HackMyIP
← Back to News
2026-08-27 The Hacker News

Weekly Threat Roundup: IoT Botnets, Phishing Kits, SharePoint RCE

PhishingMalwareThreat Intel

ReliaQuest disclosed a failed extortion attempt on August 22, 2026, after threat actors impersonated an internal security employee via a lookalike domain and fraudulent SSO page. According to the company, attackers registered a domain mimicking ReliaQuest's branding, hosted a fake single sign-on portal behind a content delivery network, and called multiple employees by name to steer them toward the phishing page. One teammate entered credentials and approved an MFA push notification, granting the attacker brief view-only access to the identity dashboard. ReliaQuest confirmed no applications, systems, or customer data were accessed. The playbook matches ShinyHunters' tactics—impersonation calls, disposable domains, MFA push abuse, and rapid authenticator enrollment—which researchers can investigate further using a WHOIS lookup on suspicious registrations. The company subsequently appeared on ShinyHunters' dark web portal alongside the recently tracked "reliaquest[.]claims" domain pattern.

Separately, fake websites advertising productivity software are distributing trojanized Electron-based applications, including Kitchen Canvas, Food or Meal Formula, DocConvertWizard, and various PDF conversion tools. These apps function normally but contain malware capable of dynamically executing injected scripts and accessing desktop capture functionality through Electron APIs, giving attackers persistent visibility into victim machines. In a parallel campaign, security researchers identified an undocumented phishing framework internally branded "JWR" by its developer, designed to convincingly impersonate checkout and login pages across multiple brands. Employees who reused credentials across these fake portals can verify exposure with a password checker and an email breach checker.

Beyond these incidents, the week surfaced several high-impact threats: a 296,000-device IoT botnet borrowing AI techniques to coordinate activity, command-and-control traffic disguised within public infrastructure to evade detection, and over 100 water utility systems targeted by opportunistic scanning. A new SharePoint remote code execution exploit chain also emerged, shrinking the window for defenders to patch before widespread exploitation. The recurring theme across these campaigns—social engineering, trojanized lures, exposed infrastructure—reinforces that attackers continue exploiting low-friction trust gaps wherever defenders leave them.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →