FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-03T19:23:25Z88c840300beb028204c24bf9e5b3e989c9a18ff5754aa3f9494a30c4e7b26d54
AWS GovCloudAlarum TechnologiesAndroid malwareCISAFBIGitHub leak','social engineering','Meta AI support bot','accountIoTMicrosoft vulnerabilitiesNetNutPatch TuesdayPopaPopa botnetScattered SpiderTV boxesThe Gentlemenaccount takeoveradvertising fraudbotnetcredentials leakeddata leakdata scrapingdomain seizureexploit coderansomwareresidential proxy

What happened

A collection of KrebsOnSecurity reports detailing multiple high-impact cyber incidents: the FBI seized hundreds of domains tied to NetNut after research linked the Popa Android/TV-box botnet (millions of compromised devices) to Alarum Technologies; guilty pleas by Scattered Spider members over the 2024 TfL attack; identification and investigation of The Gentlemen ransomware group; a record June 2026 Microsoft Patch Tuesday fixing nearly 200 flaws (dozens critical, public exploit code for some); abuse of Meta’s AI support bot to hijack Instagram accounts; Dutch seizures and arrests for hosting+

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
88c840300beb028204c24bf9e5b3e989c9a18ff5754aa3f9494a30c4e7b26d54
Enrichment time
2026-07-03T19:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.