FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-06T01:23:29Zaa8e03fb98432e8c4a582a3b96b6fca2e5c6070d67fb28bc6443599fdcfb093d
AWS GovCloudAlarum TechnologiesAndroid TVCISADDoSDortFBI domain seizureGitHub leakKimwolfNetNutNetherlands server seizurePopaRussian influence operationsScattered SpiderStark Industries SolutionsThe GentlemenTransport for Londonaccount takeoveradvertising fraudbotnetcongressional inquirycredential leakmass scrapingransomwareresidential proxy abuse

What happened

Multiple high-impact cyber incidents and law-enforcement actions were reported: the FBI seized hundreds of domains tied to NetNut after research linked the company (Alarum Technologies/ALAR) to the Popa Android-based botnet that abused millions of consumer TV boxes as residential proxies for ad fraud, account takeover and mass scraping. Separately, Netherlands authorities seized ~800 servers and arrested hosting co-owners accused of aiding Russian cyber operations. Notable arrests and prosecutions include the alleged Kimwolf botmaster “Dort” (charged in Canada and the U.S.) and two Scattered /

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
aa8e03fb98432e8c4a582a3b96b6fca2e5c6070d67fb28bc6443599fdcfb093d
Enrichment time
2026-07-06T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish