FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-03T01:23:28Z4be689a8a501c02511cd837726ccb284906bb6530a8d4db00e6100a300709010
AWS GovCloud leakAlarum TechnologiesCISAFBI seizureGitHub credential exposureInstagram account takeoverIoT botnetKimwolfMeta AI support botMicrosoft Patch TuesdayNetNutNetherlands server seizuresPopa botnetRussian influence opsScattered SpiderThe GentlemenTransport for Londonransomwareresidential proxyzero-day/exploit code

What happened

KrebsOnSecurity reported a wave of major cyber incidents: the FBI seized hundreds of NetNut-related domains after research linked the publicly traded Alarum Technologies’ residential proxy service to the Popa Android-based botnet (millions of compromised devices used for ad fraud, account takeovers and scraping). Separately, two Scattered Spider members pleaded guilty for the 2024 Transport for London attack; a suspected Kimwolf botmaster was arrested; and investigators tied hosting firms to Russian cyber operations after Dutch server seizures. High-impact operational incidents include a CISA‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
4be689a8a501c02511cd837726ccb284906bb6530a8d4db00e6100a300709010
Enrichment time
2026-07-03T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish