Dysphoria Botnet Compromises Nearly 296,000 IoT Devices

Nearly 296,000 internet-connected devices have been compromised by the Dysphoria botnet, which appears to be intended primarily for distributed denial-of-service attacks and has recently gained residential proxy functionality, the Shadowserver Foundation said. The disclosure comes in a week that also saw more than 100 internet-exposed U.S. water and wastewater systems targeted and Microsoft SharePoint vulnerabilities probed in honeypot activity.
Dysphoria illustrates the continuing value of exposed connected devices to criminal operators. A compromised IoT estate can be used for DDoS activity, while proxy functionality can provide traffic paths through residential connections. The report did not identify the device types involved or attribute the botnet to a named group.
Exposed systems remain a common entry point
CISA said Iranian threat actors targeted more than 100 internet-exposed systems in the U.S. Water and Wastewater Systems Sector during attacks in July. The activity involved programmable logic controllers connected directly to cellular modems. CISA warned that directly connecting PLCs to the internet through cellular modems can create significant security risks.
The agency said reducing internet exposure does not require disabling necessary remote access. Organizations should remove remote access when it is unnecessary and secure it where it is required. Huntress' Ben Bernstein characterized the activity as opportunistic, automated scanning against publicly accessible systems, while noting that attackers were using AI tools to write exploit scripts for these devices.
SharePoint chain is being tested
Defused Cyber reported that attackers were exercising two Microsoft SharePoint flaws against its honeypots: CVE-2026-55040, an authentication bypass in the JWT token validation pipeline, and CVE-2026-63520, an improper input-validation issue in Microsoft Office SharePoint that can allow code execution. Its observations showed the JWT bypass followed by substantial administrator enumeration and probing of the Business Data Catalog sink associated with CVE-2026-63520.
No code execution had been observed in those honeypots at the time of the report. Even so, the sequence demonstrates why defenders need to treat public vulnerability disclosures and internet-facing services as an operational priority rather than a routine maintenance item.
Botnet operators are also changing their infrastructure
Other findings show attackers adapting both command infrastructure and operational workflows. Palo Alto Networks Unit 42 said the Aeternum C++ botnet loader shifted its command-and-control infrastructure entirely to the public Polygon blockchain, using smart contracts and public RPC endpoints for instructions. Joe Security described ToxNetV2 as an AArch64 Linux peer-to-peer botnet whose controller uses NVIDIA NIM with the z-ai/glm-5.2 model to propose structured actions from host and botnet telemetry, subject to operator approval.
For businesses, the practical implication is to maintain an accurate inventory of externally reachable devices and services, eliminate unnecessary access paths, secure the remote connections that remain, and rapidly assess exposed systems when new flaws or active probing emerge.

