‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-21T07:23:27Z•6bbf145cd1790d343fa5c0855f73c7ad4cbe3bdbc709de86cbf5790cc5dd9962
AI support botAWS GovCloudAlarum TechnologiesAndroidCISACanvasGitHub leakInstagram account takeoverKimwolf','DDoS','Netherlands arrests','hosting abuse','RussiaMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetdata extortiondata leakdata-scrapingpublic exploitsransomwareresidential-proxyvulnerabilities
What happened
A series of major cyber incidents and investigations: security researchers tied the Popa Android-based botnet — which hijacked millions of consumer TV boxes to provide residential proxying for ad fraud, account takeovers and large‑scale data scraping — to NetNut, a "residential proxy" service run by publicly traded Alarum Technologies (NASDAQ: ALAR). Other coverage highlights a rapidly rising ransomware group called The Gentlemen recruiting affiliates with generous revenue shares; a record June 2026 Microsoft Patch Tuesday fixing ~200 vulnerabilities (dozens rated critical and at least three w
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 6bbf145cd1790d343fa5c0855f73c7ad4cbe3bdbc709de86cbf5790cc5dd9962
- Enrichment time
- 2026-06-21T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.