‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-20T01:23:28Z•6cc45aae90e06858b308e874acbaa9ee156c9cedd70a7b7092f809d7f71bb3da
account takeoveradvertising fraudalarum technologiesaws govcloudbotnetcanvas breachcisacredentials leakdata extortiondata scrapinggithub leakinstagram compromiseiot botnetkimwolfmeta aimicrosoft patch tuesdaynetherlands takedownnetnutpoparansomwareresidential proxysocial engineeringthe gentlemenvulnerabilitieszero-day exploit
What happened
KrebsOnSecurity compiled multiple high-impact incidents from May–June 2026: researchers tied the large Android/consumer-TV-box Popa botnet (used for advertising fraud, account takeovers and mass scraping) to NetNut, a residential-proxy service run by publicly traded Alarum Technologies. A new profile examines identity clues for the administrator of the prolific ransomware group “The Gentlemen.” Microsoft shipped a record Patch Tuesday fixing nearly 200 flaws (dozens rated critical and at least three with public exploit code). Attackers abused Meta’s AI support assistant to reset Instagram log‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 6cc45aae90e06858b308e874acbaa9ee156c9cedd70a7b7092f809d7f71bb3da
- Enrichment time
- 2026-06-20T01:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.