FBI Seizes NetNut Proxy Platform, Popa Botnet
2026-07-04T19:23:25Z•fbe3cd3623cfcef1de641a17d74dff5e0cdad9153ac6bd8d75795e22abe19d33
AWS-GovCloudAlarum TechnologiesAndroid-botnetCISAFBI-seizureGitHub-leakIoT-botnetKimwolfMeta-AI-abuseMicrosoft-Patch-TuesdayNetNutPopaScattered SpiderThe Gentlemenaccount-takeoverbotnetcredential-leakdomain-takedownexploit-code-publiclaw-enforcementransomwareresidential-proxyvulnerabilities
What happened
Multiple high-impact cyber incidents and law-enforcement actions were reported: the FBI and industry partners seized hundreds of domains tied to NetNut, a residential-proxy platform allegedly operated by NASDAQ-listed Alarum Technologies, after multiple firms linked NetNut to the Popa Android/IoT botnet that has enslaved millions of consumer TV boxes for proxying, ad fraud, account takeovers and large-scale data scraping. Separately, authorities arrested/charged alleged botnet operators (Kimwolf) and Dutch police seized servers and arrested operators of hosting used for Russian cyber activity;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- fbe3cd3623cfcef1de641a17d74dff5e0cdad9153ac6bd8d75795e22abe19d33
- Enrichment time
- 2026-07-04T19:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.