All Posts
Anomali Cyber Watch
1
min read

Iran's Cyber Offensive Enters a Dangerous New Phase: What CISOs Must Know on Day 104

Published on
June 12, 2026
Table of Contents
<p> <strong> Threat Assessment Level: ELEVATED </strong> </p> <p> <em> (Maintained from prior cycle; raised due to CVE-2026-10520 active exploitation and imminent Pioneer Kitten weaponization window) </em> </p> <h2> <strong> Introduction </strong> </h2> <p> One hundred and four days into the renewed Iran-Israel conflict, Iranian state-sponsored cyber operations are entering a critical inflection point. While diplomatic channels remain active, the infrastructure being positioned behind the scenes tells a different story: a CVSS 10.0 zero-day in Ivanti Sentry is now under active exploitation with a public proof-of-concept, a previously unknown Iranian espionage group has been unmasked after six years of silent operations across Gulf state governments, and Iranian proxy relay infrastructure is rotating ports in patterns consistent with pre-operational preparation. </p> <p> For CISOs, the message is unambiguous: the window between vulnerability disclosure and weaponization by Iranian APTs has collapsed to 48&ndash;72 hours. If your organization operates Ivanti edge devices, serves Gulf state clients, or sits within the defense industrial base supply chain, the time to act is measured in hours &mdash; not days. </p> <h2> <strong> What Changed </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Development </strong> </p> </th> <th> <p> <strong> Date </strong> </p> </th> <th> <p> <strong> Significance </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> CVE-2026-10520 </strong> (Ivanti Sentry RCE, CVSS 10.0) added to CISA KEV </p> </td> <td> <p> 2026-06-11 </p> </td> <td> <p> Unauthenticated root-level remote code execution; public PoC available. Pioneer Kitten historically weaponizes Ivanti vulns within 48&ndash;72 hours of PoC release. </p> </td> </tr> <tr> <td> <p> <strong> UNC5625 / PINEDROP </strong> campaign publicly attributed by Mandiant </p> </td> <td> <p> 2026-06-12 </p> </td> <td> <p> Previously unknown Iranian-nexus espionage actor operating since 2020, targeting Kuwait, Saudi Arabia, and UAE government and technology sectors with novel DNS DGA command-and-control. </p> </td> </tr> <tr> <td> <p> <strong> ASN 213790 proxy infrastructure refresh </strong> </p> </td> <td> <p> 2026-06-12 </p> </td> <td> <p> Three IPs on Tehran-based hosting rotated to new non-standard ports &mdash; operational readiness indicator for Iranian anonymization relays. </p> </td> </tr> <tr> <td> <p> <strong> APT-linked dual-use node activated </strong> (37.148.2[.]228) </p> </td> <td> <p> 2026-06-12 </p> </td> <td> <p> Iranian IP confirmed as both SSH brute-force scanner and suspected C2 server, tagged "Recently-Linked-to-APT" by Recorded Future. </p> </td> </tr> <tr> <td> <p> <strong> Three ICS advisories </strong> (Brickcom cameras, Naxclow IoT, Siemens KACO inverters) </p> </td> <td> <p> 2026-06-09&ndash;11 </p> </td> <td> <p> Expanded attack surface for surveillance exploitation and energy OT credential theft. </p> </td> </tr> </tbody> </table> <h2> <strong> Conflict &amp; Threat Timeline </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Date </strong> </p> </th> <th> <p> <strong> Event </strong> </p> </th> <th> <p> <strong> Impact </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 2026-02-28 </p> </td> <td> <p> Iran-Israel conflict renewed </p> </td> <td> <p> Cyber operations tempo begins escalating </p> </td> </tr> <tr> <td> <p> 2026-03-24 </p> </td> <td> <p> CyberAv3ngers ICS targeting detected </p> </td> <td> <p> OT/ICS infrastructure enters active threat window </p> </td> </tr> <tr> <td> <p> 2026-03-25 </p> </td> <td> <p> Pioneer Kitten DIB pre-positioning confirmed </p> </td> <td> <p> Defense industrial base supply chain at risk </p> </td> </tr> <tr> <td> <p> 2026-05-22 </p> </td> <td> <p> MuddyWater last observed activity </p> </td> <td> <p> Now 21 days silent &mdash; possible retooling </p> </td> </tr> <tr> <td> <p> 2026-06-08 </p> </td> <td> <p> CVE-2026-42271 (LiteLLM MCP RCE) added to KEV </p> </td> <td> <p> AI/ML gateway infrastructure under active exploitation </p> </td> </tr> <tr> <td> <p> 2026-06-08 </p> </td> <td> <p> Iran declares "resumption of hostilities" </p> </td> <td> <p> Geopolitical trigger for potential cyber escalation </p> </td> </tr> <tr> <td> <p> 2026-06-09 </p> </td> <td> <p> CVE-2026-7473 (Arista EOS) added to KEV </p> </td> <td> <p> IT/OT network segmentation boundaries threatened </p> </td> </tr> <tr> <td> <p> 2026-06-11 </p> </td> <td> <p> CVE-2026-10520 (Ivanti Sentry) added to KEV </p> </td> <td> <p> CVSS 10.0 &mdash; unauthenticated root RCE, PoC public </p> </td> </tr> <tr> <td> <p> 2026-06-12 </p> </td> <td> <p> UNC5625/PINEDROP campaign disclosed </p> </td> <td> <p> Six-year Iranian espionage operation across Gulf states revealed </p> </td> </tr> <tr> <td> <p> 2026-06-12 </p> </td> <td> <p> ASN 213790 port rotation detected </p> </td> <td> <p> Iranian relay infrastructure refreshing for operational use </p> </td> </tr> </tbody> </table> <h2> <strong> Key Threat Analysis </strong> </h2> <h3> <strong> 1. CVE-2026-10520: The Ivanti Sentry Crisis </strong> </h3> <p> This is the most urgent finding of this cycle. CVE-2026-10520 is an OS command injection vulnerability in Ivanti Sentry that allows a <strong> remote, unauthenticated attacker </strong> to achieve root-level code execution. CVSS 10.0. CISA has confirmed active exploitation in the wild, and watchTowr Labs has published a working proof-of-concept on GitHub. </p> <p> <strong> Why this matters for your organization: </strong> Pioneer Kitten (also tracked as UNC757 and Fox Kitten) &mdash; an MOIS-adjacent Iranian threat actor &mdash; has a documented pattern of weaponizing Ivanti vulnerabilities within 48&ndash;72 hours of PoC availability. Their playbook is well-established: exploit edge devices &rarr; establish persistent access &rarr; broker that access to ransomware affiliates or use it for espionage pre-positioning. CISA Advisory AA22-320A documents this exact pattern. </p> <p> A companion vulnerability, <strong> CVE-2026-10523 </strong> , was disclosed in the same advisory. Both affect Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1. </p> <p> <strong> Affected versions: </strong> All Ivanti Sentry instances not updated to R10.5.2, R10.6.2, or R10.7.1. </p> <h3> <strong> 2. UNC5625 / PINEDROP: Six Years of Silent Espionage Unmasked </strong> </h3> <p> Mandiant's Campaign 24.086 reveals <strong> UNC5625 </strong> , a suspected Iranian-nexus espionage actor that has operated undetected since February 2020. Their targets: government entities and technology companies in <strong> Kuwait, Saudi Arabia, and the UAE </strong> . </p> <p> What makes UNC5625 technically notable is their command-and-control architecture: </p> <ul> <li> <strong> DNS-based DGA C2 </strong> : The malware resolves domain names where the IP addresses returned are decoded as ASCII commands &mdash; a technique that evades standard DNS threat feeds relying on domain reputation </li> <li> <strong> Pastebin as secondary C2 </strong> : Living-off-trusted-services to blend with legitimate traffic </li> <li> <strong> Persistence in language pack directories </strong> : Scripts hidden in System32\bg-BG\ and SysWOW64\ar-SA\ subdirectories &mdash; locations rarely monitored by EDR </li> </ul> <p> The PINEDROP backdoor exists in both PowerShell and DLL variants, with the DLL variant (NCObjAPI.dll) compiled as recently as July 2024. </p> <h3> <strong> 3. Iranian Infrastructure Positioning </strong> </h3> <p> Three distinct infrastructure signals emerged this cycle: </p> <p> <strong> ASN 213790 ("Limited Network", Tehran): </strong> Three IPs refreshed with SOCKS4 proxy activity on non-standard ports (4401, 17976, 4843). This ASN has hosted 7+ malicious IPs across multiple Iranian actor groups and represents shared anonymization infrastructure. </p> <p> <strong> ASN 48944 ("Khalij Fars Ettela Resan"): </strong> IP 109.238.181[.]53 active at confidence 71. </p> <p> <strong> ASN 205647 ("Pardis Fanvari Partak"): </strong> IP 37.148.2[.]228 confirmed as dual-use &mdash; both SSH brute-force scanning and suspected C2 server. The "Recently-Linked-to-APT" tag from Recorded Future indicates this node is associated with a named threat group, though specific attribution remains pending. </p> <h3> <strong> 4. Named Threat Actors &mdash; Current Status </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Actor </strong> </p> </th> <th> <p> <strong> Affiliation </strong> </p> </th> <th> <p> <strong> Status (as of 2026-06-12) </strong> </p> </th> <th> <p> <strong> Primary Concern </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> Pioneer Kitten </strong> (UNC757, Fox Kitten) </p> </td> <td> <p> MOIS-adjacent </p> </td> <td> <p> Expected to weaponize CVE-2026-10520 within 48&ndash;72 hrs </p> </td> <td> <p> Edge device exploitation &rarr; access brokering </p> </td> </tr> <tr> <td> <p> <strong> APT42 / Charming Kitten </strong> </p> </td> <td> <p> IRGC-IO </p> </td> <td> <p> Updated in ThreatStream Next-Gen 2026-06-12 </p> </td> <td> <p> Credential harvesting, social engineering </p> </td> </tr> <tr> <td> <p> <strong> UNC5625 </strong> </p> </td> <td> <p> Suspected Iranian-nexus </p> </td> <td> <p> Newly attributed; active since 2020 </p> </td> <td> <p> Gulf state government/tech espionage </p> </td> </tr> <tr> <td> <p> <strong> MuddyWater </strong> (UNC5667/UNC3313) </p> </td> <td> <p> MOIS </p> </td> <td> <p> Silent 21 days &mdash; possible retooling </p> </td> <td> <p> PowerShell-based intrusions, telecom targeting </p> </td> </tr> <tr> <td> <p> <strong> CyberAv3ngers </strong> </p> </td> <td> <p> IRGC-affiliated </p> </td> <td> <p> Quiet 80 days on ICS/OT operations </p> </td> <td> <p> IOCONTROL malware, PLC/HMI targeting </p> </td> </tr> <tr> <td> <p> <strong> APT34 / OilRig </strong> </p> </td> <td> <p> MOIS </p> </td> <td> <p> Active infrastructure on tracked ASNs </p> </td> <td> <p> DNS tunneling, supply chain compromise </p> </td> </tr> </tbody> </table> <h3> <strong> 5. ICS/OT Attack Surface Expansion </strong> </h3> <p> Three new ICS advisories expand the attack surface relevant to Iranian OT-targeting capabilities: </p> <ul> <li> <strong> Brickcom IP Cameras </strong> : Unauthenticated access to live video feeds &mdash; relevant to battle damage assessment (BDA) and surveillance operations </li> <li> <strong> Siemens KACO Blueplanet Inverters </strong> : Credentials derivable from device serial numbers &mdash; energy/solar infrastructure at risk </li> <li> <strong> Naxclow IoT Platform </strong> : Device impersonation and communication interception capabilities </li> </ul> <p> These advisories do not indicate active exploitation but expand the vulnerability surface that actors like CyberAv3ngers have historically targeted. </p> <h2> <strong> Predictive Analysis </strong> </h2> <table> <thead> <tr> <th> <p> <strong> Scenario </strong> </p> </th> <th> <p> <strong> Probability </strong> </p> </th> <th> <p> <strong> Timeframe </strong> </p> </th> <th> <p> <strong> Basis </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Pioneer Kitten begins scanning/exploiting CVE-2026-10520 </p> </td> <td> <p> <strong> 75% (HIGH) </strong> </p> </td> <td> <p> 24&ndash;48 hours </p> </td> <td> <p> Established pattern: Ivanti CVE &rarr; PoC &rarr; weaponization within 48&ndash;72 hrs (per CISA AA22-320A) </p> </td> </tr> <tr> <td> <p> UNC5625 PINEDROP C2 infrastructure generates new subdomains in response to public exposure </p> </td> <td> <p> <strong> 50% (MODERATE) </strong> </p> </td> <td> <p> 48&ndash;72 hours </p> </td> <td> <p> Standard actor response to burned infrastructure is rotation, not abandonment </p> </td> </tr> <tr> <td> <p> MuddyWater resurfaces with retooled capabilities after 21-day silence </p> </td> <td> <p> <strong> 45% (MODERATE) </strong> </p> </td> <td> <p> 7&ndash;14 days </p> </td> <td> <p> Historical pattern of operational pauses preceding new campaign launches </p> </td> </tr> <tr> <td> <p> Pro-Iran hacktivist surge (DDoS, defacement) tied to kinetic escalation </p> </td> <td> <p> <strong> 35% (LOW-MODERATE) </strong> </p> </td> <td> <p> Contingent on kinetic trigger </p> </td> <td> <p> Hacktivist tempo historically correlates with military escalation events </p> </td> </tr> <tr> <td> <p> CyberAv3ngers deploy IOCONTROL variant against energy OT </p> </td> <td> <p> <strong> 30% (LOW-MODERATE) </strong> </p> </td> <td> <p> 14&ndash;30 days </p> </td> <td> <p> 80-day quiet period + expanded OT vuln surface + "resumption of hostilities" declaration </p> </td> </tr> </tbody> </table> <h2> <strong> SOC Operational Guidance </strong> </h2> <h3> <strong> Detection Priorities </strong> </h3> <p> <strong> CRITICAL &mdash; Monitor Immediately: </strong> </p> <table> <thead> <tr> <th> <p> <strong> What to Detect </strong> </p> </th> <th> <p> <strong> ATT&amp;CK Technique </strong> </p> </th> <th> <p> <strong> Detection Logic </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Exploitation of Ivanti Sentry </p> </td> <td> <p> T1190 (Exploit Public-Facing Application) </p> </td> <td> <p> Monitor Ivanti Sentry logs for unauthenticated API calls, unexpected shell spawns, or new cron jobs. Alert on any root-level process creation from Sentry web service context. </p> </td> </tr> <tr> <td> <p> DNS queries to PINEDROP C2 domains </p> </td> <td> <p> T1071.004 (C2: DNS) </p> </td> <td> <p> Alert on DNS queries to kuwaits[.]net, xhyh[.]org, and any subdomain of kuwaits[.]net matching pattern [a-z0-9]{4,6}.kuwaits[.]net. </p> </td> </tr> <tr> <td> <p> Outbound connections to Iranian proxy infrastructure </p> </td> <td> <p> T1090.003 (Multi-hop Proxy) </p> </td> <td> <p> Block/alert on connections to 206.123.156[.]209:4401, 206.123.156[.]233:17976, 206.123.156[.]238:4843, and 37.148.2[.]228. </p> </td> </tr> <tr> <td> <p> SSH brute-force from APT-linked infrastructure </p> </td> <td> <p> T1110.001 / T1110.003 (Password Guessing/Spraying) </p> </td> <td> <p> Correlate failed SSH authentication attempts from 37.148.2[.]228 against all internet-facing SSH services. </p> </td> </tr> </tbody> </table> <p> <strong> HIGH &mdash; Hunt Within 7 Days: </strong> </p> <table> <thead> <tr> <th> <p> <strong> Hunt Hypothesis </strong> </p> </th> <th> <p> <strong> ATT&amp;CK Technique </strong> </p> </th> <th> <p> <strong> Indicators </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> PINEDROP persistence in language pack directories </p> </td> <td> <p> T1053.005 (Scheduled Task) </p> </td> <td> <p> Search for scheduled tasks named windowstoolkits, Intesractives, or UpdateLibrary. Scan for SyncRes.ps1 or CSRR.ps1 in System32\bg-BG\, SysWOW64\ar-SA\, or System32\ar-SA\. </p> </td> </tr> <tr> <td> <p> PINEDROP DLL sideloading </p> </td> <td> <p> T1620 (Reflective Code Loading) </p> </td> <td> <p> Hunt for NCObjAPI.dll in C:\Windows\System32\wbem\. Validate DLL signature &mdash; legitimate NCObjAPI.dll should be signed by Microsoft. </p> </td> </tr> <tr> <td> <p> Pioneer Kitten dormant access in edge devices </p> </td> <td> <p> T1190 + T1078 (Valid Accounts) </p> </td> <td> <p> Audit all Ivanti, Citrix, and Fortinet edge appliances for unauthorized local accounts, unexpected SSH keys, or web shells. Cross-reference with CISA AA22-320A indicators. </p> </td> </tr> <tr> <td> <p> DNS DGA activity consistent with PINEDROP </p> </td> <td> <p> T1568.002 (Dynamic Resolution: DGA) </p> </td> <td> <p> <strong> Baseline DNS query patterns; alert on endpoints generating high-volume queries to uncommon TLDs with random-appearing subdomains (entropy &gt; 3.5 in subdomain label). </strong> </p> </td> </tr> </tbody> </table> <p> <strong> MODERATE &mdash; Ongoing Monitoring: </strong> </p> <table> <thead> <tr> <th> <p> <strong> What to Monitor </strong> </p> </th> <th> <p> <strong> ATT&amp;CK Technique </strong> </p> </th> <th> <p> <strong> Rationale </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Pastebin/text storage site access from servers </p> </td> <td> <p> T1102 (Web Service C2) </p> </td> <td> <p> UNC5625 uses Pastebin as secondary C2. Alert on server-to-Pastebin connections outside developer workstations. </p> </td> </tr> <tr> <td> <p> IP camera firmware/configuration changes </p> </td> <td> <p> T1125 (Video Capture) </p> </td> <td> <p> Brickcom advisory indicates unauthenticated access. Monitor for configuration changes or new streaming sessions on surveillance infrastructure. </p> </td> </tr> <tr> <td> <p> Solar inverter credential access </p> </td> <td> <p> T1552.001 (Credentials in Files) </p> </td> <td> <p> KACO Blueplanet inverters use serial-number-derived credentials. Monitor for authentication attempts using default/predictable credentials. </p> </td> </tr> </tbody> </table> <h2> <strong> Sector-Specific Defensive Priorities </strong> </h2> <h3> <strong> Financial Services </strong> </h3> <p> <strong> Primary threat: </strong> Pioneer Kitten access brokering to ransomware affiliates after exploiting edge devices. UNC5625 targeting of Gulf state technology companies may include fintech providers. </p> <p> <strong> Actions: </strong> </p> <ul> <li> Immediately verify Ivanti Sentry patch status across all branches and data centers </li> <li> Review VPN concentrator and edge device configurations for unauthorized accounts </li> <li> Implement DNS sinkholing for kuwaits[.]net and xhyh[.]org at the enterprise DNS resolver </li> <li> Ensure SWIFT/payment systems are network-segmented from internet-facing edge infrastructure </li> <li> Validate that MFA is enforced on all administrative access to edge appliances (Pioneer Kitten exploits often lead to credential theft for lateral movement) </li> </ul> <h3> <strong> Energy </strong> </h3> <p> <strong> Primary threat: </strong> CyberAv3ngers ICS/OT targeting (dormant but historically active), Siemens KACO inverter credential vulnerability, and Iranian pre-positioning in energy OT networks. </p> <p> <strong> Actions: </strong> </p> <ul> <li> Audit all Siemens KACO Blueplanet inverter deployments; rotate any credentials derived from serial numbers immediately </li> <li> Verify OT/IT network segmentation boundaries &mdash; CVE-2026-7473 (Arista EOS tunnel decapsulation) threatens these boundaries </li> <li> Hunt for IOCONTROL malware variants on Unitronics PLCs and Schneider Electric EcoStruxure systems </li> <li> Ensure all remote access to OT environments requires hardware MFA tokens (not SMS/push) </li> <li> Review Brickcom camera deployments at energy facilities &mdash; unauthenticated video access could enable physical security reconnaissance </li> </ul> <h3> <strong> Healthcare </strong> </h3> <p> <strong> Primary threat: </strong> Ransomware deployment via Pioneer Kitten access brokering. Healthcare organizations running Ivanti mobile device management (MDM) infrastructure are at elevated risk given the Sentry vulnerability. </p> <p> <strong> Actions: </strong> </p> <ul> <li> Emergency patch or isolate all Ivanti Sentry instances managing mobile device enrollment </li> <li> Validate that clinical systems (EHR, PACS, lab systems) cannot be reached from DMZ/edge device networks </li> <li> Implement network detection for SSH brute-force attempts from 37.148.2[.]228 against any internet-facing service </li> <li> Ensure offline backups of critical clinical data are current and tested (ransomware preparedness) </li> <li> Review third-party vendor remote access &mdash; Pioneer Kitten frequently pivots through managed service providers </li> </ul> <h3> <strong> Government (Especially Gulf States) </strong> </h3> <p> <strong> Primary threat: </strong> UNC5625/PINEDROP espionage targeting government entities in Kuwait, Saudi Arabia, and UAE. APT42 credential harvesting campaigns against government officials. </p> <p> <strong> Actions: </strong> </p> <ul> <li> Immediately hunt for PINEDROP indicators: scheduled tasks (windowstoolkits, Intesractives, UpdateLibrary), PowerShell scripts in language pack subdirectories, NCObjAPI.dll in System32\wbem\ </li> <li> Deploy DNS monitoring for high-entropy subdomain queries to .net and .org TLDs (PINEDROP DGA pattern) </li> <li> Audit Pastebin access from government networks &mdash; block or alert on server-initiated connections </li> <li> Review all accounts created since 2020 on domain controllers for potential long-term UNC5625 persistence </li> <li> Brief senior officials on APT42 social engineering tactics (impersonation of journalists, think tank researchers) </li> </ul> <h3> <strong> Aviation &amp; Logistics </strong> </h3> <p> <strong> Primary threat: </strong> Iranian pre-positioning in logistics networks supporting military operations. Pioneer Kitten's expanded targeting profile now spans 11 countries and 8 sectors including transportation. </p> <p> <strong> Actions: </strong> </p> <ul> <li> Audit all Ivanti and Citrix edge devices in airport operations and logistics management networks </li> <li> Verify that cargo management and flight operations systems are segmented from corporate IT </li> <li> Monitor for SSH brute-force and credential spraying against operational technology interfaces </li> <li> Review maritime logistics partner connections &mdash; subsea cable operators and port authorities are within Iranian targeting scope </li> <li> Implement geo-blocking for Iranian ASNs (213790, 48944, 25124, 205647) on all operational systems where feasible </li> </ul> <h2> <strong> Prioritized Defense Recommendations </strong> </h2> <h3> <strong> IMMEDIATE (Within 24 Hours) </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Team </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> 🔴 CRITICAL </strong> </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Patch all Ivanti Sentry instances to R10.5.2/R10.6.2/R10.7.1. </strong> If patching is not possible within 24 hours, isolate Sentry from internet access. CVE-2026-10520 is CVSS 10.0 with active exploitation and public PoC. Pioneer Kitten weaponization expected within 48 hours. </p> </td> </tr> <tr> <td> <p> <strong> 🔴 CRITICAL </strong> </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Deploy DNS blocks/sinkholes </strong> for kuwaits[.]net and xhyh[.]org (PINEDROP C2). Monitor for any historical DNS queries to these domains in the past 6 years (UNC5625 active since 2020). </p> </td> </tr> <tr> <td> <p> <strong> 🔴 HIGH </strong> </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Add Iranian infrastructure IPs to blocklist/watchlist: </strong> 206.123.156[.]209, 206.123.156[.]233, 206.123.156[.]238, 37.148.2[.]228, 109.238.181[.]53, 81.91.157[.]134. Monitor for any outbound connections. </p> </td> </tr> <tr> <td> <p> <strong> 🟠 HIGH </strong> </p> </td> <td> <p> Executive </p> </td> <td> <p> <strong> Activate incident response readiness </strong> for potential Ivanti Sentry compromise. Pre-stage IR retainer, confirm forensic imaging capabilities for edge appliances, and brief legal on potential notification obligations. </p> </td> </tr> </tbody> </table> <h3> <strong> 7-DAY </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Team </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> 🟠 HIGH </strong> </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Conduct PINEDROP threat hunt </strong> across all Windows endpoints: search for scheduled tasks, PowerShell scripts in language subdirectories, and NCObjAPI.dll sideloading (see Hunt Hypotheses above). </p> </td> </tr> <tr> <td> <p> <strong> 🟠 HIGH </strong> </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Audit all Brickcom IP camera deployments </strong> for internet exposure. Segment behind authenticated reverse proxy. Disable unauthenticated RTSP/HTTP streaming. </p> </td> </tr> <tr> <td> <p> <strong> 🟡 MODERATE </strong> </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Rotate credentials on Siemens KACO Blueplanet inverters </strong> where credentials are derived from device serial numbers. Apply firmware updates per ICSA-26-160-02. </p> </td> </tr> <tr> <td> <p> <strong> 🟡 MODERATE </strong> </p> </td> <td> <p> SOC </p> </td> <td> <p> <strong> Baseline DNS query entropy </strong> across the enterprise. Implement alerting for endpoints generating queries with subdomain entropy &gt; 3.5 to uncommon TLDs (DGA detection for PINEDROP and similar). </p> </td> </tr> <tr> <td> <p> <strong> 🟡 MODERATE </strong> </p> </td> <td> <p> IT Ops </p> </td> <td> <p> <strong> Verify Arista EOS patching </strong> for CVE-2026-7473 on all switches enforcing IT/OT segmentation boundaries. </p> </td> </tr> </tbody> </table> <h3> <strong> 30-DAY </strong> </h3> <table> <thead> <tr> <th> <p> <strong> Priority </strong> </p> </th> <th> <p> <strong> Team </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> 🟡 MODERATE </strong> </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Commission proactive threat hunt for Pioneer Kitten/UNC757 dormant access across all Ivanti, Citrix, and Fortinet edge devices. The 80-day absence of DIB targeting signals combined with a new Ivanti KEV creates high probability of imminent activation. </strong> </p> </td> </tr> <tr> <td> <p> <strong> 🟡 MODERATE </strong> </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Evaluate AI/ML infrastructure exposure </strong> to CVE-2026-42271 (LiteLLM MCP RCE). If LiteLLM or MCP toolchains are deployed, ensure they are not internet-accessible and are patched. </p> </td> </tr> <tr> <td> <p> 🔵 STANDARD </p> </td> <td> <p> CTI </p> </td> <td> <p> <strong> Implement Telegram channel monitoring </strong> for pro-Iran hacktivist groups (Handala, Cyber Toufan, DieNet, 313 Team) to restore early warning capability for hacktivist surge operations. </p> </td> </tr> <tr> <td> <p> 🔵 STANDARD </p> </td> <td> <p> CISO </p> </td> <td> <p> <strong> Conduct tabletop exercise </strong> simulating Pioneer Kitten edge device compromise &rarr; lateral movement &rarr; ransomware deployment scenario. Include legal, communications, and executive leadership. </p> </td> </tr> </tbody> </table> <h2> <strong> IOC Blocking Table </strong> </h2> <p> The following network IOCs have been verified through intelligence collection and should be incorporated into defensive controls. File hash indicators for PINEDROP-related samples could not be verified against collected intelligence and have been withheld; consult Anomali ThreatStream Next-Gen for the latest verified file indicators associated with UNC5625/PINEDROP. </p> <table> <thead> <tr> <th> <p> <strong> Type </strong> </p> </th> <th> <p> <strong> Value </strong> </p> </th> <th> <p> <strong> Context </strong> </p> </th> <th> <p> <strong> Action </strong> </p> </th> </tr> </thead> <tbody> <tr> <td> <p> IPv4 </p> </td> <td> <p> 206.123.156[.]209 </p> </td> <td> <p> ASN 213790 SOCKS4 proxy (port 4401) &mdash; Iranian relay infra </p> </td> <td> <p> Block/Monitor </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 206.123.156[.]233 </p> </td> <td> <p> ASN 213790 SOCKS4 proxy (port 17976) &mdash; Iranian relay infra </p> </td> <td> <p> Block/Monitor </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 206.123.156[.]238 </p> </td> <td> <p> ASN 213790 SOCKS4 proxy (port 4843) &mdash; Iranian relay infra </p> </td> <td> <p> Block/Monitor </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 37.148.2[.]228 </p> </td> <td> <p> ASN 205647 &mdash; APT-linked C2 + SSH brute-force </p> </td> <td> <p> Block </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 109.238.181[.]53 </p> </td> <td> <p> ASN 48944 &mdash; Iranian proxy infrastructure </p> </td> <td> <p> Block/Monitor </p> </td> </tr> <tr> <td> <p> IPv4 </p> </td> <td> <p> 81.91.157[.]134 </p> </td> <td> <p> ASN 25124 &mdash; Iranian proxy infrastructure (port 5678) </p> </td> <td> <p> Block/Monitor </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> kuwaits[.]net </p> </td> <td> <p> UNC5625 PINEDROP DGA C2 domain </p> </td> <td> <p> Sinkhole/Block </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> xhyh[.]org </p> </td> <td> <p> UNC5625 PINEDROP C2 domain </p> </td> <td> <p> Sinkhole/Block </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> i7841.kuwaits[.]net </p> </td> <td> <p> PINEDROP DGA subdomain example </p> </td> <td> <p> Block (wildcard *.kuwaits[.]net) </p> </td> </tr> </tbody> </table> <p> Additional IOCs &mdash; including verified file hashes for PINEDROP variants &mdash; are available through Anomali ThreatStream Next-Gen and partner feeds. </p> <h2> <strong> The Bottom Line </strong> </h2> <p> We are at an inflection point. The convergence of three factors demands immediate executive attention: </p> <ol> <li> <strong> A CVSS 10.0 vulnerability in a product that Iranian APTs specialize in exploiting </strong> &mdash; with a public PoC and confirmed active exploitation. The weaponization clock started ticking 24 hours ago. </li> <li> <strong> A six-year Iranian espionage operation just became public </strong> &mdash; meaning UNC5625 will either burn their infrastructure (creating a detection window) or accelerate collection before access is lost. Either way, the next 72 hours are critical for hunting. </li> <li> <strong> MuddyWater's 21-day silence and CyberAv3ngers' 80-day absence </strong> are not signs of reduced threat &mdash; they are signs of preparation. Iranian actors historically go quiet before major operational shifts. </li> </ol> <p> The Iran-Israel conflict is now 104 days old. Every week that passes without a diplomatic resolution increases the probability that pre-positioned cyber access will be activated for destructive purposes. The infrastructure is in place. The vulnerabilities are known. The only question is timing. </p> <p> <strong> Patch Ivanti Sentry today. Hunt for PINEDROP tonight. Brief your board this week. </strong> </p> <p> <em> Published 2026-06-12 | Anomali CTI Desk </em> </p> <p> <em> Intelligence cutoff: 2026-06-12T14:00:00Z </em> </p>

FEATURED RESOURCES

June 12, 2026
Anomali Cyber Watch

Iran's Cyber Offensive Enters a Dangerous New Phase: What CISOs Must Know on Day 104

Read More
June 12, 2026
Anomali Cyber Watch
Public Sector

Three Critical Zero-Days in 72 Hours: What State Government IT Leaders Must Do Now

Read More
June 11, 2026
Anomali Cyber Watch

Iranian Cyber Operations in Strategic Pause — But Pre-Positioning Accelerates Behind the Diplomacy

Read More
Explore All