Skip to main content
Emerging ThreatsMalware & Ransomware

Botnets Leverage AI, Public Infrastructure in Sophisticated Attacks

Employees work at desks in an office, one looking concerned, with a cityscape visible through a large window.

Nearly 296,000 devices have been compromised by a botnet named Dysphoria, and that single figure helps explain why this week’s threats read like a catalog of low-friction attack techniques rather than show-stopping novel ideas.

ReliaQuest social‑engineering attempt, August 22, 2026

On August 22, 2026, ReliaQuest confirmed an impersonation campaign that used a lookalike domain and a fake single sign‑on (SSO) page to target its employees. The attacker “stood up a fake ReliaQuest single sign‑on (SSO) page behind a content delivery network,” the company said, then called multiple teammates, “each time posing as a security employee by name.” One teammate entered credentials and approved an MFA push, which “handed the attacker a brief session on our identity dashboard.” ReliaQuest reported the access was view‑only and “no applications or systems were accessed, and no customer data was ever touched.” ReliaQuest also noted the playbook aligns with tactics used by ShinyHunters and other extortion crews, and ShinyHunters had listed the company on its dark‑web portal.

Dysphoria: 296K IoT devices and new residential‑proxy functionality

The Shadowserver Foundation reported that the Dysphoria botnet “targets IoT devices and its primary function appears to be for use in DDoS‑attacks.” Shadowserver confirmed the botnet has compromised nearly 296,000 devices and has recently gained residential proxy functionality, a capability that can obscure operator traffic and complicate attribution and mitigation.

Aeternum on Polygon and ToxNetV2’s LLM feedback loop

Command channels are moving into public infrastructure and AI is being folded into operational workflows. Palo Alto Networks Unit 42 described a C++ botnet loader named Aeternum that “has shifted its C2 infrastructure entirely to the public Polygon blockchain,” writing encrypted and plaintext instructions into smart contracts and relying on public RPC endpoints for infected devices to retrieve commands. At the same time, Joe Security reported that an AArch64 Linux peer‑to‑peer botnet called ToxNetV2 has integrated an LLM: the controller communicates with NVIDIA NIM using the z‑ai/glm‑5.2 model, parsing model responses into structured actions that are queued “for operator approval.” Joe Security emphasized the system is “not fully autonomous or self‑modifying” but that approved AI‑generated actions can reach command execution, file writes, remote SSH, persistent state, and a compilation workflow.

CISA: 100+ internet‑exposed water systems targeted — PLCs and cellular modems

The Cybersecurity and Infrastructure Security Agency (CISA) said July attacks on the U.S. Water and Wastewater Systems (WWS) Sector “targeted over 100 internet‑exposed systems” and attributed the activity to Iranian threat actors. CISA warned the attacks leveraged programmable logic controllers (PLCs) connected directly to cellular modems and cautioned that “directly connecting PLCs to the internet through cellular modems can create significant security risks.” Huntress’ Ben Bernstein described the activity as opportunistic, noting attackers are “ultimately still just walking through a wide open front door,” even as some campaigns make use of AI‑written exploit scripts.

SharePoint CVE‑2026‑55040 and CVE‑2026‑63520 under active probing

Defused Cyber reported active exploitation attempts against two Microsoft SharePoint flaws: CVE‑2026‑55040, an authentication bypass in the JWT token validation pipeline, and CVE‑2026‑63520, an improper input validation that can allow code execution. Defused observed the JWT bypass exercised followed by “heavy admin enumeration and probing of the Business Data Catalog sink behind CVE‑2026‑63520,” though it noted “no code execution observed yet.”

What this means for security teams, water utilities, and AI operators

  • Security teams: Microsoft warned exploit windows are shrinking as disclosures and exploits spread in hours; Microsoft proposed a network‑centered “control plane” to reduce exploitability while patching continues. This bulletin shows attackers blend old vectors (SSO mimicry, fake downloads, exposed PLCs) with new infrastructure (blockchain C2, LLM assistance).
  • Water utilities and critical‑infrastructure operators: CISA’s findings reinforce that PLCs exposed via cellular modems are a high‑risk configuration—remove unnecessary remote access and secure required access, CISA advised.
  • AI service operators and developers: Reco’s finding that “four in five AI tools operate without IT oversight” and Pillar Security’s Deadbugz research—where a malicious MCP server initially appears as a benign “productivity‑suite” and then instructs agents to seek SSH keys and AWS credentials—underscore the need to govern runtime agent behavior and vet third‑party MCP servers.

The week’s record is simple and sharp: attackers keep combining cheap access with flexible tooling. Blockchain contracts, LLMs, fake SSO pages, and exposed PLCs are not equally advanced, but each can yield the same result if defenders leave even one front door open. Patch windows are narrowing, public services are becoming command channels, and AI is being woven into the decision loop—not to replace operators, but to amplify them. The practical takeaway in the reporting is equally plain: reduce exposure, tighten approval flows, and assume the next low‑friction trick will arrive before you finish your next update.

Source: ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories — The Hacker News