FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-06T19:23:28Z•a637ef9c78da37e458af2f15a01133eb2f7060e486d756de7dcae3480ad8e98e
Alarum TechnologiesAndroid botnetDDoSFBIIoT botnetKimwolfNetNutNetherlands seizuresPopaScattered SpiderStark Industries SolutionsThe GentlemenThe Gentlemen ransomwareaccount takeoveradvertising fraudbotnetdata scrapingdomain seizurehosting infrastructurelaw enforcement takedownmalwareproxy abuseransomwareresidential proxysanctions evasion infrastructure support
What happened
Collection of KrebsOnSecurity reports (May–Jul 2026) documenting several high-impact cyber incidents: the FBI seized hundreds of domains used by NetNut, a residential-proxy service allegedly tied to the Popa Android-based botnet that has enslaved millions of consumer TV boxes for traffic relaying, ad fraud, account takeover and mass scraping; researchers link Popa to publicly-traded Alarum Technologies (NetNut). Other notable items: guilty pleas by two Scattered Spider members for the 2024 Transport for London attack; profiling of The Gentlemen ransomware group operator and its affiliate model
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- a637ef9c78da37e458af2f15a01133eb2f7060e486d756de7dcae3480ad8e98e
- Enrichment time
- 2026-07-06T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.