296K IoT Botnet Strikes, 100+ Water Systems Targeted, SharePoint RCE Chain Exposed + 27 New Threat Stories

0
2

Key Takeaways

  • Attackers continue to rely on low‑friction tricks—fake login pages, bogus software, and social engineering—to gain initial access.
  • Automation and AI are being woven into botnet operations, making threats more adaptive while still requiring human approval for high‑impact actions.
  • Decentralized infrastructure (blockchain‑based C2, cloud‑hosted databases) is rising, complicating takedowns and increasing resilience.
  • Credential‑stealing malware remains prolific, with new families employing sandbox evasion, multi‑stage delivery, and broad data‑harvesting capabilities.
  • Critical sectors such as water utilities and healthcare‑adjacent systems are being scanned and exploited, often via exposed IoT devices.
  • Zero‑day hardware‑level flaws (e.g., HP ThinPro disk‑encryption bypass) show that physical access can still undermine software protections.
  • Enterprise AI tools frequently operate without IT oversight, creating hidden data‑exfiltration pathways.
  • Defenders must patch promptly, enforce least‑privilege controls, and treat any exposed service as a potential entry point.

Social Engineering Attack on ReliaQuest
On August 22, 2026, a threat actor registered a look‑alike domain and hosted a fake ReliaQuest single‑sign‑on page behind a CDN. By impersonating security‑team members via phone calls, the attacker convinced one employee to enter credentials and approve an MFA push, granting a brief, view‑only session on the identity dashboard. ReliaQuest confirmed no systems or customer data were accessed, but noted the tactics align with those used by ShinyHunters and similar extortion groups, including rapid domain turnover and MFA‑push abuse.

Trojanized Productivity Apps via Fake Websites
Cyber‑criminals are luring users with counterfeit websites advertising productivity tools such as Kitchen Canvas, Food or Meal Formula, and DocConvertWizard. The Electron‑based apps appear legitimate but execute injected scripts and abuse desktop‑capture APIs, enabling attackers to harvest data and run arbitrary code once installed. The deception relies on the perceived usefulness of the software to bypass user skepticism.

Live Operator‑Driven Phishing Framework (JWR)
Cisco Talos uncovered an undocumented phishing platform dubbed “JWR” that maintains a real‑time, AES‑CTR‑encrypted WebSocket between victim browsers and the attacker. Unlike static credential‑stealing pages, JWR lets operators steer each session live, exfiltrating payment data, identity documents, SSNs, 2FA codes, and full device fingerprints. The framework appears to be a variant of the Outsider phishing‑as‑a‑service platform.

Android Fraud Bot‑as‑a‑Service (Octagon)
Researchers disclosed Octagon, an Android malware‑as‑a‑service sold by Russian‑speaking actor AndroidKitKat for $1,400 per month. It provides accessibility overlays, hidden VNC, SMS and OTP interception, unlock‑pattern capture, and on‑screen balance reading. After installation, Octagon targets crypto wallets and banking apps while the delivery masquerades as an unrelated utility, illustrating the MaaS model’s ease of deployment.

Rust‑Based Backdoor (C2Looper) Linked to Ransomware
Zscaler ThreatLabz identified a new Rust malware family, C2Looper, likely used by a ransomware‑affiliated actor. Delivered through a multi‑stage ClickFix chain, C2Looper supports remote shell execution, reconnaissance, and deployment of additional tooling. It dynamically resolves Windows APIs, encrypts strings, and a variant leverages GitHub for command‑and‑control communications, showing a trend toward language‑choice flexibility and stealth.

Massive IoT Botnet (Dysphoria) and Residential Proxy Use
The Shadowserver Foundation reported that the Dysphoria botnet has compromised nearly 296,000 IoT devices, primarily for DDoS attacks. Recently, the botnet added residential proxy functionality, allowing attackers to route traffic through compromised home devices and further obscure their origins, illustrating the convergent use of IoT for both volumetric and stealthy operations.

Blockchain‑Based C2 (Aeternum on Polygon)
Palo Alto Networks Unit 42 described Aeternum, a C++ botnet loader that has moved its command‑and‑control entirely to the public Polygon blockchain. Infected devices query public RPC endpoints to retrieve encrypted or plaintext instructions stored in smart contracts. The design leverages decentralization, VM detection, and anti‑AV tactics to create a resilient, low‑cost infrastructure that hinders traditional takedown efforts.

