‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
2026-06-22T07:23:58Z•c2f81fd54587e78fb7392f919bc04c16945d23fd324ba1137d875561643a3031
account takeoveradvertising fraudai support botalarum technologiesandroid tv boxesaws govcloudcisacritical vulnerabilitiesdata leakddos botnetdort arrestgithub leakinstagram compromisekimwolfmass scrapingmetamicrosoft patch tuesdaynetherlands hosting seizurenetnutpopa botnetpublic exploit coderansomware affiliatesresidential proxyrussian cyber operationsthe gentlemen ransomware
What happened
A collection of KrebsOnSecurity reports covering multiple high-impact incidents: researchers link the Popa Android-based botnet to NetNut/Alarum Technologies, showing millions of consumer TV boxes were hijacked as residential proxies for ad fraud, account takeovers and mass scraping; an investigation into the identity of the administrator behind The Gentlemen ransomware gang; Microsoft’s June 2026 Patch Tuesday fixed nearly 200 vulnerabilities (dozens critical) with public exploit code for several flaws; attackers abused Meta’s AI support assistant to reset Instagram passwords and briefly defá
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- c2f81fd54587e78fb7392f919bc04c16945d23fd324ba1137d875561643a3031
- Enrichment time
- 2026-06-22T07:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.