INTEL_REPORT
Krebs on Security · published 7/2/2026, 7:27:33 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
FBI Seizes NetNut Proxy Platform, Popa Botnet The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two …
https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet
sha256:944410c879d59dbb27a3eb2cea2698d29d73bcffe205d2fe9697d47e86b015d4
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | spur.us | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.