INTEL_REPORT
Krebs on Security · published 6/18/2026, 5:37:58 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASD…
https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm
sha256:34e5e63371652dc9b4792278028fe24b34b64fe59bfbc0d587472e769427c3f0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| synthient.com |
| Open → |