FBI Seizes NetNut Proxy Platform, Popa Botnet

2026-07-05T19:23:29Zf18f5fbaa6842c4d2c110796d9c68cfc77e2bbb835f102e809a4f85ae2af676c
AWS GovCloudAlarum TechnologiesAndroidCISAFBIIoT-compromiseKimwolfMicrosoftNetNutNetherlandsPatch TuesdayPopaScattered SpiderStark Industries SolutionsTV-boxesThe Gentlemenarrestsbotnetcredential-leaked-on-GitHub','Meta','AI-support-bot','account-tflaw-enforcementpublic-exploit-coderansomwareresidential-proxyserver-seizurevulnerabilities

What happened

June–July 2026 reporting from KrebsOnSecurity highlights a series of high-impact cyber incidents: the FBI seized hundreds of domains tied to NetNut after researchers linked the Popa Android/TV-box botnet (≈2M+ compromised devices) to NetNut operator Alarum Technologies (NASDAQ: ALAR); multiple law-enforcement actions and arrests (including an alleged Kimwolf botmaster and Dutch seizures of ~800 servers) disrupted infrastructure used for DDoS, influence operations and malware hosting; two UK Scattered Spider members pleaded guilty; researchers exposed The Gentlemen ransomware operator activity;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
f18f5fbaa6842c4d2c110796d9c68cfc77e2bbb835f102e809a4f85ae2af676c
Enrichment time
2026-07-05T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI Seizes NetNut Proxy Platform, Popa Botnet · Baitaphish