‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-21T19:23:28Z•82188c6912cbdff26e0decc77e7d4e29fb5f8fae86eee76d9e6435d7e72f98db
AI social engineeringAWS GovCloudAlarum TechnologiesCISACanvasDDoS botnet (Kimwolf)Instagram hijackMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetcredential leakdata breachdata extortiondata scrapingeducation platformpublic exploitransomwareresidential proxy abusezero-day
What happened
KrebsOnSecurity headlines covering June–May 2026 show a surge in high-impact cyber incidents: researchers linked the long-running Android Popa botnet (used for advertising fraud, account takeover and mass scraping) to NetNut/Alarum Technologies; analysis surfaced likely real-world operators behind The Gentlemen ransomware gang; Microsoft issued a record Patch Tuesday (nearly 200 fixes, ~30 rated critical and public exploit code for at least three bugs); attackers abused Meta’s AI support assistant to hijack Instagram accounts; Dutch authorities seized ~800 servers and arrested hosting co-‑own
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 82188c6912cbdff26e0decc77e7d4e29fb5f8fae86eee76d9e6435d7e72f98db
- Enrichment time
- 2026-06-21T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.