FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-03T07:23:27Z•e478d8699d1ef8c0690069bf4cfcd6de68f9a163d5cd3d89c1e15c5cbdd55e1c
AWS GovCloud credentials leakAlarum TechnologiesAndroid TV boxesCISAFBI domain seizureGitHub leakInstagram account takeoverKimwolfMeta AI support abuseMicrosoft Patch TuesdayNetNutNetherlands server seizurePopa botnetRussian influence operationsScattered SpiderThe Gentlemen ransomwareaccount takeoverad fraudbotnetcritical vulnerabilitiesmass scrapingpublic exploit coderesidential proxy
What happened
A cluster of high-impact cyber incidents: the FBI, working with partners, seized hundreds of domains tied to NetNut after multiple firms linked the company’s residential proxy service (operated by Alarum Technologies) to the Popa botnet — a sprawling Android/TV-box botnet of an estimated >2 million compromised devices used for ad fraud, account takeover and mass scraping. Related enforcement: arrests in the Kimwolf botmaster case and Dutch seizures of ~800 servers linked to Russian operations; two Scattered Spider members pleaded guilty in the UK. Separately, CISA contractor credentials for AW
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- e478d8699d1ef8c0690069bf4cfcd6de68f9a163d5cd3d89c1e15c5cbdd55e1c
- Enrichment time
- 2026-07-03T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.