FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-06T07:23:30Z55af5c94908802b4d69973f151b23b159ab6d632f85f7d9a10d251805a934bd3
account-takeoverad-fraudalarum-technologiesaws-govcloudbotnetcisacredentials-exposeddata-leakdomain-seizuredropped-tv-boxesexploit-code-publicly-available」「meta-ai-abuse」「instagram-takeovfbi-seizuregithub-exposureiot-botnetkimwolflaw-enforcementmass-scrapingmicrosoft-patch-tuesdaynetnutpopaproxy-abuseresidential-proxyscattered-spidervulnerabilitieszero-day-exploits

What happened

Multiple high-impact cyber incidents reported: the FBI seized hundreds of domains tied to NetNut, a residential-proxy operator (Alarum Technologies/ALAR) that researchers linked to the Popa Android-based botnet — a network of millions of compromised TV boxes used for ad fraud, account takeovers and large-scale scraping. Related law-enforcement actions include arrests and infrastructure seizures in the Netherlands, Canada and the U.K. (including guilty pleas from Scattered Spider members and the arrest of an alleged Kimwolf botmaster). Separately, CISA suffered a major data leak after a vendor/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
55af5c94908802b4d69973f151b23b159ab6d632f85f7d9a10d251805a934bd3
Enrichment time
2026-07-06T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish