IoT Botnet Water Systems SharePoint Exploits ThreatsDay Report

Threat Overview

The latest ThreatsDay bulletin, published by The Hacker News on 2026‑08‑27, maps a sprawling landscape of cyber‑threats that span industrial control systems, cloud services, and everyday productivity tools. At its core is a 296,000‑device IoT botnet named Dysphoria, a wave of attacks on more than 100 water and wastewater systems, and a new SharePoint remote code execution chain that exploits two CVEs. The report also documents 27 additional stories ranging from AI‑assisted phishing to blockchain‑backed command‑and‑control, highlighting how attackers are increasingly blending technical sophistication with low‑friction human factors.

Key Threats

1. Dysphoria IoT Botnet

Dysphoria compromises a wide range of connected devices by exploiting known firmware vulnerabilities. Its primary goal is volumetric DDoS attacks, but the botnet has recently gained residential proxy capabilities, allowing attackers to tunnel traffic through compromised devices. When combined with the 100+ exposed water systems, Dysphoria can serve as a foothold for lateral movement into critical infrastructure.

2. Water System Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) reported that Iranian threat actors targeted over 100 internet‑exposed water systems in July 2026. The attacks leveraged programmable logic controllers connected directly to cellular modems, creating a direct path for exploitation. The attackers used AI to craft scripts that identify and exploit PLC firmware flaws, underscoring the need for stringent network segmentation and secure remote access.

3. SharePoint RCE Chain

Defused Cyber warned that threat actors are chaining two Microsoft SharePoint flaws – CVE-2026-55040 and CVE-2026-63520 – to gain remote code execution. The first flaw allows authentication bypass in the JWT token validation pipeline, while the second flaw enables code execution via improper input validation within Microsoft Office SharePoint. Attackers can enumerate administrative accounts and probe the Business Data Catalog, potentially escalating privileges to system‑level access.

4. Fake Social Engineering and Malware Delivery

ReliaQuest experienced a social‑engineering incident where an attacker impersonated a security employee, registered a lookalike domain, and lured a staff member to a fake SSO page. Though access was read‑only, the attack demonstrated the continued effectiveness of MFA push abuse. Additionally, fake productivity apps (Electron‑based) and fake security scans now deliver malware through deceptive download links. These campaigns often employ dynamic script injection and desktop‑capture APIs to exfiltrate data silently.

5. Advanced Phishing and Malware‑as‑a‑Service

Twitter and Telegram channels host new phishing frameworks such as JWR, which uses a live operator‑driven WebSocket to steer victims in real time, capturing not only payment data but also identity documents and 2FA codes. Android banking malware Octagon, sold for $1,400/month, can intercept SMS OTPs and read crypto wallets. The Chinese‑speaking TA4922 uses PackClient, a RAT sold via Telegram, to deliver a payload that supports remote desktop, file management, and webcam streaming.

6. AI‑Enabled Botnets and Blockchain C2

ToxNetV2 now integrates an LLM (NVIDIA NIM) into its decision loop, allowing operators to approve high‑impact actions after AI analysis. Aeternum shifts its command channel to the Polygon blockchain, using smart contracts to issue instructions that evade traditional takedown methods. Meanwhile, the Miraak post‑exploitation framework leverages cloud‑hosted PostgreSQL for command execution, making it difficult to detect using conventional network sensors.

7. Credential Stealers and Ransomware

New stealer families such as Vanta, Scarface, Phantom, Salat, DARTHVADER, and DestinyStealer exploit a variety of delivery vectors: phishing emails, fake installer bundles, and malicious LNK files. They harvest browser passwords, cryptocurrency wallets, VPN credentials, and even webcam footage, often using sophisticated anti‑sandbox checks and multilayered obfuscation. A newly discovered RAT, CNCMachineRMS, is delivered via the ClickFix chain and offers remote shell, persistence, and stealth features.

8. Other Emerging Threats

Malwarebytes reports fake Microsoft security scans that prompt users to uninstall legitimate antivirus software. A new Chrome extension masquerading as Google Translate steals browser data and allows live remote control. The Deadbugz supply‑chain attack injects malicious MCP servers into GitHub pull requests, coercing AI agents into extracting SSH keys and cloud credentials. Microsoft’s own Purview vulnerability allows a single malicious message to execute stored XSS, leading to token theft and account takeover.

Recommendations for Defenders

  • Patch Rapidly. Microsoft warns that exploit windows are shrinking; adopt a zero‑trust network model and apply critical patches within 24–48 hours.
  • Secure Remote Access. Disable unnecessary internet exposure for PLCs and critical devices; enforce MFA and device‑level segmentation.
  • Monitor for Blockchain‑Based C2. Use blockchain analytics to flag unusual contract interactions and block traffic to known Polygon smart‑contract endpoints.
  • Deploy AI‑Aware Anomaly Detection. Implement solutions that detect AI‑generated traffic patterns and block LLM‑based command flows.
  • Implement Layered Defense at the Endpoint. Deploy EDR that can detect Electron‑based injection, fake SSO pages, and ransomware‐style persistence mechanisms.
  • Control Third‑Party Code. Vet all external libraries, especially MCP servers and AI agents, for data‑exfiltration capabilities and enforce IT oversight.
  • Educate Users. Conduct regular phishing simulations and train staff to verify domain authenticity before entering credentials.
  • Adopt Trace‑Standard for AI. Integrate the TRACE open specification to ensure hardware‑attested runtime evidence for AI workloads.

Conclusion

The ThreatsDay bulletin underscores that the line between “advanced” and “ordinary” is blurring. Whether it’s a botnet using a public blockchain for command and control or a simple fake login page, attackers rely on exposed trust points and human opportunism. By hardening infrastructure, tightening patch cycles, and embedding AI‑aware detection, defenders can reduce the attack surface and mitigate the high‑impact threats highlighted in this report.

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading