TLP:GREEN  ·  Iran / Israel Conflict
Day 194 of the Iran Conflict — The Quiet Cycle Is the Dangerous One:

The Invisible Rootkit, the 974-CVE Avalanche, and Iran's Quiet Before the Storm

ELEVATED. Unchanged from the prior cycle, but for uncomfortable reasons. A rootkit that lives entirely in memory (PoisonedRefresh) now defeats file-based detection on F5 BIG-IP APM appliances; Microsoft shipped 974 CVEs in a single month with two zero-days already exploited; Iranian-linked Mirai infrastructure is being refreshed with new samples and C2 domains; and Pioneer Kitten has gone silent for 31 days on defense industrial base pre-positioning. Silence, in an active conflict, is the most dangerous signal on the board.

I am a
My sector

DateDevelopmentSignificance
Sep 9<strong>PoisonedRefresh rootkit disclosed</strong> by Sophos and ESET — exploits CVE-2025-53521 (CVSS 9.8, CISA KEV) on F5 BIG-IP APM and hides a PHP web shell entirely in memory via Apache module loader hookingDetection paradigm shift for any organization running F5 infrastructure — the implant never touches disk
Sep 8<strong>Microsoft ships 974 CVEs</strong> — 113 Critical, two actively exploited zero-days (CVE-2026-81963, CVE-2026-85880) and two unauthenticated CVSS 9.8 network RCEs (CVE-2026-69730 Windows DNS, CVE-2026-69829 Windows Shell)Largest Patch Tuesday in history; attack surface expanding faster than most patch pipelines can absorb
Sep 8<strong>CISA adds four new KEV entries</strong> including CVE-2026-75650, a CVSS 10.0 template engine injection in Adobe CommerceNo authentication and no user interaction required — as severe as web application flaws get
Sep 7–9<strong>Iranian-tagged Mirai botnet variants refreshed</strong> — two new samples, a new C2 domain family (<code>nivatrix[.]boats</code>) and a Sberbank-themed phishing domain registered in IranBotnet refresh during hacktivist silence suggests preparation, not retirement; possible deepening Russian-Iranian criminal cooperation
Sep 3–9<strong>Seven ICS advisories published</strong> covering Rockwell, Schneider Electric, IXON and othersDirectly relevant to energy and industrial control environments already in the Iranian targeting aperture
Sep 8<strong>Pioneer Kitten goes quiet for 31 days</strong> — profile updated with no new campaign dataLongest intelligence gap on DIB pre-positioning since the conflict began; during an active war, the absence is itself the finding

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Day 0 of the Iran conflict; cyber operations commence alongside kinetic escalation
Sustained proxy operationsJul – Sep 2026Cyber Av3ngers compromise 100+ U.S. municipal water systems via IOCONTROL malware
Cyber-physical threshold crossedAug 22–26, 2026IRGC-affiliated actors shut down a UK power generation facility — first confirmed Iranian cyber-physical attack on Five Eyes energy infrastructure
Retaliatory window opensAug 29, 2026U.S. State Department announces $10M bounty on IRGC-CEC cyber chief Amir Yaryab; 11-day retaliatory window opens
ICS exposure surgeSep 3–9, 2026CISA publishes seven ICS advisories: Rockwell ControlFLASH and ArmorStart, Schneider Easergy, IXON VPN, Pyramid NetStaX, Tycon TPDIN, CareCam Pro (ICSA-26-251-01)
Infrastructure and implant refreshSep 5–9, 2026APT42 (IRGC-IO) refreshes TAMECAT/NICECURL against the nuclear sector; UNC7033 ClickFix campaign updated; Iran-tagged Mirai variants surface on nivatrix[.]boats and cozyvistany[.]com
Current (Day 194)Sep 9, 2026PoisonedRefresh disclosed on F5 BIG-IP APM; 974-CVE Patch Tuesday with two exploited zero-days; four new CISA KEVs; Pioneer Kitten at 31 days silent on DIB pre-positioning

Disclosed on September 9 by Sophos and named by ESET, PoisonedRefresh is a meaningful evolution in adversary tradecraft. Deployed against F5 BIG-IP APM appliances via CVE-2025-53521 (CVSS 9.8, unauthenticated RCE), the implant hides a fully functional PHP web shell in memory by hooking Apache's APR module loader and intercepting PHP file operations at the kernel level. The web shell never exists on disk in its final form.

A secondary backdoor uses a Unix domain socket at /run/bigtlog.pipe for interactive shell access — a technique that evades network monitoring focused on TCP port activity.

Why this matters for the Iran conflict: Iranian state actors including MuddyWater (MOIS), APT34/OilRig and Pioneer Kitten have historically favored web shells (SEASHARPEE, HighShell, BELLACIAO) as persistence on compromised edge appliances. PoisonedRefresh's in-memory evasion aligns precisely with actors seeking persistent, stealthy access to allied military and government networks. No attribution to Iranian actors has been made, but the technique is tailor-made for adoption by groups already targeting F5 infrastructure.

T1014T1505.003T1059.004T1190

Microsoft's September Patch Tuesday was not just large — it was structurally significant. At 974 CVEs (113 Critical) it continues a 2026 trend that has already produced over 2,600 patches year-to-date, more than double the pace of previous record years. AI-assisted vulnerability discovery is cited as the driver.

CVECVSSTypeStatus
CVE-2026-819637.8Windows Update Stack EoPActively exploited, CISA KEV
CVE-2026-858807.8Windows ALPC heap buffer overflow EoPActively exploited, CISA KEV
CVE-2026-697309.8Windows DNS use-after-free RCEExploitation "likely" per Microsoft
CVE-2026-698299.8Windows Shell heap buffer overflow RCENo auth, no user interaction
CVE-2026-7565010.0Adobe Commerce template engine RCEActively exploited, CISA KEV

The EoP zero-days tell a specific story: attackers already have initial access and are escalating privileges. The two CVSS 9.8 network RCEs — particularly CVE-2026-69730 against Windows DNS — are unauthenticated and require no user interaction. The strategic concern extends beyond any single CVE: if an organization cannot test and deploy at a pace matching 974 CVEs per month, that is a structural vulnerability no single tool can fix.

T1190T1203T1068

Fresh Mirai variants tagged to Iranian infrastructure surfaced between September 7–9, with two new samples distributed from scooter.cozyvistany[.]com (targeting i486 and ARM architectures) and a new C2 domain family, nivatrix[.]boats, with seven confirmed subdomains. Kaspersky rates the C2 infrastructure at confidence 100.

A related finding — a Sberbank-themed phishing domain registered in Iran — adds a data point to the deepening Russian-Iranian criminal nexus. Targeting Russian banking customers from Iranian infrastructure suggests either shared criminal operations, Iranian actors harvesting Russian credentials for operational funding, or a deliberate blurring of state and criminal activity that complicates attribution.

This matters because the Mirai refresh directly supports DDoS capability — the primary weapon of pro-Iran hacktivist proxies including Cyber Av3ngers, Handala and DieNet. Infrastructure refresh during a period of hacktivist silence suggests preparation, not retirement.

T1583.004T1105T1498

Pioneer Kitten (also tracked as Fox Kitten, UNC757) exploits VPN and edge appliances — particularly Fortinet and Citrix — to gain initial access to defense industrial base contractor networks. Its ThreatStream profile was updated on September 8 with no new campaign data, IOCs or targeting detail.

That marks 31 consecutive days without new intelligence on Iranian pre-positioning in DIB networks, the longest gap since the conflict began. With Iranian operations running at sustained tempo across energy, water, telecoms and nuclear espionage, the absence of visible DIB activity is the highest-consequence blind spot on the board.

Assessment: the likely explanation is not that Pioneer Kitten has stopped operating. It is that dormant access is already established and awaiting an activation trigger — a conflict escalation event, a political inflection point, or a retaliatory directive.

T1133T1078T1505.003T1567.002

Seven ICS advisories published between September 3–9 affect vendors deployed directly in energy, water and industrial environments.

AdvisoryVendor / ProductImpact
ICSA-26-246-03Rockwell ControlFLASHRemote code execution
ICSA-26-246-04Rockwell ArmorStart LTWeb server DoS + injection
ICSA-26-246-02IXON VPN ClientRCE on client machine
ICSA-26-169-07 (Update A)Schneider Easergy / EcoStruxure / PowerLogic / SaitelMultiple vulnerabilities
ICSA-26-246-07Pyramid Solutions NetStaX EtherNet/IPMemory corruption
ICSA-26-246-08Tycon Systems TPDIN-Monitor-WEB3MitM + factory reset
ICSA-26-251-01CareCam Pro IP CameraFull device takeover

Rockwell ControlFLASH (RCE) and Schneider Easergy (substation controllers) are the highest-priority items. Easergy devices sit in electrical substations — the same class of infrastructure targeted in the August 22–26 UK power facility attack attributed to IRGC-affiliated actors.

ScenarioProbabilityTimeframeBasis
Additional exploitation of Microsoft September CVEs (particularly CVE-2026-69730 DNS RCE)75%72 hours974-CVE batch provides massive attack surface; PoC development accelerates within days of disclosure; two CVEs already exploited ITW
Iranian hacktivist groups (Handala, Cyber Toufan, DieNet) begin pre-election IO operations targeting Israeli political infrastructure50%7–14 daysIsraeli Knesset elections announced for October 2026; historical pattern shows Iranian IO campaigns begin 2–3 weeks before target political events; current 194-day hacktivist silence is anomalous
PoisonedRefresh in-memory technique adopted by Iranian APTs for F5 appliances in allied networks45%30 daysTechnique's evasion characteristics align with Iranian operational preferences; Iranian actors already target F5 infrastructure; CVE-2025-53521 is in CISA KEV
Pioneer Kitten dormant access activation in DIB networks triggered by conflict escalation30%Event-driven31-day quiet period consistent with pre-positioned access; historical Pioneer Kitten pattern involves long dwell times before activation; conflict escalation or retaliatory directive would serve as trigger
Coordinated hacktivist DDoS campaign using refreshed Mirai infrastructure timed to political event40%14–30 daysFresh botnet infrastructure (nivatrix[.]boats C2, new Mirai variants) being staged; Knesset elections provide timing anchor; Cyber Av3ngers demonstrated capability against 100+ water systems

PriorityRuleATT&CKRationale
IMMEDIATEAlert on .php3 requests to F5 BIG-IP APM returning HTTP 201T1505.003PoisonedRefresh web shell indicator
IMMEDIATEAlert on /run/bigtlog.pipe socket creation on Linux appliancesT1059.004PoisonedRefresh backdoor
IMMEDIATEBlock nivatrix[.]boats and cozyvistany[.]com at DNST1583.004 T1105Active Iranian botnet C2 and distribution
HIGHMonitor Windows DNS server processes for child process spawningT1190 T1203CVE-2026-69730 pre-exploitation detection
HIGHAlert on Rclone/Wasabi S3 patterns in egress trafficT1567.002Pioneer Kitten exfiltration TTP
HIGHDetect anomalous VPN authentication from contractor subnets outside business hoursT1078 T1133Pioneer Kitten initial access pattern
IOC Blocking Table:
cozyvistany[.]comnivatrix[.]boatsblubel.nivatrix[.]boatsdromongongor.nivatrix[.]boatsglafar71.nivatrix[.]boatsglariz.nivatrix[.]boatsgramonlannal646.nivatrix[.]boatsgrukinminfar265.nivatrix[.]boatsprunintil.nivatrix[.]boats6sbermarket.sberbank.pay.nod32update01g.irani24[.]com

Block the above across firewalls, DNS sinkholes, proxy filters and endpoint detection platforms. nivatrix[.]boats is the botnet C2 domain family (Kaspersky confidence 100); cozyvistany[.]com is the Mirai distribution server, with download URLs http://scooter.cozyvistany[.]com/iran.i486 and http://scooter.cozyvistany[.]com/iran.armv7l; the Sberbank-themed domain carries an Iranian registrant. SHA-256 hashes for the Mirai variants and associated botnet samples are available for verified download and blocking via Anomali ThreatStream — retrieve current hash IOCs before deploying production blocking rules. Additional IOCs, including APT42 TAMECAT/NICECURL infrastructure, MuddyWater (MOIS) tooling and Cyber Av3ngers IOCONTROL indicators, are available through Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1014
Is PoisonedRefresh already resident on an F5 BIG-IP APM appliance?
Adversaries have exploited CVE-2025-53521 to deploy in-memory web shells. File integrity monitoring will not detect this. Monitor Apache worker processes for reads to /proc/self/maps followed by memory permission changes (APR hook installation), alert on requests to apm_css.php3, full_wt.php3 or webtop_popup_css.php3 returning HTTP 201 with CSS content-type headers, check every F5 appliance for the /run/bigtlog.pipe Unix domain socket, and review Apache module load order for unexpected shared objects. T1014 T1505.003 T1059.004 T1190
HUNT 02 · T1133
Does Pioneer Kitten already hold dormant access via a VPN concentrator?
Pioneer Kitten (UNC757) may have pre-positioned access through compromised VPN concentrators or edge appliances and be maintaining dormant persistence. Audit Fortinet and Citrix VPN logs for anomalous authentication — particularly service accounts or contractor credentials authenticating outside business hours; search for web shells on edge appliances even if recently patched, as shells may persist post-patch; hunt Rclone or Wasabi S3 exfiltration patterns in egress; and review RDP and SSH sessions originating from contractor subnets. T1078 T1505.003 T1021.001 T1021.002 T1567.002
HUNT 03 · T1190
Are Windows DNS servers exposed to imminent CVE-2026-69730 weaponization?
CVE-2026-69730 (CVSS 9.8, unauthenticated DNS RCE) will be weaponized rapidly against internet-facing or internally exposed Windows DNS servers. Identify all Windows DNS servers (Server 2012+) and verify patch status, monitor DNS server processes for anomalous child process spawning, baseline query volume and alert on sudden spikes, and segment DNS servers from sensitive network zones where possible. T1203 T1068

