‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-18T19:23:29Z•4787ce637a650c0a1dbf20a00e2d151a0054a2b4c95a44e48cd2e17560b8680b
AI support botAWS GovCloudAlarum TechnologiesAndroidCISAGitHub leakInstagram hijackMetaMicrosoft Patch TuesdayNetNutNetherlandsPopaRussia-linked operations」「Kimwolf」「IoT botnet」「DDoS」「Canvas dataThe Gentlemenaccount takeoveradvertising fraudbotnetdata leakhosting seizurelawmakers inquirypublic exploitransomwareresidential proxyvulnerabilitiesweb scraping
What happened
This feed aggregates multiple high-impact security stories: researchers link the Popa Android TV-box botnet to NetNut (Alarum Technologies), alleging its use for residential proxying, ad fraud, account takeovers and mass scraping. A new investigation profiles the operator/administrator behind the ransomware group “The Gentlemen.” Microsoft’s June 2026 Patch Tuesday fixed nearly 200 flaws (dozens rated critical) with public exploit code for several. Attackers abused Meta’s AI support assistant to reset Instagram passwords and hijack high-profile accounts. Dutch authorities seized ~800 servers &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 4787ce637a650c0a1dbf20a00e2d151a0054a2b4c95a44e48cd2e17560b8680b
- Enrichment time
- 2026-06-18T19:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.