FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-07T01:23:28Zbfb0f6db1465df78b12aeaa27136f78cdb5dbd8324627cc29aad05667b2eb256
account-takeoverai-support-botalarum-technologiesaws-govcloudbotnetcisacredential-leakdomain-seizureiot-botnetkimwolflaw-enforcementmetamicrosoft-patch-tuesdaynetnutpoparansomwareresidential-proxyscattered-spiderthe-gentlemenzero-day-exploits

What happened

Multiple high-impact cyber incidents reported by KrebsOnSecurity: the FBI seized hundreds of domains tied to NetNut after research linked the service to the Popa Android-based botnet that has enslaved millions of consumer TV boxes to operate as a residential proxy service (operator: Alarum Technologies [NASDAQ: ALAR]). Separately, two key Scattered Spider members pleaded guilty for the 2024 Transport for London attack; arrests were also made in the Netherlands and Canada relating to hosting infra and IoT botnet activity (Kimwolf). Microsoft released a record Patch Tuesday (nearly 200 fixes, ~3

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
bfb0f6db1465df78b12aeaa27136f78cdb5dbd8324627cc29aad05667b2eb256
Enrichment time
2026-07-07T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish