FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-05T13:23:28Z•7acf2127d393413085711b5049723d41b14f59d64b81d597994ca9ad9e2b2049
AWS GovCloudAlarum TechnologiesAndroidCISAFBIIoTKimwolfMicrosoft Patch TuesdayNetNutPopaScattered SpiderTV boxesThe Gentlemenaccount takeoveradvertising fraudbotnetcredentials exposure','GitHub leak','meta','AI support bot','insdata leakdata scrapingdomain seizurelaw enforcementpublic exploitransomwareresidential proxyvulnerabilities
What happened
Multiple high-impact cyber incidents and law-enforcement actions reported: the FBI seized hundreds of domains tied to NetNut after firms linked the company (Alarum Technologies) to the Popa botnet — an Android/IoT-based proxy network running on millions of compromised TV boxes used for advertising fraud, account takeovers and large-scale scraping. Separate takedowns and arrests include Dutch seizures of ~800 servers for aiding Russian operations and the arrest of an alleged Kimwolf botmaster; two Scattered Spider members pleaded guilty in a major Transport for London attack. Major operational/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 7acf2127d393413085711b5049723d41b14f59d64b81d597994ca9ad9e2b2049
- Enrichment time
- 2026-07-05T13:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.