‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-23T13:23:29Z•910da5ddf1fda7f8201feb3b0b98bdcb8f0ee887f73ba28cc13f3599bb527dad
AI support botAWS GovCloudAlarum TechnologiesAndroidCISAGitHub exposureInstagram takeoverMetaMicrosoftNetNutNetherlandsPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetdata leakdata scrapingexploit coderansomwarerecruitmentresidential proxyserver seizure','Russian operations'vulnerabilities
What happened
Multiple high-impact security incidents reported: the Popa Android-based botnet (millions of compromised TV boxes) is linked to NetNut/Alarum Technologies and has been used for ad fraud, account takeovers and mass data scraping; The Gentlemen ransomware group has become the second-most active gang, aggressively recruiting affiliates (reportedly offering 90% cuts); Microsoft’s June 2026 Patch Tuesday fixed nearly 200 vulnerabilities (≈36 rated critical) with public exploit code for at least three flaws; attackers abused Meta’s AI support assistant to hijack high-profile Instagram accounts; the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 910da5ddf1fda7f8201feb3b0b98bdcb8f0ee887f73ba28cc13f3599bb527dad
- Enrichment time
- 2026-06-23T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.