FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-06T13:23:36Z•91d0638b4cb076a740118a5624a7dce28ea6e69f725e4e27d5f9b4fbc242ec3e
AWS GovCloud credentialsAlarum TechnologiesAndroid botnetCISA data leakDDoSFBI seizureGitHub leakInstagram account takeoverKimwolfMeta AI support botMicrosoft Patch Tuesday June 2026NetNutNetherlands server seizurePopa botnetScattered SpiderStark Industries SolutionsTV-box malwareThe Gentlemen ransomwareaccount takeoveradvertising fraudlaw enforcement actionsmass data scrapingpublic exploit coderesidential-proxyzero-day exploitation
What happened
Multiple high-impact cyber incidents reported: the FBI seized hundreds of domains tied to NetNut (a residential-proxy service run by Alarum Technologies) after links were established between NetNut and the Popa botnet — an Android/TV-box based botnet (millions of compromised devices) used for proxying traffic to enable ad fraud, account takeovers and large-scale data scraping. Separately, law enforcement actions included arrests tied to Kimwolf (alleged botmaster “Dort”) and the Netherlands’ seizure of ~800 servers and arrests for hosting infrastructure used in Russian cyber operations. In the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 91d0638b4cb076a740118a5624a7dce28ea6e69f725e4e27d5f9b4fbc242ec3e
- Enrichment time
- 2026-07-06T13:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.