdaynetnutpopaproxy abuseransomwareresidential proxyscattered spiderthe gentlemenvulnerabilities
What happened
This collection of KrebsOnSecurity reports describes multiple high-impact cyber incidents in mid-2026: the FBI seized hundreds of domains tied to NetNut (Alarum Technologies) after research linked the company’s residential proxy service to the Popa botnet — a multi-million-device Android/TV-box botnet used for ad fraud, account takeovers and large-scale scraping. Separately, law enforcement arrested alleged botmasters (including a Kimwolf suspect) and Dutch authorities seized hundreds of servers used to support Russian operations. A CISA contractor accidentally published AWS GovCloud keys and敏
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 306f6d8d9adc862cee34b1d640b7cf584c886375a2ec77f4936d1f0616705cb6
- Enrichment time
- 2026-07-07T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.