FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-03T19:23:25Z•88c840300beb028204c24bf9e5b3e989c9a18ff5754aa3f9494a30c4e7b26d54
AWS GovCloudAlarum TechnologiesAndroid malwareCISAFBIGitHub leak','social engineering','Meta AI support bot','accountIoTMicrosoft vulnerabilitiesNetNutPatch TuesdayPopaPopa botnetScattered SpiderTV boxesThe Gentlemenaccount takeoveradvertising fraudbotnetcredentials leakeddata leakdata scrapingdomain seizureexploit coderansomwareresidential proxy
What happened
A collection of KrebsOnSecurity reports detailing multiple high-impact cyber incidents: the FBI seized hundreds of domains tied to NetNut after research linked the Popa Android/TV-box botnet (millions of compromised devices) to Alarum Technologies; guilty pleas by Scattered Spider members over the 2024 TfL attack; identification and investigation of The Gentlemen ransomware group; a record June 2026 Microsoft Patch Tuesday fixing nearly 200 flaws (dozens critical, public exploit code for some); abuse of Meta’s AI support bot to hijack Instagram accounts; Dutch seizures and arrests for hosting+
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 88c840300beb028204c24bf9e5b3e989c9a18ff5754aa3f9494a30c4e7b26d54
- Enrichment time
- 2026-07-03T19:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.