All Posts
Anomali Cyber Watch
1
min read

Iran's Cyber War Machine Isn't Stopping for Peace Talks — What CISOs Need to Know Now

Published on
May 25, 2026
Table of Contents
<p> <strong> Threat Assessment Level: HIGH </strong> </p> <p> Eighty-six days into the US-Iran conflict that began on February 28, 2026, Iranian cyber operations are running at confirmed wartime tempo &mdash; and the emerging peace negotiations are making things <em> more </em> dangerous, not less. While diplomats describe a deal as a "work in progress," IRGC and MOIS-affiliated threat actors are exploiting industrial control systems, deploying new espionage backdoors at industrial scale, and conducting destructive wiper attacks against Western targets. </p> <p> History is unambiguous on this point: diplomatic pauses are when Iranian operators consolidate access, not when they stand down. If your organization operates critical infrastructure, supports the defense industrial base, or runs ICS/SCADA environments, the next 30 days represent a peak risk window. </p> <h2> <strong> What Changed </strong> </h2> <p> Recent intelligence updates have brought four developments that shift the operational picture: </p> <ul> <li> <strong> <strong> HYDRO KITTEN confirmed exploiting Rockwell Automation PLCs </strong> &mdash; CrowdStrike confirmed (2026-05-22) that in late February 2026, the IRGC-CEC-affiliated group exploited CVE-2021-22681 to bypass authentication on Allen Bradley PLCs running RSLogix 5000 (versions 20&ndash;38). This marks an expansion from Unitronics PLCs to Rockwell Automation &mdash; broadening the ICS attack surface across US industrial infrastructure. </strong> </li> </ul> <ul> <li> <strong> UNC1549 deployed POLLREGISTER backdoor via fake telecom recruitment </strong> &mdash; Google Threat Intelligence confirmed (2026-05-24) that UNC1549 (Imperial Kitten/Smoke Sandstorm/TA455) launched a recruitment-themed phishing campaign impersonating T-Mobile careers, delivering a new backdoor via DLL sideloading with WebSocket Secure C2 communications. This is the seventh-plus malware variant from this group in six months. </li> </ul> <ul> <li> <strong> US law enforcement publicly attributed "Handala Hack" to MOIS </strong> &mdash; Three independent sources (Check Point, CyberExpress, Foundation for Defense of Democracies) confirmed that the Handala hacktivist persona is operated by Void Manticore (Red Sandstorm), a MOIS-affiliated destructive operations unit responsible for the Stryker wiper attack in March 2026. Attribution was confirmed by US law enforcement on 2026-03-27. </li> </ul> <ul> <li> <strong> MuddyWater has been operationally silent for five months </strong> &mdash; The most historically prolific Iranian APT group has not had a confirmed operation since its UDPGangster backdoor deployment in December 2025. Extended silence during an active military conflict is a strong indicator of retooling for a major operation, not de-escalation. </li> </ul> <h2> <strong> Conflict &amp; Threat Timeline </strong> </h2> <table> <thead> <tr> <th> <p> Date </p> </th> <th> <p> Event </p> </th> <th> <p> Actor </p> </th> <th> <p> Significance </p> </th> </tr> </thead> <tbody> <tr> <td> <p> 2025-12 </p> </td> <td> <p> UDPGangster backdoor deployed </p> </td> <td> <p> MuddyWater (MOIS) </p> </td> <td> <p> Last confirmed MuddyWater operation &mdash; now 5 months silent </p> </td> </tr> <tr> <td> <p> 2025-12 </p> </td> <td> <p> POLLREGISTER infrastructure staged </p> </td> <td> <p> UNC1549 (IRGC) </p> </td> <td> <p> Pre-conflict positioning of telecom espionage capability </p> </td> </tr> <tr> <td> <p> 2026-02-28 </p> </td> <td> <p> US announces major combat operations against Iran </p> </td> <td> <p> &mdash; </p> </td> <td> <p> Conflict start; kinetic + cyber operations begin simultaneously </p> </td> </tr> <tr> <td> <p> Late Feb 2026 </p> </td> <td> <p> CVE-2021-22681 exploited against Rockwell PLCs </p> </td> <td> <p> HYDRO KITTEN (IRGC-CEC) </p> </td> <td> <p> First confirmed ICS compromise of the conflict </p> </td> </tr> <tr> <td> <p> 2026-03-12 </p> </td> <td> <p> Handala = Void Manticore attribution published </p> </td> <td> <p> Check Point Research </p> </td> <td> <p> MOIS destructive ops unmasked </p> </td> </tr> <tr> <td> <p> 2026-03-13 </p> </td> <td> <p> Stryker wiper attack confirmed (20+ systems) </p> </td> <td> <p> Handala/Void Manticore </p> </td> <td> <p> Destructive capability demonstrated against defense sector </p> </td> </tr> <tr> <td> <p> 2026-03-27 </p> </td> <td> <p> US law enforcement confirms Handala = Iranian state </p> </td> <td> <p> FDD reporting </p> </td> <td> <p> Plausible deniability removed </p> </td> </tr> <tr> <td> <p> 2026-05-19 </p> </td> <td> <p> CISA advisory: Siemens RUGGEDCOM APE1808 PAN-OS vuln </p> </td> <td> <p> &mdash; </p> </td> <td> <p> OT perimeter devices at risk of unauthenticated RCE </p> </td> </tr> <tr> <td> <p> 2026-05-20&ndash;22 </p> </td> <td> <p> 10 CVEs added to CISA KEV in 3 days </p> </td> <td> <p> &mdash; </p> </td> <td> <p> Accelerated exploitation across multiple product families </p> </td> </tr> <tr> <td> <p> 2026-05-21 </p> </td> <td> <p> 5 ICS advisories in single day (ABB, Hitachi Energy) </p> </td> <td> <p> CISA </p> </td> <td> <p> Expanding ICS attack surface: ABB B&amp;R, Hitachi GMS600 </p> </td> </tr> <tr> <td> <p> 2026-05-22 </p> </td> <td> <p> HYDRO KITTEN profile updated with Rockwell exploitation </p> </td> <td> <p> CrowdStrike </p> </td> <td> <p> Confirmation of ICS access to Allen Bradley PLCs </p> </td> </tr> <tr> <td> <p> 2026-05-24 </p> </td> <td> <p> UNC1549 six new RAT variants confirmed </p> </td> <td> <p> Unit 42 </p> </td> <td> <p> MiniUpdate, MiniJunk V2 targeting aerospace/defense </p> </td> </tr> <tr> <td> <p> 2026-05-25 </p> </td> <td> <p> Peace deal described as "work in progress" </p> </td> <td> <p> ABC News/Rubio </p> </td> <td> <p> Negotiation phase = maximum pre-positioning incentive </p> </td> </tr> </tbody> </table> <h2> <strong> Key Threat Analysis </strong> </h2> <h3> <strong> HYDRO KITTEN &mdash; ICS/OT Escalation Beyond Unitronics </strong> </h3> <p> <strong> Aliases: </strong> Cyber Av3ngers, BAUXITE, SoldiersOfSolomon, APT Iran </p> <p> <strong> Affiliation: </strong> IRGC Cyber-Electronic Command (CEC) </p> <p> <strong> Target: </strong> US and Israeli critical infrastructure &mdash; water, fuel, energy </p> <p> HYDRO KITTEN's exploitation of CVE-2021-22681 (Rockwell RSLogix 5000 authentication bypass) represents a significant capability escalation. Previously known for targeting Unitronics Vision PLCs in US water systems, the group has now demonstrated access to Rockwell Allen Bradley PLCs &mdash; the dominant PLC platform in US manufacturing, energy, and fuel infrastructure. </p> <p> Their confirmed CVE exploitation portfolio now spans 20+ vulnerabilities including: CVE-2025-0282 (Ivanti), CVE-2024-55591 (Fortinet), CVE-2024-0012 and CVE-2024-9474 (PAN-OS), CVE-2024-47575 (FortiManager), and CVE-2024-53704 (SonicWall). Custom malware includes <strong> IOControl </strong> (ICS backdoor) and <strong> Crucio </strong> (ransomware used as cover for destructive operations). </p> <p> The three-month silence since the February exploitation is not reassuring &mdash; it likely indicates either operational security discipline or a shift to classified operations ahead of a potential negotiation collapse. </p> <h3> <strong> UNC1549 &mdash; Industrialized Espionage Tooling </strong> </h3> <p> <strong> Aliases: </strong> Imperial Kitten, Smoke Sandstorm, TA455, Nimbusmanticore, Screening Serpens </p> <p> <strong> Affiliation: </strong> IRGC </p> <p> <strong> Target: </strong> Telecommunications, aerospace, defense (US, Israel, UAE) </p> <p> UNC1549 is operating what appears to be a continuous delivery pipeline for espionage tools. The newly confirmed <strong> POLLREGISTER </strong> backdoor uses a sophisticated infection chain: </p> <ul> <li> <strong> Recruitment-themed phishing (fake T-Mobile careers site) </strong> </li> </ul> <ul> <li> Malicious ZIP containing a .lnk file that triggers msiexec.exe </li> </ul> <ul> <li> MST file installs legitimate Chrome alongside malicious VERSION.dll </li> </ul> <ul> <li> DLL sideloading via VSWebLauncher.exe establishes persistence </li> </ul> <ul> <li> C2 via HTTPS registration (POST /rg) then upgrades to WebSocket Secure (/ws?token=) </li> </ul> <ul> <li> Azure-hosted infrastructure (cld-global.azurewebsites[.]net) for C2 </li> </ul> <p> The use of Azure Web Apps for C2 makes traffic blend with legitimate cloud communications &mdash; a deliberate choice to evade network-based detection. </p> <h3> <strong> Void Manticore / Handala &mdash; Destructive Operations Unmasked </strong> </h3> <p> <strong> Aliases: </strong> Red Sandstorm </p> <p> <strong> Affiliation: </strong> MOIS (Ministry of Intelligence and Security) </p> <p> <strong> Target: </strong> Israeli defense and technology sector; Western critical infrastructure </p> <p> The public attribution of the "Handala Hack" persona to Void Manticore by US law enforcement removes the thin veneer of hacktivism from what are state-directed destructive operations. The Stryker wiper attack (March 2026) demonstrated the capability to destroy 20+ systems with pre-wipe branding &mdash; a psychological operations technique designed to maximize fear and media coverage. </p> <p> The removal of plausible deniability creates a binary: either Iran escalates under its own flag, or it develops new personas. Either path increases risk. </p> <h3> <strong> MuddyWater &mdash; The Silence That Should Alarm You </strong> </h3> <p> <strong> Aliases: </strong> TEMP.Zagros, Static Kitten, Seedworm </p> <p> <strong> Affiliation: </strong> MOIS subordinate unit </p> <p> <strong> Last confirmed operation: </strong> UDPGangster backdoor deployment (December 2025) </p> <p> MuddyWater is historically the most operationally prolific Iranian APT group. Five months of silence during an active military conflict is not a sign of de-escalation &mdash; it is a strong indicator of retooling for a major operation. This group has consistently demonstrated the ability to rapidly deploy new tooling after quiet periods. </p> <h2> <strong> Predictive Analysis </strong> </h2> <p> Based on the current intelligence picture, historical Iranian operational patterns, and the negotiation-under-fire geopolitical context: </p> <table> <thead> <tr> <th> <p> Scenario </p> </th> <th> <p> Probability </p> </th> <th> <p> Timeframe </p> </th> <th> <p> Indicators to Watch </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Handala/Cyber Toufan release new destructive claims timed to peace negotiation milestones </p> </td> <td> <p> <strong> 60% </strong> </p> </td> <td> <p> 7&ndash;14 days </p> </td> <td> <p> Telegram channel activity; new data leak sites; defacement campaigns </p> </td> </tr> <tr> <td> <p> UNC1549 pivots POLLREGISTER infrastructure to target DIB contractors </p> </td> <td> <p> <strong> 35% </strong> </p> </td> <td> <p> 7&ndash;21 days </p> </td> <td> <p> New recruitment-themed domains impersonating defense companies; Azure C2 expansion </p> </td> </tr> <tr> <td> <p> MuddyWater resurfaces with new tooling after 5-month retooling period </p> </td> <td> <p> <strong> 40% </strong> </p> </td> <td> <p> 14&ndash;30 days </p> </td> <td> <p> New C2 infrastructure registration; phishing campaigns targeting government/telco </p> </td> </tr> <tr> <td> <p> HYDRO KITTEN claims successful PLC manipulation (beyond access) </p> </td> <td> <p> <strong> 25% </strong> </p> </td> <td> <p> 30&ndash;60 days </p> </td> <td> <p> Telegram claims; unexplained ICS anomalies in water/fuel sectors </p> </td> </tr> <tr> <td> <p> Coordinated multi-actor campaign launch (MuddyWater + Handala + HYDRO KITTEN) </p> </td> <td> <p> <strong> 20% </strong> </p> </td> <td> <p> If talks collapse </p> </td> <td> <p> Simultaneous activity across multiple sectors; shared infrastructure activation </p> </td> </tr> </tbody> </table> <h2> <strong> SOC Operational Guidance </strong> </h2> <h3> <strong> Detection Priorities </strong> </h3> <ol> <li> <strong> POLLREGISTER Infection Chain (UNC1549) </strong> </li> </ol> <table> <thead> <tr> <th> <p> ATT&amp;CK Technique </p> </th> <th> <p> Detection Logic </p> </th> <th> <p> Priority </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> T1204.002 </strong> (User Execution: Malicious File) </p> </td> <td> <p> Alert on .lnk files executing msiexec.exe with /i flag pointing to remote or unusual .mst files </p> </td> <td> <p> <strong> CRITICAL </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1574.002 </strong> (DLL Side-Loading) </p> </td> <td> <p> Monitor for VERSION.dll loaded by non-standard executables, particularly VSWebLauncher.exe </p> </td> <td> <p> <strong> CRITICAL </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1053.005 </strong> (Scheduled Task) </p> </td> <td> <p> Detect creation of scheduled task named "VSWebLauncher UpdateService" </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1071.001 </strong> (Web Protocols) </p> </td> <td> <p> Monitor for POST /rg with JSON body containing clientId field, followed by WebSocket upgrade to /ws?token= </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> </tbody> </table> <p> <strong> Hunting Hypothesis: </strong> "An adversary is using legitimate software installers (Chrome) as a delivery mechanism for DLL sideloading, with C2 communications hidden in Azure Web App traffic." </p> <p> <strong> Hunt Query Guidance: </strong> </p> <ul> <li> Search for msiexec.exe spawned by .lnk files in user Downloads/Temp directories </li> <li> Look for VSWebLauncher.exe in non-standard paths with network connections to *.azurewebsites.net </li> <li> Identify scheduled tasks created within 5 minutes of Chrome installation events </li> </ul> <ol start="2"> <li> <strong> HYDRO KITTEN ICS Access (CVE-2021-22681) </strong> </li> </ol> <table> <thead> <tr> <th> <p> ATT&amp;CK Technique </p> </th> <th> <p> Detection Logic </p> </th> <th> <p> Priority </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> T1190 </strong> / <strong> T0890 </strong> (Exploit Public-Facing App / ICS Exploitation) </p> </td> <td> <p> Monitor for unauthenticated connections to RSLogix 5000 project files; unexpected PLC program downloads </p> </td> <td> <p> <strong> CRITICAL </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1078 </strong> (Valid Accounts) </p> </td> <td> <p> Alert on PLC authentication events from non-engineering workstations </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> <tr> <td> <p> <strong> T0816 </strong> (Device Restart/Shutdown) </p> </td> <td> <p> Correlate unexpected PLC restarts with preceding network connections from non-OT subnets </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> </tbody> </table> <p> <strong> Hunting Hypothesis: </strong> "An adversary has bypassed authentication on Rockwell Allen Bradley PLCs and is maintaining persistent access for future destructive operations." </p> <ol start="3"> <li> <strong> Void Manticore / Handala Destructive Operations </strong> </li> </ol> <table> <thead> <tr> <th> <p> ATT&amp;CK Technique </p> </th> <th> <p> Detection Logic </p> </th> <th> <p> Priority </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> T1485 </strong> (Data Destruction) </p> </td> <td> <p> Monitor for mass file deletion or overwrite patterns (&gt;100 files in &lt;60 seconds) </p> </td> <td> <p> <strong> CRITICAL </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1531 </strong> (Account Access Removal) </p> </td> <td> <p> Alert on bulk Active Directory account disablement or password resets </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1491.002 </strong> (External Defacement) </p> </td> <td> <p> Monitor for unauthorized changes to login screens, wallpapers, or web-facing assets </p> </td> <td> <p> <strong> MEDIUM </strong> </p> </td> </tr> </tbody> </table> <ol start="4"> <li> <strong> Dormant Access Reactivation </strong> </li> </ol> <table> <thead> <tr> <th> <p> ATT&amp;CK Technique </p> </th> <th> <p> Detection Logic </p> </th> <th> <p> Priority </p> </th> </tr> </thead> <tbody> <tr> <td> <p> <strong> T1078 </strong> (Valid Accounts) </p> </td> <td> <p> Alert on VPN authentications from accounts dormant &gt;90 days, especially with Iranian working-hours patterns (UTC+3:30) </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1048 </strong> (Exfiltration Over Alternative Protocol) </p> </td> <td> <p> Monitor for Rclone or Wasabi S3 connections from corporate endpoints </p> </td> <td> <p> <strong> HIGH </strong> </p> </td> </tr> <tr> <td> <p> <strong> T1071.004 </strong> (DNS) </p> </td> <td> <p> Detect DNS queries to dynamic DNS providers (No-IP, serveftp.com, myftp.org) from internal hosts </p> </td> <td> <p> <strong> MEDIUM </strong> </p> </td> </tr> </tbody> </table> <h3> <strong> IOC Blocking Table </strong> </h3> <p> Deploy the following indicators at DNS, proxy, and endpoint layers: </p> <table> <thead> <tr> <th> <p> Type </p> </th> <th> <p> Value </p> </th> <th> <p> Context </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Domain </p> </td> <td> <p> careerst-mobile[.]com </p> </td> <td> <p> UNC1549 POLLREGISTER phishing </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> t-ebix-portal[.]com </p> </td> <td> <p> UNC1549 POLLREGISTER phishing </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> cld-global[.]com </p> </td> <td> <p> UNC1549 POLLREGISTER C2 </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> cld-global.azurewebsites[.]net </p> </td> <td> <p> UNC1549 POLLREGISTER C2 </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> cldglobal.azurewebsites[.]net </p> </td> <td> <p> UNC1549 POLLREGISTER C2 </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> mantechcareers.serveftp[.]com </p> </td> <td> <p> APT33 DIB targeting (historical, still active) </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> mtcareers.myftp[.]org </p> </td> <td> <p> APT33 DIB targeting (historical, still active) </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> customermgmt[.]net </p> </td> <td> <p> APT33 C2 infrastructure </p> </td> </tr> <tr> <td> <p> Domain </p> </td> <td> <p> iranianelectric[.]ir </p> </td> <td> <p> Compromised domain, Iranian APT staging </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 05d4bd9be981fb1ac3a7ff9548b2571a447c252e4bc99382e2d940fa137c076c </p> </td> <td> <p> ChromeSetup64.zip (POLLREGISTER dropper) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 8b3b49554fdb36a8ba54848863f1ce8f81990e7608d38ab34cfcaf5bcc6c79a3 </p> </td> <td> <p> ChromeSetup64.lnk (POLLREGISTER) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 122415ac44dbbd2b8cfe335cbd5365c1a24437e30a750d6ec16eb92b17e27125 </p> </td> <td> <p> ChromeUpdate.mst (POLLREGISTER installer) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> c04f8514f5c2176b1a86e25a243108483b86d60c05793c3c8779dd2fca51e226 </p> </td> <td> <p> VERSION.dll (POLLREGISTER backdoor) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 419d4359c97b30164ee2225d33b3f8fca3248a8eea5f83cb4d53562bbdc80c89 </p> </td> <td> <p> VSWebLauncher.exe (sideloading host) </p> </td> </tr> <tr> <td> <p> SHA-256 </p> </td> <td> <p> 27d02c32a8c23350622ea7231e31066e6dc8ae15a0d18eb9098261b6834c3890 </p> </td> <td> <p> Binary.sIEvXeEm (POLLREGISTER component) </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> 9a1b964ff95a216cb3f66482b33a8af8 </p> </td> <td> <p> ChromeSetup64.zip </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> 010a0667d341e26fc0e057f26b1b0094 </p> </td> <td> <p> ChromeSetup64.lnk </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> b4e817bd7119f93f7593fd63c3dee26d </p> </td> <td> <p> ChromeUpdate.mst </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> a1787fc51fea1b01ed72a7e19cc36bfc </p> </td> <td> <p> VERSION.dll (POLLREGISTER) </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> dc1469e9326cd41185b80c078fae2583 </p> </td> <td> <p> VSWebLauncher.exe </p> </td> </tr> <tr> <td> <p> MD5 </p> </td> <td> <p> 36d83f11e6d66ecc44bedc1c51fadef5 </p> </td> <td> <p> Binary.sIEvXeEm </p> </td> </tr> <tr> <td> <p> IP </p> </td> <td> <p> 213.252.246[.]80 </p> </td> <td> <p> Associated Iranian APT infrastructure </p> </td> </tr> <tr> <td> <p> IP </p> </td> <td> <p> 37.220.6[.]115 </p> </td> <td> <p> Associated Iranian APT infrastructure </p> </td> </tr> </tbody> </table> <p> <em> Additional IOCs available via Anomali ThreatStream. </em> </p> <h2> <strong> Sector-Specific Defensive Priorities </strong> </h2> <h3> <strong> Financial Services </strong> </h3> <p> <strong> Primary threat: </strong> Destructive wiper attacks disguised as ransomware (Crucio variant); account manipulation for sanctions evasion intelligence. </p> <ul> <li> Audit SWIFT and core banking system access controls for dormant privileged accounts </li> <li> Review DDoS mitigation capacity &mdash; Iranian hacktivist groups historically target financial sector websites during escalation phases </li> <li> Ensure offline backup integrity for critical transaction databases &mdash; Void Manticore's wiper operations target backup systems first </li> </ul> <h3> <strong> Energy </strong> </h3> <p> <strong> Primary threat: </strong> ICS/SCADA compromise via CVE-2021-22681 (Rockwell) and edge device exploitation (PAN-OS on RUGGEDCOM). </p> <ul> <li> <strong> Immediate: </strong> Inventory all Rockwell RSLogix 5000 installations (versions 20&ndash;38) and verify CVE-2021-22681 patch status </li> <li> Segment Allen Bradley PLCs from corporate networks &mdash; no engineering workstation should bridge IT/OT without jump server controls </li> <li> Audit Siemens RUGGEDCOM APE1808 devices for PAN-OS Captive Portal exposure; disable if not operationally required </li> <li> Patch ABB B&amp;R Automation Studio/Runtime and Hitachi Energy GMS600 (CVE-2022-4304) per CISA ICSA-26-141 series </li> <li> Deploy OT-specific network monitoring for anomalous PLC program transfers and firmware modifications </li> <li> Review EV charging infrastructure (ABB Terra AC Wallbox) connectivity &mdash; emerging attack surface </li> </ul> <h3> <strong> Healthcare </strong> </h3> <p> <strong> Primary threat: </strong> Collateral damage from wiper operations; supply chain compromise through medical device ICS components. </p> <ul> <li> Verify segmentation between medical device networks and general IT infrastructure </li> <li> Audit any ABB or Hitachi Energy components in building management systems (HVAC, power distribution) </li> <li> Ensure clinical systems have tested offline operational procedures &mdash; Iranian destructive operations target availability </li> <li> Monitor for recruitment-themed phishing targeting healthcare IT staff (UNC1549 pattern may expand beyond telecom) </li> </ul> <h3> <strong> Government </strong> </h3> <p> <strong> Primary threat: </strong> Espionage pre-positioning for post-conflict intelligence collection; BDA (battle damage assessment) surveillance. </p> <ul> <li> Hunt for existing Iranian APT access: search for Pioneer Kitten/Fox Kitten VPN credential patterns in authentication logs </li> <li> Audit Azure/M365 environments for unauthorized app registrations and OAuth grants &mdash; UNC1549 uses Azure infrastructure extensively </li> <li> Brief cleared personnel on recruitment-themed social engineering (fake career sites, LinkedIn approaches) </li> <li> Monitor for Handala-style defacement attempts against public-facing government websites during negotiation milestones </li> <li> Review DNS logs for queries to dynamic DNS providers (No-IP, serveftp.com, myftp.org) </li> </ul> <h3> <strong> Aviation &amp; Logistics </strong> </h3> <p> <strong> Primary threat: </strong> UNC1549 espionage targeting aerospace design data and supply chain intelligence; HYDRO KITTEN targeting fuel/logistics infrastructure. </p> <ul> <li> Deploy POLLREGISTER IOCs across all endpoint and network detection platforms immediately </li> <li> Brief recruiting/HR teams on fake career site phishing &mdash; UNC1549 specifically targets job seekers in aerospace and defense </li> <li> Audit PLM systems (Windchill, Teamcenter) for unauthorized access or bulk data downloads </li> <li> Review fuel management and logistics automation systems for Rockwell PLC exposure </li> <li> Monitor for anomalous outbound connections to *.azurewebsites.net from engineering workstations </li> </ul> <h2> <strong> Prioritized Defense Recommendations </strong> </h2> <h3> <strong> IMMEDIATE (Within 24 Hours) </strong> </h3> <table> <thead> <tr> <th> <p> Action </p> </th> <th> <p> Owner </p> </th> <th> <p> Rationale </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Block POLLREGISTER C2 domains (cld-global[.]com, cld-global.azurewebsites[.]net, cldglobal.azurewebsites[.]net) at DNS/proxy </p> </td> <td> <p> SOC </p> </td> <td> <p> Active UNC1549 campaign with confirmed IOCs </p> </td> </tr> <tr> <td> <p> Deploy detection for msiexec.exe fetching remote .mst files from non-corporate sources </p> </td> <td> <p> SOC </p> </td> <td> <p> POLLREGISTER delivery mechanism ( <strong> T1204.002 </strong> ) </p> </td> </tr> <tr> <td> <p> Create Sigma/YARA rules for VERSION.dll sideloading via VSWebLauncher.exe and "VSWebLauncher UpdateService" scheduled task </p> </td> <td> <p> SOC </p> </td> <td> <p> POLLREGISTER persistence detection ( <strong> T1574.002 </strong> , <strong> T1053.005 </strong> ) </p> </td> </tr> <tr> <td> <p> Audit all Rockwell RSLogix 5000 installations (v20&ndash;38) for CVE-2021-22681 patch status </p> </td> <td> <p> IT Ops / OT Eng </p> </td> <td> <p> Confirmed HYDRO KITTEN exploitation of this vulnerability </p> </td> </tr> <tr> <td> <p> Segment Allen Bradley PLCs from corporate networks; restrict engineering access to jump servers </p> </td> <td> <p> IT Ops / OT Eng </p> </td> <td> <p> Prevent lateral movement from IT to OT </p> </td> </tr> <tr> <td> <p> Block APT33 historical domains (mantechcareers.serveftp[.]com, mtcareers.myftp[.]org, customermgmt[.]net) </p> </td> <td> <p> SOC </p> </td> <td> <p> Still active in threat intelligence feeds; DIB targeting </p> </td> </tr> </tbody> </table> <h3> <strong> 7-DAY </strong> </h3> <table> <thead> <tr> <th> <p> Action </p> </th> <th> <p> Owner </p> </th> <th> <p> Rationale </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Patch Siemens RUGGEDCOM APE1808 PAN-OS Captive Portal (CISA ICSA-26-139-02); disable User-ID Authentication Portal if not required </p> </td> <td> <p> IT Ops </p> </td> <td> <p> Unauthenticated RCE on OT perimeter devices </p> </td> </tr> <tr> <td> <p> Patch ABB B&amp;R Automation Studio/Runtime and Hitachi Energy GMS600 (CVE-2022-4304) </p> </td> <td> <p> IT Ops / OT Eng </p> </td> <td> <p> Five CISA ICS advisories in single day; internet-facing instances priority </p> </td> </tr> <tr> <td> <p> Conduct proactive threat hunt for dormant Iranian APT access: Pioneer Kitten VPN credentials, Rclone/Wasabi exfiltration, APT33 domain activity in DIB networks </p> </td> <td> <p> SOC / Hunt Team </p> </td> <td> <p> 30+ days of silence on DIB targeting during active conflict is anomalous </p> </td> </tr> <tr> <td> <p> Brief all hiring/recruiting teams on UNC1549 recruitment-themed phishing TTPs </p> </td> <td> <p> HR / Security Awareness </p> </td> <td> <p> Verify all interview scheduling links; reject non-corporate Chrome installation requests </p> </td> </tr> <tr> <td> <p> Review Azure/M365 app registrations and OAuth consent grants for unauthorized