‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

2026-06-19T13:23:31Zb634c09002e2732a2d903336da224715e43ac9f650b377301ca8e5c663feabd1
AI social engineeringAI support botAWS GovCloud keys leak','GitHub leak','data leak','lawmakers','CAlarum TechnologiesAndroidCISAInstagramMetaMicrosoftNetNutPatch TuesdayPopaThe Gentlemenaccount takeoveradvertising fraudbotnetdata scrapingpublic exploitransomwareransomware affiliatesresidential proxyset-top boxesvulnerabilitieszero-day

What happened

A cluster of major cybersecurity incidents and trends reported by KrebsOnSecurity in May–June 2026: researchers linked the Popa Android-based botnet—used to hijack millions of consumer TV/set‑top boxes for advertising fraud, account takeovers and mass scraping—to NetNut/Alarum Technologies (a publicly traded Israeli “residential proxy” provider). A new, fast‑growing ransomware group called “The Gentlemen” has emerged as a top operator by victim count, using an aggressive affiliate model (paying affiliates up to 90%) to scale. Microsoft’s June Patch Tuesday addressed a record ~200 flaws (nearly

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
b634c09002e2732a2d903336da224715e43ac9f650b377301ca8e5c663feabd1
Enrichment time
2026-06-19T13:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.