FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-03T07:23:27Ze478d8699d1ef8c0690069bf4cfcd6de68f9a163d5cd3d89c1e15c5cbdd55e1c
AWS GovCloud credentials leakAlarum TechnologiesAndroid TV boxesCISAFBI domain seizureGitHub leakInstagram account takeoverKimwolfMeta AI support abuseMicrosoft Patch TuesdayNetNutNetherlands server seizurePopa botnetRussian influence operationsScattered SpiderThe Gentlemen ransomwareaccount takeoverad fraudbotnetcritical vulnerabilitiesmass scrapingpublic exploit coderesidential proxy

What happened

A cluster of high-impact cyber incidents: the FBI, working with partners, seized hundreds of domains tied to NetNut after multiple firms linked the company’s residential proxy service (operated by Alarum Technologies) to the Popa botnet — a sprawling Android/TV-box botnet of an estimated >2 million compromised devices used for ad fraud, account takeover and mass scraping. Related enforcement: arrests in the Kimwolf botmaster case and Dutch seizures of ~800 servers linked to Russian operations; two Scattered Spider members pleaded guilty in the UK. Separately, CISA contractor credentials for AW

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
e478d8699d1ef8c0690069bf4cfcd6de68f9a163d5cd3d89c1e15c5cbdd55e1c
Enrichment time
2026-07-03T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.