IoT Botnets and Water Systems Top ThreatsDay
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
Attackers are getting more creative, but they still lean on a few time-tested tricks: fake login pages, fake security scans, fake productivity apps. Pretending to be useful remains one of the easier ways into a machine. The rest of the week gets stranger—botnets borrowing AI, command traffic hiding in public infrastructure, and exploit windows shrinking again.
This is the ThreatsDay bulletin for the week of August 27, 2026, a roundup of the most notable cybersecurity stories, from a failed extortion attempt against ReliaQuest to a botnet that leverages AI for decision-making.
Social Engineering Attempt Fails
Cybersecurity firm ReliaQuest confirmed that one of its employees was targeted in a social engineering attack on August 22, 2026. Attackers impersonated a member of ReliaQuest's security team, registering a lookalike domain and hosting a fake single sign-on (SSO) page behind a content delivery network. The threat actor called multiple employees, posing as security personnel, to steer them toward the fake page.
One employee fell for the trick, entering their password and approving a push notification, which gave the attacker a brief session on ReliaQuest's identity dashboard. The company said the access was view-only, and no applications or systems were accessed. No customer data was exposed. Although ReliaQuest did not attribute the attack to a specific actor, the playbook aligns with ShinyHunters and other extortion crews, including "an impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator."
"The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network."
— ReliaQuest, in a statement on the incident
ShinyHunters had listed ReliaQuest on its dark web portal. ReliaQuest is tracking a ShinyHunters campaign using domains following the "company[.]claims" pattern, including "reliaquest[.]claims."
Trojanized Productivity Apps
Fake websites advertising productivity software are luring users into downloading malicious Electron-based applications. These apps, such as Kitchen Canvas, Food or Meal Formula, and DocConvertWizard, appear functional but contain hidden malware.
The applications gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. This approach lets attackers run arbitrary code on victims' machines while maintaining a legitimate-looking facade.
Live Operator-Driven Phishing
Cisco Talos detailed an undocumented phishing framework internally branded "JWR." It impersonates checkout and login pages across major payment and shopping platforms. What sets JWR apart is its real-time, operator-driven client engine.
"The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live," Cisco Talos said. "The victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver's license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor's server once a session ends."
JWR is assessed to be a variant of The Outsider phishing-as-a-service (PhaaS) platform, based on similarities in the client engine scripts and functionalities.
Android Fraud Bot for Rent
Researchers at iVerify disclosed Octagon, a previously undocumented Android on-device fraud bot sold as malware-as-a-service (MaaS) by the Russian-speaking actor AndroidKitKat.
"The operator advertises Octagon for $1,400 a month, giving buyers accessibility overlays, hidden VNC, SMS and one-time password interception, unlock-pattern capture, and on-screen balance reading," iVerify said. "It targets crypto wallets and banking apps after installation, while the delivery app can use an unrelated theme."
Rust Backdoor Tied to Ransomware
Zscaler ThreatLabz discovered a new Rust-based malware family called C2Looper, likely used by a ransomware-related threat actor. The malware is delivered through a multi-stage ClickFix infection chain and was first spotted in July 2026.
"C2Looper supports typical backdoor commands including remote shell execution, reconnaissance, and deploying additional malware tooling," Zscaler said. "C2Looper dynamically resolves Windows APIs and encrypts strings." There is also a variant with additional features, including the use of GitHub for command-and-control (C2) communications.
Botnet Targets 296K IoT Devices
The Shadowserver Foundation reported that a botnet named Dysphoria has compromised nearly 296,000 devices. Its primary function appears to be DDoS attacks, but it has recently gained residential proxy functionality, making it more versatile for malicious activities.
This botnet's scale highlights the ongoing risk posed by insecure IoT devices, which are often left with default credentials and unpatched vulnerabilities.
C2 Moves Onto Polygon
Palo Alto Networks Unit 42 detailed Aeternum, a C++ botnet loader that has shifted its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of using centralized servers or domains, attackers write encrypted and plaintext instructions directly via smart contracts.
"Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts," Unit 42 said. "Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands. The Aeternum botnet uses decentralized networks and evasion techniques, such as virtual machine detection and antivirus scanning, to operate effectively. This combination establishes a highly resilient, low-cost threat that complicates existing law enforcement takedown methods."
AI Enters Botnet Workflows
Joe Security reported on ToxNetV2, an AArch64 Linux peer-to-peer botnet that integrates a large language model (LLM) into its controller's operational workflow. The controller uses the z-ai/glm-5.2 model via NVIDIA NIM to make decisions based on telemetry from infected environments.
"The controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval," Joe Security said. "The system is not fully autonomous or self-modifying. The operator remains the final approval point for its higher-impact AI-generated actions. Once approved, however, those actions can reach local command execution, file writes, remote SSH, persistent state, and a compilation workflow."
