FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-05T01:23:26Z70065b1666ae424969d1b186b036da5f690440e9f749a61b184637ccb7a31f54
AWS GovCloudAlarum TechnologiesAndroid botnetCISADDoS attacksFBI domain seizureGitHub leakInstagram compromiseIoTKimwolfMeta AI support botMicrosoft vulnerabilitiesNetNutPatch TuesdayPopaPopa botnetScattered SpiderThe Gentlemenaccount takeoverbotnetcredential leakexploit coderansomwareresidential proxyzero-day

What happened

Multiple high-impact cyber incidents reported: the FBI seized hundreds of domains tied to NetNut after research linked the company’s residential-proxy service to the Popa Android-based botnet that has commandeered millions of consumer devices; Popa is attributed to Alarum Technologies (NetNut). Separately, two Scattered Spider members pleaded guilty over the 2024 TfL attack, and Canadian and Dutch authorities made arrests/seizures tied to Kimwolf and hosting firms aiding Russian operations. Other notable items: The Gentlemen ransomware gang’s rapid rise, a record Microsoft Patch Tuesday (nearl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
70065b1666ae424969d1b186b036da5f690440e9f749a61b184637ccb7a31f54
Enrichment time
2026-07-05T01:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish