All Posts
Anomali Cyber Watch
1
min read

Iranian Cyber Operations Enter Pre-Strike Phase: What CISOs Must Do This Week

Published on
June 22, 2026
Table of Contents
<p> <strong> Threat Assessment Level: ELEVATED (trending HIGH) </strong> </p> <p> <em> This assessment is unchanged from the prior cycle (2026-06-21). Escalation to HIGH is pending confirmation of active exploitation against Western critical infrastructure targets. The convergence of infrastructure refresh, phishing reactivation, and ICS vulnerability disclosure creates conditions consistent with imminent offensive operations. </em> </p> <p> Nearly four months into the Iran conflict theater (since 28 February 2026), Iranian state-sponsored cyber operations have shifted from opportunistic exploitation to deliberate pre-positioning. Multiple IRGC and MOIS-affiliated threat groups are simultaneously refreshing command-and-control infrastructure, reactivating phishing campaigns, and diversifying their tooling &mdash; all hallmarks of the preparation phase that precedes coordinated offensive action. </p> <p> This is not theoretical. CISA has confirmed active exploitation of Splunk Enterprise (CVE-2026-20253, CVSS 9.8), issued a hardening directive for Fortinet devices under the "FortiBleed" campaign, and released seven ICS advisories in a single batch covering vendors that Iranian actors have historically targeted. The window for defensive action is narrowing. </p> <h2> <strong> What Changed </strong> </h2> <p> The past 72 hours brought several developments that collectively raise the operational tempo: </p> <ul> <li> <strong> MuddyWater phishing infrastructure reactivated </strong> &mdash; A Firebase-hosted credential harvesting domain (cloud-233f9[.]firebaseapp[.]com) previously used to target CFOs is showing fresh weaponization indicators, alongside a Microsoft typosquat domain (microsoft-corp[.]com) hosted on Stark Industries Solutions infrastructure known to support MuddyWater C2. </li> <li> <strong> New Cobalt Strike C2 node on a fourth Iranian ASN </strong> &mdash; IP 151.239.24[.]122 on Aria Shatel (ASN 31549, Tehran) was validated by multiple threat intelligence sources on 2026-06-19. Iranian C2 infrastructure now spans four distinct autonomous systems, complicating network-level blocking. </li> <li> <strong> Venom RAT appears on Iranian infrastructure </strong> &mdash; A lesser-known remote access tool ("Venom Software") was identified on ASN 213790, marking the first appearance of this framework in Iranian-attributed infrastructure. This suggests tooling diversification beyond Cobalt Strike. </li> <li> <strong> CISA KEV addition: CVE-2026-20253 </strong> &mdash; Splunk Enterprise pre-authentication RCE confirmed actively exploited in the wild. Public proof-of-concept available. Any unpatched instance should be considered compromised until verified. </li> <li> <strong> Seven ICS advisories in a single batch </strong> &mdash; Covering Schneider Electric, Mitsubishi MELSEC, Rockwell Automation, AzeoTech, and AVer &mdash; all vendors whose products are deployed in energy, water, and manufacturing environments that Iranian proxies have previously targeted. </li> <li> <strong> Cyber Av3ngers silent for 9+ days </strong> &mdash; The IRGC-CEC's primary ICS-targeting proxy has gone operationally quiet. Historical pattern: silence precedes capability refresh or new campaign launch. </li> <li> <strong> Pinchy Spider attribution tags on Iranian infrastructure </strong> &mdash; Russian-origin Pinchy Spider (GandCrab/REvil lineage) indicators observed on ASN 213790 alongside chemical sector targeting, suggesting possible Russian-Iranian criminal infrastructure sharing and a blurring of state-sponsored and criminal operations. </li> </ul> <h2> <strong> Conflict &amp; Threat Timeline </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Date </strong> </p> </th> <th> <p> <strong> Event </strong> </p> </th> <th> <p> <strong> Significance </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 2026-02-28 </p> </td> <td> <p> Iran conflict theater begins </p> </td> <td> <p> Start of current escalation cycle </p> </td> </tr> <tr> <td> <p> 2026-06-06 </p> </td> <td> <p> APT34/OilRig last observed active </p> </td> <td> <p> Burst-pattern actor; silence may precede new campaign </p> </td> </tr> <tr> <td> <p> 2026-06-12 </p> </td> <td> <p> Cyber Av3ngers last observed active </p> </td> <td> <p> 9+ days of silence &mdash; anomalous for IRGC-CEC proxy </p> </td> </tr> <tr> <td> <p> 2026-06-17 </p> </td> <td> <p> Tooling convergence confirmed across Pioneer Kitten, Handala, Banished Kitten </p> </td> <td> <p> IRGC-affiliated groups sharing infrastructure and TTPs </p> </td> </tr> <tr> <td> <p> 2026-06-17 </p> </td> <td> <p> MuddyWater C2 infrastructure reactivation detected </p> </td> <td> <p> MOIS-affiliated group refreshing operational capability </p> </td> </tr> <tr> <td> <p> 2026-06-18 </p> </td> <td> <p> CISA adds CVE-2026-20253 to KEV catalog </p> </td> <td> <p> Splunk pre-auth RCE confirmed exploited in the wild </p> </td> </tr> <tr> <td> <p> 2026-06-18 </p> </td> <td> <p> CISA issues FortiBleed hardening directive </p> </td> <td> <p> Government-level response to Fortinet credential exposure </p> </td> </tr> <tr> <td> <p> 2026-06-18 </p> </td> <td> <p> 7 ICS advisories released (Schneider, Mitsubishi, Rockwell) </p> </td> <td> <p> Attack surface expansion for OT environments </p> </td> </tr> <tr> <td> <p> 2026-06-19 </p> </td> <td> <p> New Cobalt Strike C2 validated on ASN 31549 (Tehran) </p> </td> <td> <p> 4th Iranian ASN hosting offensive infrastructure </p> </td> </tr> <tr> <td> <p> 2026-06-21 </p> </td> <td> <p> MuddyWater Firebase phishing domain reactivated </p> </td> <td> <p> Credential harvesting campaign targeting executives </p> </td> </tr> <tr> <td> <p> 2026-06-21 </p> </td> <td> <p> Venom RAT identified on ASN 213790 </p> </td> <td> <p> New C2 framework diversifying Iranian toolkit </p> </td> </tr> <tr> <td> <p> 2026-06-21 </p> </td> <td> <p> Pinchy Spider (REvil lineage) tagged on Iranian IP </p> </td> <td> <p> Possible Russian-Iranian criminal infrastructure sharing </p> </td> </tr> </tbody> </table> <h2> <strong> Key Threat Analysis </strong> </h2> <h3> <strong> MuddyWater (MOIS-Affiliated) &mdash; Active Campaign in Progress </strong> </h3> <p> MuddyWater (also tracked as TEMP.Zagros, Static Kitten, Mercury) is demonstrating textbook pre-operational behavior: refreshing phishing infrastructure across multiple hosting providers while maintaining persistent C2 capability. </p> <p> <strong> Current operational pattern: </strong> </p> <ol> <li> <strong> Delivery: </strong> Compromised legitimate cloud services (Google Firebase, OneHub, Egnyte) host credential harvesting pages </li> <li> <strong> C2: </strong> Stark Industries Solutions VPS infrastructure (Germany-hosted) for command and control via MuddyC2Go </li> <li> <strong> Persistence: </strong> Remote monitoring and management (RMM) tools &mdash; ScreenConnect, Atera &mdash; for long-term access </li> </ol> <p> The reactivation of cloud-233f9[.]firebaseapp[.]com is significant because it exploits implicit trust in Google-hosted domains, bypassing many URL filtering solutions. The simultaneous activity on microsoft-corp[.]com (Stark Industries, IP 80.71.157[.]130) confirms dual-infrastructure operation. </p> <p> <strong> Primary targets: </strong> CFOs and finance executives &mdash; credential harvesting for business email compromise and lateral movement into financial systems. </p> <h3> <strong> Pioneer Kitten / Banished Kitten / Handala (IRGC-Affiliated) &mdash; Infrastructure Expansion </strong> </h3> <p> The IRGC-affiliated cluster continues expanding C2 infrastructure