entries </p> </td> <td> <p> Identity / Cloud Security </p> </td> <td> <p> UNC1549 leverages Azure infrastructure; potential for OAuth abuse </p> </td> </tr> </tbody> </table> <h3> <strong> 30-DAY </strong> </h3> <table> <thead> <tr> <th> <p> Action </p> </th> <th> <p> Owner </p> </th> <th> <p> Rationale </p> </th> </tr> </thead> <tbody> <tr> <td> <p> Commission dedicated threat hunt for MuddyWater retooling indicators </p> </td> <td> <p> CISO / Hunt Team </p> </td> <td> <p> 5-month operational silence during active conflict = probable capability development </p> </td> </tr> <tr> <td> <p> Request cleared threat briefing from DC3/DCSA on current Iranian DIB targeting </p> </td> <td> <p> CISO / GRC </p> </td> <td> <p> Fill PIR-007 intelligence gap; validate or refute absence hypothesis </p> </td> </tr> <tr> <td> <p> Conduct tabletop exercise: "Iranian ICS destructive attack during peace negotiation collapse" </p> </td> <td> <p> CISO / IR Team </p> </td> <td> <p> Test response procedures for scenario with 25% probability in 30&ndash;60 day window </p> </td> </tr> <tr> <td> <p> Evaluate OT network monitoring tooling for PLC program change detection </p> </td> <td> <p> OT Security / Engineering </p> </td> <td> <p> Current detection gap for post-exploitation PLC manipulation </p> </td> </tr> <tr> <td> <p> Establish automated correlation between geopolitical signals and Iranian actor infrastructure changes </p> </td> <td> <p> CTI Team </p> </td> <td> <p> Reduce detection latency for pre-positioning activities during diplomatic transitions </p> </td> </tr> </tbody> </table> <h2> <strong> The Bottom Line </strong> </h2> <p> The peace talks don't change your risk calculus &mdash; they increase it. Iranian cyber doctrine treats negotiation phases as opportunities to consolidate access, not as reasons to stand down. The confirmed exploitation of Rockwell PLCs, the industrialized pace of UNC1549's espionage tooling, and the unmasking of MOIS destructive operations under the Handala persona all point to an adversary operating at maximum capacity with nothing to lose. </p> <p> Three things should keep you up tonight: </p> <ul> <li> <strong> <strong> The ICS attack surface just doubled. </strong> HYDRO KITTEN's jump from Unitronics to Rockwell Automation means every Allen Bradley PLC in your environment is now a confirmed target &mdash; not a theoretical one. </strong> </li> </ul> <ul> <li> <strong> The silence is the signal. </strong> MuddyWater's five-month quiet period and the 30-day gap in defense industrial base targeting intelligence don't mean the threat receded. They mean you can't see what's happening. Act accordingly. </li> </ul> <ul> <li> <strong> The clock is ticking on pre-positioned access. </strong> If peace talks collapse, the retaliatory cyber operations won't start from scratch &mdash; they'll activate access that was established weeks or months ago. Your window to find and evict that access is now. </li> </ul> <p> Patch the PLCs. Block the C2s. Hunt for the dormant access. Brief your board that peace talks are a cyber escalation trigger, not a de-escalation signal. </p> <p> <em> Published 2026-05-25 by the Anomali CTI Desk. Intelligence derived from Anomali ThreatStream, CISA advisories, CrowdStrike, Google Threat Intelligence, Check Point Research, and open-source reporting. For IOC feeds and detection content, contact your Anomali representative. </em> </p>

FEATURED RESOURCES

May 26, 2026
Anomali Cyber Watch

Iranian Cyber Operations Enter Most Dangerous Phase: Physical Destruction Without Malware Under Ceasefire Cover

Read More
May 25, 2026
Anomali Cyber Watch

Iran's Cyber War Machine Isn't Stopping for Peace Talks — What CISOs Need to Know Now

Read More
May 26, 2026
Anomali Cyber Watch
Public Sector

Active Exploitation of State Government Systems: Drupal Under Attack, M365 Credentials at Risk, and VPN Infrastructure Compromised

Read More
Explore All