‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-23T01:23:31Z•54b1b97384cba6c8dd8b322d6aa801eb80593c66a083cceffbc29531267e1d5b
AWS GovCloudAlarum TechnologiesAndroid botnetCISAGitHub leak','credential leak'','Kimwolf','Dort','IoT botnet','DInstagram account takeoverMeta AI support botMicrosoft Patch TuesdayNetNutNetherlandsPopaRussian influence operationsStark Industries SolutionsTV boxesThe Gentlemenaccount takeoveradvertising fraudaffiliate programdata scrapingpublic exploitsransomwareresidential proxyserver seizuresocial engineeringzero-day
What happened
This feed aggregates several high-impact security incidents from mid-2026: the Popa Android/TV-box botnet has been linked to NetNut (Alarum Technologies), fueling ad fraud, account takeovers and mass scraping; a prolific ransomware group “The Gentlemen” is rapidly recruiting affiliates and may be tied to an identifiable administrator; Microsoft shipped a record ~200 fixes in June (nearly three dozen critical bugs) with public exploit code for multiple flaws; attackers abused Meta’s AI support assistant to take over Instagram accounts; Dutch authorities seized ~800 servers and arrested two for,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 54b1b97384cba6c8dd8b322d6aa801eb80593c66a083cceffbc29531267e1d5b
- Enrichment time
- 2026-06-23T01:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.