The AI subsystem resides within a broader Tox-based botnet with encrypted peer-to-peer C2, host-management capabilities, scanner workers, self-propagation logic, and 17 network-attack launchers.
Two Stealers Target Credentials
Researchers at Splunk detailed a new information stealer called Phantom Stealer, which collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints. It has been observed in multiple campaigns across different countries, distributed through phishing lures, cracked software, and malicious links on platforms like Discord and Telegram.
"Since its appearance, Phantom Stealer has been observed in multiple campaigns targeting users across different countries, frequently distributed through phishing lures, cracked software, and malicious links spread via platforms like Discord and Telegram," Splunk said. "Its modular design and relatively low barrier to entry have made it an attractive option for both novice and experienced threat actors, contributing to its growing adoption and making it a persistent and evolving threat in the infostealer landscape."
A second stealer, Salat Stealer, is written in Go and can perform system reconnaissance, conduct credential theft, and monitor victim activity through desktop streaming and audio/video capture.
ClickFix Chain Drops New RAT
LevelBlue uncovered a new remote access trojan (RAT) called CNCMachineRMS, delivered via the BabaDeda Loader. The infection chain starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL.
"Four decoy DLLs load through ordinary Windows import resolution, then the final stage smuggles shellcode into execution via EnumTimeFormatsEx, a benign date-formatting API," LevelBlue said. The trojan provides remote administration, including an interactive shell, file manager, screen capture, local account backdoor, seven persistence mechanisms, and twenty typed commands for executing further payloads.
Modular Abyssos RAT Emerges
Zscaler also reported on Abyssos, a new C++ RAT that supports credential theft, file exfiltration, and remote access via VNC. First detected in June 2026, Abyssos uses a custom TCP protocol for network communication.
"Abyssos supports a number of different network commands and downloads additional modules from the command-and-control (C2) server to enhance its capabilities," Zscaler said.
Unpatched Boot Chain Flaw in HP ThinPro
AmberWolf disclosed a zero-day boot-chain vulnerability in HP ThinPro 8 and 9 that allows physical attackers to bypass TPM full-disk encryption and extract LUKS keys. The flaw stems from an incomplete measured-boot policy that omits the Linux kernel and initramfs.
AmberWolf advises defenders: "turn Secure Boot on and set a BIOS password. Both slow an attacker down; neither closes the PCR gap. Beyond that, treat the encryption as no protection once the device is out of your control. Destroy the M.2 on disposal, and do not rely on ThinPro FDE for a lost or returned unit." The vulnerability remains unpatched.
Mobile Attacks in Q2 2026
Kaspersky data shows more than 1.99 million attacks against mobile devices were blocked in Q2 2026, involving malware, adware, or unwanted software. The Trojan-Banker category was the most prevalent, with a 30.77% share of detected apps. More than 304,000 malicious installation packages were discovered, including 93,574 related to mobile banking trojans and 570 related to ransomware.
New Python Stealer Vanta Stealer
Point Wild disclosed a new Python-based stealer called Vanta Stealer, which combines extensive credential harvesting with layered obfuscation. It targets Chromium-based browsers, Discord, Telegram Desktop, Steam, Riot Games, Roblox, Minecraft, Mullvad VPN, cryptocurrency wallets, and locally stored sensitive documents.
"In addition to harvesting browser passwords, cookies, and stored payment information," Vanta Stealer poses a significant risk to both individuals and organizations.
Why It Matters for Your Organization
These incidents underscore that attackers are constantly refining their methods, whether through social engineering, AI-assisted botnets, or abuse of legitimate platforms like GitHub and public blockchains. The ReliaQuest incident shows that even security companies are not immune to human error—a single employee approving a push notification can lead to a brief but real compromise. The rise of IoT botnets like Dysphoria, with hundreds of thousands of devices, means distributed denial-of-service attacks can be launched with ease, potentially impacting any online service.
For businesses, the key takeaways are clear: enforce robust multi-factor authentication (MFA) policies that resist push-abuse, keep all software patched—especially IoT devices—and consider that even legitimate-looking tools might be Trojanized. The unpatched HP ThinPro flaw reminds us that physical security is equally important; encryption is only as good as its implementation. As AI becomes integrated into botnets, the threat landscape will evolve, but the fundamentals—vigilance, patching, and user awareness—remain critical.
Sources
- The Hacker News Original source
Continue Reading
OpenAI Agents Cheat Test, Breach Hugging Face
An internal OpenAI test went awry, leading AI agents to hack into Hugging Face's network.
Hidden HTML Hijacks AI Email Summarizers
Forcepoint shows invisible text can silently change what an AI assistant reads in your email.
Grid Order Targets Foreign Backdoors
Executive Order 14420 bars risky foreign grid gear, empowering DOE to vet or remove equipment.