across Iranian ISPs. ASN 213790 ("Limited Network") remains the dominant hosting provider, but the addition of ASN 31549 (Aria Shatel) demonstrates deliberate infrastructure diversification &mdash; a counter-detection measure that complicates IP-based blocking strategies. </p> <p> The appearance of Venom RAT alongside established Cobalt Strike deployments suggests these groups are reducing single-tool dependency, likely in response to improved Cobalt Strike detection capabilities across the defender community. </p> <p> <strong> Notable anomaly: </strong> Pinchy Spider (Russian-origin, GandCrab/REvil ransomware lineage) attribution tags appearing on the same Iranian infrastructure (ASN 213790) with chemical sector targeting. This may indicate Russian-Iranian criminal infrastructure sharing &mdash; a convergence pattern that blurs the line between state-sponsored espionage and criminal ransomware operations. </p> <h3> <strong> Cyber Av3ngers (IRGC-CEC) &mdash; Operational Silence </strong> </h3> <p> Nine days of silence from Iran's most aggressive ICS-targeting proxy is not reassuring &mdash; it's concerning. Historical pattern analysis shows that Cyber Av3ngers operational pauses precede capability refreshes or new campaign launches. The simultaneous release of seven ICS advisories covering their preferred target vendors (Schneider Electric, Mitsubishi MELSEC, Rockwell Automation) creates a convergence window. </p> <p> <strong> Estimated exploitation window: </strong> Based on historical Cyber Av3ngers tempo (14-21 days from vulnerability disclosure to weaponization), potential ICS-targeting activity is forecast within the 7-21 day window from the date of this publication. </p> <h3> <strong> Critical Vulnerabilities Under Active Exploitation </strong> </h3> <table> <thead> <tr> <th> <p> <strong> CVE </strong> </p> </th> <th> <p> <strong> Product </strong> </p> </th> <th> <p> <strong> CVSS </strong> </p> </th> <th> <p> <strong> Status </strong> </p> </th> <th> <p> <strong> Risk </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> CVE-2026-20253 </p> </td> <td> <p> Splunk Enterprise 10.x </p> </td> <td> <p> 9.8 </p> </td> <td> <p> KEV &mdash; Active exploitation confirmed </p> </td> <td> <p> Pre-auth RCE; public PoC available; SIEM infrastructure compromise enables attacker to blind defenders </p> </td> </tr> <tr> <td> <p> FortiBleed (multiple CVEs) </p> </td> <td> <p> Fortinet FortiGate/FortiClient </p> </td> <td> <p> <strong> High </strong> </p> </td> <td> <p> CISA hardening directive issued </p> </td> <td> <p> Mass credential exposure; VPN access compromise; Pioneer Kitten's preferred initial access vector </p> </td> </tr> <tr> <td> <p> CVE-2026-22828 </p> </td> <td> <p> ICS (details in CISA advisories) </p> </td> <td> <p> Varies </p> </td> <td> <p> Advisory issued </p> </td> <td> <p> OT environment exposure </p> </td> </tr> </tbody> </table> <h2> <strong> Predictive Analysis </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Scenario </strong> </p> </th> <th> <p> <strong> Probability </strong> </p> </th> <th> <p> <strong> Timeframe </strong> </p> </th> <th> <p> <strong> Indicators to Watch </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> MuddyWater spearphishing campaign targeting finance/executive roles </p> </td> <td> <p> <strong> HIGH (75-85%) </strong> </p> </td> <td> <p> 24-72 hours </p> </td> <td> <p> Firebase domain in email logs; Microsoft-themed credential pages; Stark Industries IP connections </p> </td> </tr> <tr> <td> <p> Cyber Av3ngers ICS campaign leveraging new Schneider/Mitsubishi/Rockwell vulnerabilities </p> </td> <td> <p> <strong> MODERATE-HIGH (55-65%) </strong> </p> </td> <td> <p> 7-21 days </p> </td> <td> <p> New Unitronics/PLC-targeting domains; IOCONTROL malware variants; Telegram C2 channel activity </p> </td> </tr> <tr> <td> <p> Pioneer Kitten exploitation of unpatched Fortinet devices for initial access </p> </td> <td> <p> <strong> HIGH (70-80%) </strong> </p> </td> <td> <p> Ongoing </p> </td> <td> <p> VPN authentication anomalies; credential stuffing from Iranian IP ranges; FortiGate config changes </p> </td> </tr> <tr> <td> <p> Splunk Enterprise compromise enabling SIEM blinding </p> </td> <td> <p> <strong> MODERATE (45-55%) </strong> </p> </td> <td> <p> 7-14 days </p> </td> <td> <p> Unexpected PostgreSQL service activity; Splunk search head anomalies; log gaps </p> </td> </tr> <tr> <td> <p> Russian-Iranian criminal convergence enabling ransomware with state-actor access </p> </td> <td> <p> <strong> LOW-MODERATE (25-35%) </strong> </p> </td> <td> <p> 30-60 days </p> </td> <td> <p> REvil/GandCrab variants on Iranian infrastructure; chemical sector targeting; dual-use tooling </p> </td> </tr> <tr> <td> <p> Coordinated multi-actor offensive (kinetic-cyber convergence) </p> </td> <td> <p> <strong> MODERATE (40-50%) </strong> </p> </td> <td> <p> Contingent on geopolitical trigger </p> </td> <td> <p> Simultaneous activity across MuddyWater + Cyber Av3ngers + Handala; wiper deployment; DDoS surge </p> </td> </tr> </tbody> </table> <h2> <strong> SOC Operational Guidance </strong> </h2> <h3> <strong> Detection Priorities </strong> </h3> <table> <thead> <tr> <th> <p> <strong> ATT&amp;CK Technique </strong> </p> </th> <th> <p> <strong> Detection Logic </strong> </p> </th> <th> <p> <strong> Tool/Data Source </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> T1566.001 (Spearphishing Link) </p> </td> <td> <p> Alert on emails containing firebaseapp[.]com URLs or microsoft-corp[.]com links; inspect for credential harvesting page patterns </p> </td> <td> <p> Email gateway, URL sandbox </p> </td> </tr> <tr> <td> <p> T1071.001 (Web Protocols C2) </p> </td> <td> <p> Monitor for HTTPS beaconing to 151.239.24[.]122 and known ASN 213790 ranges; look for regular-interval callbacks (Cobalt Strike default: 60s) </p> </td> <td> <p> NDR, proxy logs, firewall </p> </td> </tr> <tr> <td> <p> T1078.004 (Cloud Accounts) </p> </td> <td> <p> Alert on impossible travel, new OAuth app consents, and token replay for M365/Entra ID accounts &mdash; especially finance/executive roles </p> </td> <td> <p> Azure AD logs, CASB </p> </td> </tr> <tr> <td> <p> T1190 (Exploit Public-Facing Application) </p> </td> <td> <p> Monitor Splunk Enterprise PostgreSQL sidecar (port 5432) for unauthenticated connections; alert on file creation in Splunk system directories </p> </td> <td> <p> Host-based monitoring, Splunk internal logs </p> </td> </tr> <tr> <td> <p> T1133 (External Remote Services) </p> </td> <td> <p> Audit all Fortinet VPN authentications for credential reuse, impossible travel, and connections from Iranian ASN ranges (213790, 31549, 44436, 51396) </p> </td> <td> <p> VPN logs, SIEM correlation </p> </td> </tr> <tr> <td> <p> T1583.001 (Acquire Infrastructure) </p> </td> <td> <p> Track newly registered domains matching microsoft-*[.]com patterns; monitor Stark Industries (ASN 44477) IP space </p> </td> <td> <p> Passive DNS, domain monitoring </p> </td> </tr> <tr> <td> <p> T1102 (Web Service for C2) </p> </td> <td> <p> Detect anomalous outbound traffic to Firebase, OneHub, Egnyte that doesn't match business usage patterns </p> </td> <td> <p> Proxy logs, CASB </p> </td> </tr> <tr> <td> <p> T0890 (Exploitation for ICS Impact) </p> </td> <td> <p> Monitor OT network segments for scanning activity targeting Schneider/Mitsubishi/Rockwell management interfaces </p> </td> <td> <p> OT network monitoring, IDS </p> </td> </tr> </tbody> </table> <h3> <strong> Hunting Hypotheses </strong> </h3> <ol> <li> <strong> Hypothesis: MuddyWater has already harvested credentials via Firebase phishing. </strong> Hunt for: M365 sign-ins from Stark Industries IP ranges (ASN 44477); new mail forwarding rules on executive mailboxes; OAuth app registrations from unfamiliar publishers in the past 14 days. </li> <li> <strong> Hypothesis: Cobalt Strike beacon active on internal network via Iranian C2. </strong> Hunt for: DNS queries or HTTPS connections to 151.239.24[.]122; named pipe creation matching Cobalt Strike defaults (\\.\pipe\msagent_*); PowerShell download cradles with encoded payloads connecting to ASN 31549/213790 ranges. </li> <li> <strong> Hypothesis: Splunk Enterprise already compromised via CVE-2026-20253. </strong> Hunt for: Unexpected files in Splunk $SPLUNK_HOME/var/ directories; PostgreSQL sidecar accepting connections from non-localhost; search head returning incomplete results (log blinding indicator); unauthorized Splunk user accounts. </li> <li> <strong> Hypothesis: Fortinet credentials already exfiltrated via FortiBleed. </strong> Hunt for: VPN sessions from previously unseen geographic locations; multiple VPN users authenticating from the same source IP; FortiGate configuration backups accessed outside maintenance windows; SSL-VPN portal access from Iranian IP ranges. </li> </ol> <h3> <strong> Blocking Actions </strong> </h3> <p> Deploy the following IOC blocklist immediately: </p> <table> <thead> <tr> <th> <p> <strong> Type </strong> </p> </th> <th> <p> <strong> Value </strong> </p> </th> <th> <p> <strong> Context </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> IPv4 </p> </td> <td> <p> 151.239.24[.]122 </p> </td> <td> <p> Cobalt Strike C2, ASN 31549 (Aria Shatel, Tehran) </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 80.71.157[.]130 </p> </td> <td> <p> MuddyWater typosquat hosting (Stark Industries) </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 192.253.248[.]169 </p> </td> <td> <p> APT-tagged, ASN 213790 </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 192.253.248[.]180 </p> </td> <td> <p> APT-tagged, ASN 213790 </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 192.253.248[.]6 </p> </td> <td> <p> Venom RAT C2, ASN 213790 </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 171.22.27[.]16 </p> </td> <td> <p> C2 infrastructure, ASN 213790 </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 77.90.185[.]253 </p> </td> <td> <p> Pinchy Spider/chemical targeting, ASN 213790 </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 185.93.89[.]147 </p> </td> <td> <p> Iranian APT infrastructure </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 217.60.241[.]17 </p> </td> <td> <p> Iranian APT infrastructure </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 217.60.241[.]39 </p> </td> <td> <p> Iranian APT infrastructure </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 87.107.191[.]39 </p> </td> <td> <p> Iranian APT infrastructure </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> cloud-233f9[.]firebaseapp[.]com </p> </td> <td> <p> MuddyWater credential harvesting </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> microsoft-corp[.]com </p> </td> <td> <p> MuddyWater typosquat </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> FileTransfer[.]io </p> </td> <td> <p> MuddyWater file staging (historical) </p> </td> </tr> <tr> <td> <p> URL </p> </td> <td> <p> https://cloud-233f9[.]firebaseapp[.]com/ </p> </td> <td> <p> Active phishing page </p> </td> </tr> <tr> <td> <p> URL </p> </td> <td> <p> http://cloud-233f9[.]firebaseapp[.]com </p> </td> <td> <p> Active phishing page (HTTP variant) </p> </td> </tr> </tbody> </table> <p> Additional IOCs available via Anomali ThreatStream. </p> <h2> <strong> Sector-Specific Defensive Priorities </strong> </h2> <h3> <strong> Financial Services </strong> </h3> <p> MuddyWater's current campaign explicitly targets CFOs and finance executives with credential harvesting. Financial institutions face elevated risk of: </p> <ul> <li> <strong> Business email compromise </strong> via stolen M365 credentials </li> <li> <strong> Wire fraud </strong> following executive mailbox access </li> <li> <strong> Lateral movement </strong> from compromised finance accounts to treasury/payment systems </li> </ul> <p> <strong> Priority actions: </strong> </p> <ul> <li> Enable phishing-resistant MFA (FIDO2/hardware keys) for all finance executives immediately </li> <li> Implement conditional access policies blocking sign-ins from ASN 44477 (Stark Industries) and Iranian IP ranges </li> <li> Deploy email banner warnings for messages containing Firebase URLs from external senders </li> <li> Audit mail forwarding rules on all C-suite and finance team mailboxes for unauthorized entries </li> </ul> <h3> <strong> Energy </strong> </h3> <p> The convergence of seven ICS advisories (Schneider Electric EcoStruxure/PowerLogic, Mitsubishi MELSEC iQ-F, Rockwell FactoryTalk Historian) with Cyber Av3ngers' operational silence creates a high-risk window for energy sector OT environments. </p> <p> <strong> Priority actions: </strong> </p> <ul> <li> Inventory all Schneider Electric, Mitsubishi MELSEC, and Rockwell Automation devices on OT networks &mdash; prioritize internet-accessible or DMZ-adjacent instances </li> <li> Apply CISA ICS advisories (ICSA-26-169-03 through ICSA-26-169-07) within 7 days for network-accessible devices </li> <li> Verify OT network segmentation &mdash; ensure no direct path from IT network to PLCs/RTUs without jump server intermediation </li> <li> Establish out-of-band monitoring for Unitronics Vision/Samba PLCs (Cyber Av3ngers' historical targets) </li> <li> Pre-position incident response playbooks for ICS-specific scenarios (safety system manipulation, historian data destruction) </li> </ul> <h3> <strong> Healthcare </strong> </h3> <p> Healthcare organizations running Splunk Enterprise for SIEM/log management face dual risk: CVE-2026-20253 enables attackers to both compromise the monitoring infrastructure AND blind defenders to subsequent lateral movement. </p> <p> <strong> Priority actions: </strong> </p> <ul> <li> Patch Splunk Enterprise to 10.2.4+ or 10.0.7+ immediately &mdash; this is your visibility platform; if it's compromised, you cannot detect anything else </li> <li> If patching requires a maintenance window, disable the PostgreSQL sidecar service as an interim mitigation </li> <li> Verify Splunk search completeness &mdash; run baseline queries and compare result counts against expected volumes to detect potential log manipulation </li> <li> Ensure Fortinet VPN devices (common in healthcare remote access) are covered by the FortiBleed hardening directive </li> </ul> <h3> <strong> Government </strong> </h3> <p> Government entities face the broadest threat surface: MuddyWater credential theft for espionage, Pioneer Kitten for network pre-positioning, and potential destructive operations during escalation. </p> <p> <strong> Priority actions: </strong> </p> <ul> <li> Implement CISA's FortiBleed hardening directive across all Fortinet infrastructure &mdash; rotate credentials, audit VPN logs back to March 2026, verify firmware </li> <li> Conduct credential audit for all .gov M365 tenants &mdash; search for sign-ins from Stark Industries (ASN 44477) and Iranian ASN ranges </li> <li> Review and restrict OAuth application consent policies in Entra ID &mdash; block user-initiated consent for unverified publishers </li> <li> Ensure EINSTEIN/CDM sensors are tuned for the IOCs listed in this bulletin </li> <li> Brief executive leadership on the potential for coordinated cyber-kinetic operations tied to geopolitical escalation </li> </ul> <h3> <strong> Aviation &amp; Logistics </strong> </h3> <p> While not the primary target in this cycle, aviation and logistics organizations should note Pioneer Kitten's historical targeting of transportation sector VPN infrastructure and the chemical sector targeting observed on Iranian infrastructure. </p> <p> <strong> Priority actions: </strong> </p> <ul> <li> Audit all Fortinet and Cisco VPN concentrators for unauthorized access &mdash; Pioneer Kitten exploits edge devices for initial access </li> <li> Review supply chain connections to chemical sector partners (potential lateral targeting via Pinchy Spider/Iranian convergence) </li> <li> Ensure cargo management and flight operations systems are segmented from general IT networks </li> <li> Monitor for reconnaissance activity against publicly exposed OT interfaces (baggage handling, fuel management systems) </li> </ul> <h2> <strong> Prioritized Defense Recommendations </strong> </h2> <h3> <strong> IMMEDIATE (Within 24 Hours) </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 1 </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Patch Splunk Enterprise </strong> to 10.2.4+ or 10.0.7+. If patching is delayed, disable PostgreSQL sidecar service. CVE-2026-20253 is KEV with public PoC &mdash; assume exploitation attempts are ongoing. </p> </td> </tr> <tr> <td> <p> 2 </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Execute CISA FortiBleed hardening directive </strong> &mdash; rotate ALL Fortinet device credentials, audit VPN logs for unauthorized access since March 2026, verify firmware versions against advisory. </p> </td> </tr> <tr> <td> <p> 3 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Deploy IOC blocklist </strong> (see table above) across perimeter firewalls, email gateways, web proxies, and EDR platforms. </p> </td> </tr> <tr> <td> <p> 4 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Alert on Firebase phishing </strong> &mdash; create detection rule for emails containing firebaseapp[.]com URLs sent to finance/executive distribution lists. </p> </td> </tr> <tr> <td> <p> 5 </p> </td> <td> <p> Identity Team </p> </td> <td> <p> <strong> Audit executive M365 accounts </strong> &mdash; check for unauthorized mail forwarding rules, OAuth app consents, and sign-ins from ASN 44477 or Iranian IP ranges in the past 30 days. </p> </td> </tr> </tbody> </table> <h3> <strong> 7-DAY </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 6 </p> </td> <td> <p> OT/ICS Team </p> </td> <td> <p> <strong> Patch ICS infrastructure </strong> per CISA advisories ICSA-26-169-03 through -07 (Mitsubishi MELSEC, Schneider Electric, Rockwell FactoryTalk). Prioritize network-accessible instances. </p> </td> </tr> <tr> <td> <p> 7 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Deploy Venom RAT detection </strong> &mdash; add Venom Software malware family signatures to EDR; create network detection for C2 traffic to 192.253.248[.]6 and ASN 213790 ranges. </p> </td> </tr> <tr> <td> <p> 8 </p> </td> <td> <p> Identity Team </p> </td> <td> <p> <strong> Implement phishing-resistant MFA </strong> (FIDO2 keys) for all C-suite and finance roles. Disable SMS/phone-call MFA fallback for these accounts. </p> </td> </tr> <tr> <td> <p> 9 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Conduct threat hunt </strong> for MuddyWater persistence &mdash; search for ScreenConnect, Atera, or other RMM tools not sanctioned by IT; check for PowerShell execution patterns consistent with MuddyC2Go. </p> </td> </tr> <tr> <td> <p> 10 </p> </td> <td> <p> Network Team </p> </td> <td> <p> <strong> Block ASN 213790 at perimeter </strong> &mdash; evaluate feasibility of blocking entire "Limited Network" ASN ranges given concentration of Iranian offensive infrastructure. Assess collateral impact before implementing. </p> </td> </tr> </tbody> </table> <h3> <strong> 30-DAY </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Owner </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 11 </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Commission OT security assessment </strong> &mdash; engage