‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-19T13:23:31Z•b634c09002e2732a2d903336da224715e43ac9f650b377301ca8e5c663feabd1
AI social engineeringAI support botAWS GovCloud keys leak','GitHub leak','data leak','lawmakers','CAlarum TechnologiesAndroidCISAInstagramMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetdata scrapingpublic exploitransomwareransomware affiliatesresidential proxyset-top boxesvulnerabilitieszero-day
What happened
A cluster of major cybersecurity incidents and trends reported by KrebsOnSecurity in May–June 2026: researchers linked the Popa Android-based botnet—used to hijack millions of consumer TV/set‑top boxes for advertising fraud, account takeovers and mass scraping—to NetNut/Alarum Technologies (a publicly traded Israeli “residential proxy” provider). A new, fast‑growing ransomware group called “The Gentlemen” has emerged as a top operator by victim count, using an aggressive affiliate model (paying affiliates up to 90%) to scale. Microsoft’s June Patch Tuesday addressed a record ~200 flaws (nearly
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- b634c09002e2732a2d903336da224715e43ac9f650b377301ca8e5c663feabd1
- Enrichment time
- 2026-06-19T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.