Financial Services
Banking, Payments, E-Commerce Platforms
Primary threats
Adobe Commerce / Magento CVE-2026-75650 (CVSS 10.0, CISA KEV) — unauthenticated template engine injection RCE with no user interaction
Secondary threat
Financial-sector phishing across the Russian-Iranian criminal nexus, evidenced by the Sberbank-themed domain registered in Iran
Actions
  • Inventory all Adobe Commerce instances immediately, prioritize internet-facing deployments and patch within 7 days
  • Review email gateway rules for phishing impersonating Russian and European banks
  • Tune fraud detection systems for credential harvesting patterns
Energy
Generation, Substations, Distribution
Primary threats
Schneider Easergy substation controllers, Schneider EcoStruxure/PowerLogic and Rockwell ControlFLASH (RCE) exposure across generation and distribution environments
Secondary threat
Demonstrated Iranian cyber-physical capability — the August 22–26 UK power facility shutdown and Cyber Av3ngers IOCONTROL deployment against 100+ water systems
Actions
  • Validate patching status for Schneider Easergy, EcoStruxure/PowerLogic and Rockwell ControlFLASH immediately
  • Segment OT networks from IT networks where this is not already enforced
  • Treat energy OT environments running Rockwell or Schneider systems as actively targeted, not theoretically exposed
Healthcare
Clinical Networks, Patient Monitoring
Primary threats
The 974-CVE Microsoft batch against constrained clinical patching windows, with CVE-2026-69730 (Windows DNS RCE, CVSS 9.8) especially dangerous on shared healthcare DNS infrastructure
Secondary threat
CareCam Pro IP camera advisory (ICSA-26-251-01) — full device takeover enabling surveillance or network pivot
Actions
  • Prioritize the two exploited zero-days and CVE-2026-69730 on legacy Windows estates (Server 2012+, Windows 10)
  • Audit all IP camera deployments used for patient monitoring or physical security
  • Segment cameras onto dedicated VLANs and disable unnecessary remote access features
Government
Agencies, Remote Access, Defense Contractors
Primary threat
PoisonedRefresh on F5 BIG-IP APM — the in-memory web shell defeats the file integrity monitoring many government programs rely on as a compliance control
Secondary threat
Pioneer Kitten's 31-day quiet streak against government contractors and defense industrial base networks
Actions
  • Verify F5 patching status against CVE-2025-53521 immediately
  • Run the memory-based hunts described in Detection Priorities rather than relying on FIM
  • Consider runtime application self-protection or memory forensics capability for F5 appliances
  • Treat dormant Pioneer Kitten access as a working assumption for contractor-connected networks
Aviation / Logistics
Maintenance Remote Access, Logistics Networks
Primary threats
IXON VPN Client advisory (ICSA-26-246-02) — RCE on the client machine, used in industrial remote access common to aviation maintenance and logistics
Secondary threat
MikroTik router chain (CVE-2026-67276 / CVE-2026-86060) still unpatched across many logistics and transportation remote sites
Actions
  • Review all remote access VPN deployments and patch IXON clients
  • Audit MikroTik router firmware versions at remote and branch sites
  • Ensure remote maintenance connections to OT systems traverse monitored jump servers
No sector cards match the selected filters.

Deploy Microsoft September patches for CVE-2026-81963 and CVE-2026-85880 (actively exploited zero-day EoPs) on all Windows endpoints. Treat CVE-2026-69730 (Windows DNS RCE, CVSS 9.8) as immediate on all Windows DNS servers — unauthenticated, no user interaction.
SOC Analyst
Verify all F5 BIG-IP APM devices are patched against CVE-2025-53521. Hunt PoisonedRefresh indicators: Apache workers reading /proc/self/maps, requests to apm_css.php3 / full_wt.php3 / webtop_popup_css.php3 returning HTTP 201, existence of /run/bigtlog.pipe. Disable .php3 execution where not operationally required.
Incident Responder
Block all IOCs from the blocking table across firewalls, DNS sinkholes, proxy filters and EDR. Priority: cozyvistany[.]com and *.nivatrix[.]boats. Retrieve current file hash IOCs from Anomali ThreatStream before deploying hash-based rules.
SOC Analyst
Brief executive leadership on PoisonedRefresh's implications: file-based detection (FIM, traditional AV) is ineffective against this class of implant. Memory forensics and behavioral detection may require investment.
CISO / Exec
No immediate actions for the selected roles.
Patch all Adobe Commerce / Magento installations against CVE-2026-75650 (CVSS 10.0, CISA KEV). Audit every internet-facing Commerce instance — no authentication and no user interaction are required.
Incident Responder
Apply Fortinet patches per NCSC-2026-0355 covering FortiManager (security bypass), FortiClient (DoS), FortiAnalyzer (DoS) and FortiSIEM (information falsification). Pioneer Kitten and MuddyWater (MOIS) historically exploit Fortinet appliances for initial access.
Incident Responder
Hunt for Pioneer Kitten / Fox Kitten (UNC757) TTPs across all VPN concentrator and edge appliance logs, focused on Fortinet and Citrix. Search for dormant web shells, anomalous contractor credential usage and Rclone/Wasabi exfiltration. The 31-day intelligence gap demands active hunting — do not wait for indicators.
SOC AnalystThreat Hunter
Validate ICS patching status for Rockwell ControlFLASH (RCE), Rockwell ArmorStart LT, Schneider Easergy/EcoStruxure, IXON VPN Client, Pyramid NetStaX and Tycon TPDIN. Prioritize ControlFLASH and Easergy — both directly relevant to Iranian energy-sector targeting.
ICS / OT
Establish monitoring of Telegram channels associated with Handala, Cyber Toufan, DieNet and 313 Team ahead of the October Israeli Knesset elections. Iranian IO campaigns historically stage 2–3 weeks before target political events.
Threat Hunter
No 7-day actions for the selected roles.
Commission an assessment of patch capacity. Microsoft shipped 974 CVEs in September and 2,600+ year-to-date. If the testing and deployment pipeline cannot keep pace, evaluate automated patch validation tooling, risk-based prioritization and staffing adequacy.
CISO / Exec
Evaluate detection capability against in-memory implants. PoisonedRefresh, SLEEPWALKER and BINDCLOAK represent a growing class of threats that avoid disk artifacts entirely. Assess runtime memory analysis, behavioral analytics and RASP for edge appliances.
CISO / ExecSOC Analyst
Update IR playbooks for in-memory rootkit scenarios. Disk imaging and file hash comparison will not detect PoisonedRefresh-class implants. Ensure the IR team has memory acquisition and analysis capability for Linux appliances, particularly F5 BIG-IP.
Incident Responder
Stress-test the response plan for a coordinated Iranian hacktivist campaign (DDoS + defacement + data leak) timed to the October Knesset election window. Confirm DDoS mitigation contracts are active, public web properties have failover, and communications plans exist for data leak scenarios.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

The Iran conflict's cyber dimension is now six months old and showing no signs of abating. Today's intelligence contains no single dramatic escalation event — and that is precisely what makes it dangerous. The threats surfacing now are quieter, more sophisticated and harder to detect: a rootkit that lives in memory, a botnet refreshing its infrastructure, a known threat actor going dark for a month. The organizations that will be caught off guard are the ones that mistake the absence of loud alerts for the absence of threat activity. PoisonedRefresh demonstrates that adversaries are investing in evasion designed to defeat the tools most organizations rely on; the 974-CVE month demonstrates that attack surface is expanding faster than most can shrink it; and the 31-day Pioneer Kitten silence is a reminder that the most dangerous access is the access you do not know about.

1
Patch the zero-days today — CVE-2026-81963, CVE-2026-85880, and CVE-2026-69730 on every Windows DNS server.
2
Hunt for Pioneer Kitten this week across Fortinet and Citrix edge appliances. Thirty-one days of silence is not an all-clear.
3
Ask the hard question: can your detection architecture find an adversary that never touches disk? Prepare for the hacktivist storm before October.
No items found.