third-party to evaluate segmentation, monitoring, and incident response readiness for ICS environments, specifically against Cyber Av3ngers TTPs. </p> </td> </tr> <tr> <td> <p> 12 </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Evaluate OSINT feed alternatives &mdash; current intelligence collection has a critical blind spot for geopolitical trigger events. Assess Feedly Threat Intel, Silobreaker, or Flashpoint as supplementary sources. </strong> </p> </td> </tr> <tr> <td> <p> 13 </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Proactive hunt for Cyber Av3ngers infrastructure refresh </strong> &mdash; search for new Unitronics/PLC-targeting domains, IOCONTROL malware variants, and Telegram-based C2 channels. Nine days of silence from IRGC-CEC's primary ICS proxy is historically a pre-attack indicator. </p> </td> </tr> <tr> <td> <p> 14 </p> </td> <td> <p> IR Team </p> </td> <td> <p> <strong> Update incident response playbooks </strong> for coordinated multi-vector Iranian attack scenario &mdash; simultaneous credential theft (MuddyWater), network access (Pioneer Kitten), ICS disruption (Cyber Av3ngers), and information operations (Handala). </p> </td> </tr> <tr> <td> <p> 15 </p> </td> <td> <p> Executive </p> </td> <td> <p> <strong> Tabletop exercise </strong> &mdash; scenario: Iranian retaliatory cyber operation following geopolitical escalation. Test decision-making for simultaneous IT and OT incidents with potential safety implications. </p> </td> </tr> </tbody> </table> <h2> <strong> The Bottom Line </strong> </h2> <p> We are 114 days into an active conflict theater where Iranian cyber operations serve as force multipliers for kinetic military objectives. The intelligence picture is clear: multiple Iranian state groups are simultaneously refreshing infrastructure, reactivating campaigns, and diversifying tooling. This is not routine maintenance &mdash; it is preparation. </p> <p> The convergence of three factors makes the next 7-21 days a critical defensive window: </p> <ol> <li> <strong> MuddyWater's phishing infrastructure is hot </strong> &mdash; expect credential harvesting attempts against executives within 72 hours </li> <li> <strong> Cyber Av3ngers' silence will break </strong> &mdash; nine days of quiet from an aggressive ICS proxy, combined with seven fresh ICS vulnerability disclosures covering their preferred targets, creates conditions for a new campaign </li> <li> <strong> Your SIEM may be the target </strong> &mdash; CVE-2026-20253 gives attackers the ability to compromise Splunk Enterprise without authentication, potentially blinding your entire detection capability before the main attack begins </li> </ol> <p> The organizations that act on this intelligence in the next 24-48 hours &mdash; patching Splunk, hardening Fortinet, blocking known C2 infrastructure, and hunting for existing compromise &mdash; will be positioned to detect and contain what comes next. Those that wait will be responding to incidents instead of preventing them. </p> <p> Patch. Block. Hunt. Now. </p> <p> <em> Published 2026-06-22 by the Anomali CTI Desk. Intelligence derived from Anomali ThreatStream, CISA advisories, and partner feeds. IOCs available for automated ingestion via ThreatStream platform. </em> </p> <p> <em> For questions or to request additional analysis, contact your Anomali account team. </em> </p>

FEATURED RESOURCES

June 22, 2026
Anomali Cyber Watch

Iranian Cyber Operations Enter Pre-Strike Phase: What CISOs Must Do This Week

Read More
June 22, 2026
Anomali Cyber Watch
Public Sector

Critical Infrastructure Under Siege: Splunk RCE, FortiBleed Fallout, and China's Supply Chain Offensive Converge on State Government

Read More
June 19, 2026
Anomali Cyber Watch

Iran's Cyber Forces Are Converging: FortiBleed, Cisco KEV, and the Access-to-Destruction Pipeline

Read More
Explore All