
296K IoT Botnet Scans 100+ Water Systems for Exposed HMIs and RTUs
296K IoT devices scanned water utilities for exposed control interfaces. Evidence from DNS and honeynets shows infrastructure overlap with prior OT campaigns. Low segmentation and underfunded defenses create persistent exposure.
The campaign leveraged compromised routers, cameras, and industrial gateways to map public-facing OT assets. Traffic analysis showed repeated probes for default credentials on web interfaces tied to water treatment controls, consistent with patterns seen in prior Mirai variants adapted for infrastructure scanning. Procurement records and job postings from utilities reveal persistent gaps in network segmentation between IT and OT environments that enable such reach. Contract awards for water-sector cybersecurity remain disproportionately low relative to documented exposure; CISA incident reports from 2024-2025 already flagged identical device classes in successful intrusions. The current botnet's command infrastructure overlaps with domains previously used in campaigns against energy and transport operators, indicating reuse rather than novel tooling. Independent verification of targeting came from passive DNS and honeynet telemetry rather than utility disclosures. Official statements continue to classify incidents as generic scanning while downplaying persistent access attempts. Next phase indicators point to credential-stuffing escalation against newly indexed devices within the next 60 days.
CISA: At least five additional water utilities will report credential abuse attempts on HMIs within 45 days.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html)
- [2]Supporting Source(https://www.cisa.gov/news/2025/03/12/cisa-releases-advisory-iot-ot-exposure-water-sector)
- [3]Supporting Source(https://www.shadowserver.org/news/2025-q2-iot-botnet-telemetry-report/)