‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-21T07:23:27Z6bbf145cd1790d343fa5c0855f73c7ad4cbe3bdbc709de86cbf5790cc5dd9962
AI support botAWS GovCloudAlarum TechnologiesAndroidCISACanvasGitHub leakInstagram account takeoverKimwolf','DDoS','Netherlands arrests','hosting abuse','RussiaMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetdata extortiondata leakdata-scrapingpublic exploitsransomwareresidential-proxyvulnerabilities

What happened

A series of major cyber incidents and investigations: security researchers tied the Popa Android-based botnet — which hijacked millions of consumer TV boxes to provide residential proxying for ad fraud, account takeovers and large‑scale data scraping — to NetNut, a "residential proxy" service run by publicly traded Alarum Technologies (NASDAQ: ALAR). Other coverage highlights a rapidly rising ransomware group called The Gentlemen recruiting affiliates with generous revenue shares; a record June 2026 Microsoft Patch Tuesday fixing ~200 vulnerabilities (dozens rated critical and at least three w

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
6bbf145cd1790d343fa5c0855f73c7ad4cbe3bdbc709de86cbf5790cc5dd9962
Enrichment time
2026-06-21T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm · Baitaphish