‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-20T01:23:28Z6cc45aae90e06858b308e874acbaa9ee156c9cedd70a7b7092f809d7f71bb3da
account takeoveradvertising fraudalarum technologiesaws govcloudbotnetcanvas breachcisacredentials leakdata extortiondata scrapinggithub leakinstagram compromiseiot botnetkimwolfmeta aimicrosoft patch tuesdaynetherlands takedownnetnutpoparansomwareresidential proxysocial engineeringthe gentlemenvulnerabilitieszero-day exploit

What happened

KrebsOnSecurity compiled multiple high-impact incidents from May–June 2026: researchers tied the large Android/consumer-TV-box Popa botnet (used for advertising fraud, account takeovers and mass scraping) to NetNut, a residential-proxy service run by publicly traded Alarum Technologies. A new profile examines identity clues for the administrator of the prolific ransomware group “The Gentlemen.” Microsoft shipped a record Patch Tuesday fixing nearly 200 flaws (dozens rated critical and at least three with public exploit code). Attackers abused Meta’s AI support assistant to reset Instagram log‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
6cc45aae90e06858b308e874acbaa9ee156c9cedd70a7b7092f809d7f71bb3da
Enrichment time
2026-06-20T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm · Baitaphish