FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-04T01:23:29Z•81e0db853f78bad7303c8e98fdde5d937eda8505de0daaff81f77071e3534dd4
AWS GovCloudAlarum TechnologiesCISAFBI seizureGitHub leakInstagram compromiseKimwolfMeta AI abuseMicrosoft Patch TuesdayNetNutPopaScattered SpiderThe Gentlemenaccount takeoveradvertising fraudbotnetcredential leakdata scrapinglaw enforcementpublic exploitransomwareresidential proxysocial engineeringvulnerability managementzero-day (public exploit)
What happened
Multiple high-impact incidents reported: the FBI seized hundreds of domains tied to NetNut, a residential-proxy service now linked to the Popa Android-based botnet that has enslaved millions of consumer TV boxes for proxying, ad fraud, account takeovers and large-scale data scraping — researchers tie Popa to Alarum Technologies (NetNut). Separately, a CISA contractor leaked AWS GovCloud keys and internal secrets on a public GitHub repo, exposing highly privileged government credentials. Microsoft issued a record Patch Tuesday (nearly 200 fixes, ~3 dozen critical, public exploit code for at-le…
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 81e0db853f78bad7303c8e98fdde5d937eda8505de0daaff81f77071e3534dd4
- Enrichment time
- 2026-07-04T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.