AI‑Enhanced Botnet Controller (ToxNetV2) Using LLM
Joe Security detailed ToxNetV2, an AArch64 Linux peer‑to‑peer botnet whose controller integrates a large language model (LLM) via NVIDIA NIM (z‑ai/glm‑5.2). The controller gathers host and botnet telemetry, sends it to the LLM, parses responses into structured actions, and queues them for operator approval. While not fully autonomous, the AI subsystem enables context‑aware command generation, file writes, SSH, and compilation workflows, demonstrating AI’s role in augmenting—rather than replacing—human‑driven malware operations.

Credential‑Stealing Malware Surge
Several new stealers emerged: Phantom Stealer harvests browser credentials, crypto wallets, and system fingerpieces; Salat Stealer (Go‑based) adds desktop streaming and audio/video capture; Vanta Stealer (Python) targets browsers, messaging apps, gaming platforms, VPNs, and cryptocurrency wallets with heavy obfuscation; DARTHVADER and DestinyStealer propagate via malicious LNK files posing as PDFs; ScarfaceStealer employs an Electron‑based AI‑themed lure and a weighted sandbox‑evasion score to decide execution. These families illustrate a thriving infostealer ecosystem that blends modularity, evasion, and broad data appetite.

ClickFix‑Based Delivery Chains (CNCMachineRMS, Amatera Loader)
ClickFix lures continue to abuse legitimate signed executables (e.g., IBM SPSS IDE) to load malicious DLLs via decoy libraries and benign APIs such as EnumTimeFormatsEx. One chain delivers the CNCMachineRMS RAT, granting interactive shell, file manager, screen capture, and multiple persistence mechanisms. Another chain uses PavinLoader (a loader‑as‑a‑service) leveraging EtherHiding on blockchain to retrieve Amatera Stealer and additional payloads, showing how ClickFix remains a versatile initial‑access vector.

New Modular RAT (Abyssos)
Zscaler identified Abyssos, a C++‑written remote access trojan first seen in June 2026. It uses a custom TCP protocol for C2, supports credential theft, file exfiltration, and VNC‑based remote access, and can download additional modules from its server to expand capabilities. Its modular nature allows threat actors to tailor functionality on the fly, increasing the tool’s longevity in the wild.

Disk‑Encryption Bypass in HP ThinPro (Unpatched Zero‑Day)
AmberWolf warned of an unpatched boot‑chain flaw in HP ThinPro 8 and 9 that lets attackers with physical access bypass TPM‑protected LUKS full‑disk encryption by omitting the Linux kernel and initramfs from the measured‑boot policy. Mitigations include enabling Secure Boot and setting a BIOS password, which only slow an attacker; the encryption should be considered ineffective once the device leaves administrative control, necessitating secure disposal of storage media.

Mobile Threat Landscape (Kaspersky Stats)
Kaspersky reported more than 1.99 million blocked mobile attacks in Q2 2026, with Trojan‑Banker comprising 30.8 % of detected malware. Over 304 k malicious installation packages were found, including 93.5 k banking Trojans and 570 ransomware packages, underscoring the persistent and evolving threat to smartphones from both financial malware and ransomware.

Fake Security Scan Scams (Malwarebytes)
Malwarebytes highlighted a scam campaign using 11 counterfeit websites bearing Microsoft branding (e.g., SysScan) that pretended to scan for antivirus conflicts. The pages coaxed users into uninstalling legitimate security products under the guise of compatibility fixes, then harvested personal information for subsequent refund‑call fraud, illustrating how trust in familiar branding is exploited to weaken defenses.

Privacy Controls Pilot in Windows 11
Microsoft began testing per‑app privacy controls in Windows 11, allowing Insiders to grant or deny camera, microphone, and precise‑location access on an application‑by‑application basis. Moving away from a single device‑wide setting, the feature aims to improve visibility and reduce unnecessary sensor access by desktop apps, addressing a long‑standing privacy gap for traditional software.

Telegram‑Sold RAT (PackClient) Used by TA4922
Proofpoint disclosed PackClient, a RAT and C2 framework marketed on Telegram and employed by Chinese‑speaking threat actor TA4922. The malware consists of a loader, a launcher DLL, a core module, and optional plugins enabling shell commands, SOCKS proxies, webcam streaming, keylogging, and remote desktop functionalities. Campaigns have used tax‑themed lures targeting entities in China, India, and elsewhere, showing how readily available malware lowers the barrier for espionage‑oriented actors.

Cloud‑Hosted C2 (Miraak using PostgreSQL/Timescale)
Blackpoint Cyber observed Miraak, a modular post‑exploitation framework leveraging cloud‑hosted PostgreSQL and Timescale databases for C2. Rather than traditional web endpoints, Miraak registers compromised systems via database connections, retrieves tasks, tracks jobs, and returns results. The use of managed cloud services provides scalability and blends with legitimate traffic, making detection more difficult.

Stored XSS in Microsoft Purview (Account Takeover)
Cymulate demonstrated a stored XSS vulnerability in Microsoft Purview exploitable via a single Teams message, email, or Copilot prompt containing malicious JavaScript. When a compliance reviewer opened the case, the script executed in their authenticated session, exfiltrating access and refresh tokens to an attacker‑controlled server, leading to full impersonation of a privileged identity. Microsoft issued a server‑side fix, but the incident highlights the danger of trusting user‑generated content in trusted portals.

Malicious MCP Server Supply Chain (Deadbugz)
Pillar Security described the Deadbugz campaign, which attempts to distribute a malicious Model Context Protocol (MCP) server through poisoned GitHub pull requests. The server masquerades as a productivity‑suite tool offering text formatting and summarization. After three benign tool calls, runtime‑gated metadata poisoning activates, directing the AI agent to harvest SSH keys, AWS credentials, shell history, and Kubernetes configs while concealing the activity from the user, illustrating a novel supply‑chain vector for AI‑assisted data theft.

Shrinking Exploit Windows (Microsoft Warning)
Microsoft warned that the interval between vulnerability disclosure and active exploitation is shrinking dramatically, fueled by rapid AI‑driven exploit generation and global sharing of proof‑of‑concept code. A flaw announced in the morning can become the focus of scanning and exploitation by afternoon, challenging defenders who must patch thousands of assets. The company proposed a temporary “control plane” centered on network segmentation to add a defensive layer while remediation proceeds.

Hardware‑Attested AI Evidence Standard (TRACE)
The Linux Foundation, together with AMD, Intel, Microsoft, OPAQUE, and TII, released TRACE (Trust, Runtime Attestation and Compliance Evidence), an open standard for hardware‑attested runtime and compliance evidence for AI agents and confidential workloads. TRACE creates a cryptographically verifiable artifact binding runtime environment, software, policies, data classifications, and tool usage, enabling portable proof that AI systems handle data according to policy across clouds and confidential computing environments.

Attacks on U.S. Water and Wastewater Systems
CISA reported that July 2026 cyberattacks targeted over 100 internet‑exposed water and wastewater systems, attributed to Iranian threat actors. The intrusions leveraged programmable logic controllers directly connected to cellular modems, exposing a common misconfiguration. While reducing unnecessary remote access is advised, necessary access must be secured; the use of AI to generate exploit scripts for these devices adds a troubling twist to otherwise simple opportunistic scanning.

Cloaked SEO Poisoning (Chameleon)
Fortra detailed a technique called Chameleon SEO Poisoning, where attackers manipulate search engine results to serve malicious pages only when arrived via a search query, while appearing benign to direct visitors. By cloaking content, they evade standard scanners and maintain longevity. High‑intent keywords such as bank login pages are poisoned to steal credentials, session tokens, and perform adversary‑in‑the‑middle attacks, showing how abuse of legitimate SEO can facilitate phishing at scale.

Malicious Chrome Extension via Fake Google Translate
VMRay Labs observed a multi‑stage attack delivering a Rust binary that drops a malicious Chrome extension masquerading as Google Translate and an AutoIt script deploying the StealC stealer. Once installed, the extension exfiltrates browsing history, credentials, cookies, and grants the attacker live remote control over Chrome windows, mouse/keyboard input, proxy settings, and JavaScript injection, including the ability to replace login forms with iframes while keeping the URL bar unchanged—an advanced AiTM capability.

SharePoint Flaw Probing (CVE‑2026‑55040, CVE‑2026‑63520)
Defused Cyber warned that threat actors are probing two SharePoint vulnerabilities: CVE‑2026‑55040 (JWT token validation bypass) and CVE‑2026‑63520 (improper input validation enabling code execution). Early activity includes JWT bypass followed by admin enumeration and probing of the Business Data Catalog sink; while no code execution was observed yet, the chaining of flaws highlights the risk of unpatched enterprise collaboration platforms.

AI Tools Lack IT Oversight (Reco Report)
Reco’s analysis of 500 published AI agent tools and MCP servers found that only 20 % are governed by IT oversight in enterprise ecosystems, leaving 80 % operating without clear ownership, access tracking, or supervision. Approximately 62 % of the tools can read local data and reach the internet, creating a direct pathway for data exfiltration. The report warns that agents inheriting existing permissions and OAuth grants can trigger actions beyond approved scopes, posing a significant operational risk as AI embeds deeper into business workflows.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here