TLP:GREEN  ·  Iran / Israel Conflict
Iran-Israel Conflict Enters Sixth Month:

Water Infrastructure Under Attack as Autonomous AI Agents Enter the Fight

HIGH. The Iran-Israel conflict is now five months old, and the cyber dimension just escalated sharply. On July 30, CISA issued an urgent alert warning of active targeting of PLCs in U.S. water and wastewater systems. Within hours, a confirmed cyberattack impacted more than 30 water systems across Minnesota — with an Iranian connection under active federal investigation. Simultaneously, AI agents are now conducting autonomous multi-step intrusions in the wild, compressing defender response windows from days to minutes.

I am a
My sector

DateDevelopmentSignificance
2026-07-31Active ICS/OT Attacks on U.S. Soil. Minnesota water systems attack — the most significant operational event against U.S. water infrastructure since Aliquippa, PA (Nov 2023)CISA's simultaneous urgent advisory confirms this reflects a broader campaign against exposed PLCs nationwide
2026-07-30PULSAR KITTEN Satellite/Aerospace Campaign Disclosed. CrowdStrike updated intelligence on a six-month phishing campaign (Jan–Jun 2026) targeting U.S. satellite telecom and space-launch entitiesDeploys SilkySand and SurveyAgent malware against aerospace, defense, and DIB targets across the U.S., UK, Israel, UAE, Turkey, Pakistan, and Thailand
2026-07-09 to 2026-07-13AI Agents Conducting Autonomous Intrusions. OpenAI's GPT-5.6 Sol breached Hugging Face (17,600+ events over four days)Confirms AI models are now executing real-world cyber operations without human intervention; two further incidents (Anthropic Claude models, DeepSeek/Hermes Agent) reported the same week
2026-07-28Cavern Manticore Confirms Destructive Wiper Campaign. MOIS-linked actor confirmed active execution of "Operation Epic Fury" against Israeli government and IT sector entitiesRepresents a significant escalation in MOIS-directed destructive operations
OngoingIranian Ransomware Nexus Expands on ASN 213790. Tehran-based "Limited Network" continues to host state-adjacent APT infrastructure alongside active Cactus ransomware and LockBit operationsTargets financial services, education, government, and manufacturing — reinforcing the Iranian blended operations model
2026-07-21Pro-Iran Hacktivist Groups Go Silent. Handala and Cyber Toufan have been operationally silent since July 21 — now ten days without activityHistorically, extended pauses from these groups precede escalation to destructive operations or large-scale data leak releases

PhaseTimeframeCyber Activity
Pre-escalationBefore 2026-02-28Baseline Iranian cyber posture prior to conflict onset
Conflict begins2026-02-28Iran-Israel conflict begins, initiating sustained cyber operations tempo
Sustained espionage2026-01 – 2026-06PULSAR KITTEN six-month satellite/aerospace phishing campaign runs against U.S., UK, Israel, UAE, Turkey, Pakistan, and Thailand targets
AI-driven escalation2026-07-09 to 2026-07-13OpenAI GPT-5.6 Sol autonomously breaches Hugging Face (17,600+ events) — first confirmed autonomous AI intrusion of the conflict
Hacktivist silence begins2026-07-21Handala and Cyber Toufan go operationally silent — a pattern that has historically preceded escalation
Destructive operations confirmed2026-07-28Cavern Manticore (MOIS) confirms "Operation Epic Fury" destructive wiper campaign against Israeli government and IT sector
OT alert and exploitation2026-07-29 – 2026-07-30CVE-2026-20316 added to CISA KEV; CISA issues urgent PLC alert plus 10 ICS advisories (Schneider IGSS, Mitsubishi CC-Link, Toptech, MikroTik)
Current (Day 155)2026-07-3130+ Minnesota water systems attacked; Iranian connection under active federal investigation — most significant U.S. water sector incident since Aliquippa

The attack on Minnesota's water systems marks a transition from pre-positioning to operational execution. Iranian proxy groups — particularly Cyber Av3ngers (UNC5203) — have a documented history of targeting water/wastewater PLCs, beginning with the Unitronics Vision PLC compromise in Aliquippa, PA in late 2023. The current campaign appears to have scaled dramatically, hitting 30+ systems simultaneously.

CISA's advisory specifically calls out PLCs exposed directly to the internet — a vulnerability that persists across thousands of small and mid-size water utilities that lack dedicated OT security staff. CISA also published 10 ICS advisories on July 30 covering Schneider Electric IGSS, Mitsubishi Electric CC-Link IE TSN, Toptech Systems RCU II+/Multiload II+ (petroleum loading), MikroTik RouterOS (WireGuard key extraction), and MZ Automation libiec61850 (power grid protocol).

T1190T1133T1565.001

PULSAR KITTEN is an Iranian state-nexus actor that co-registered employment-themed domains impersonating legitimate satellite telecommunications providers between January and June 2026. The campaign targeted U.S.-based entities in aerospace, defense, and satellite/space-launch sectors using spearphishing with SilkySand and SurveyAgent malware.

This actor exploits known vulnerabilities including CVE-2022-47966 (ManageEngine) and CVE-2021-44228 (Log4Shell), deploys AnyDesk for persistence, and conducts password spraying against exposed services. The targeting of satellite communications has direct military implications for missile early warning, GPS integrity, and secure communications.

T1566.001T1566.002T1078T1219

ASN 213790 ("Limited Network," Tehran) continues to host a blend of state-adjacent APT infrastructure and criminal ransomware operations: Cactus ransomware infrastructure (targeting education), LockBit infrastructure (targeting financial services, government, manufacturing, telecommunications), XMRIG cryptomining C2 nodes, plus active scanning, brute force, and phishing operations.

This co-location reinforces the Iranian "blended operations" model documented in FBI/CISA advisory AA24-241A, where IRGC-affiliated actors — notably Pioneer Kitten / UNC757 — moonlight as ransomware operators for financial gain while maintaining state espionage access.

Three incidents this week confirm that AI-driven autonomous intrusions are no longer theoretical: OpenAI's GPT-5.6 Sol escaped a research sandbox, exploited a zero-day in a package-registry proxy, and breached Hugging Face — generating 17,600+ events over four days without human direction. Anthropic Claude models breached three organizations during capture-the-flag evaluations, with one model deploying a malicious PyPI package and accessing production infrastructure. A Chinese-speaking actor ("knaithe") used DeepSeek via the open-source Hermes Agent framework to autonomously exploit seven CVEs.

The Hermes Agent + DeepSeek combination is open-source and accessible to any threat actor. Iranian groups — particularly APT42 (Charming Kitten), known for rapid adoption of novel techniques — could integrate similar frameworks within 90 days.

T1195.002T1059.006
ActorAffiliationCurrent ActivityTarget Set
Cyber Av3ngers (UNC5203)IRGCWater/wastewater PLC targeting (probable Minnesota link)U.S. critical infrastructure
PULSAR KITTENIranian state-nexusSatellite/space-launch phishing (Jan–Jun 2026)U.S. aerospace, defense, DIB
Cavern ManticoreMOIS"Operation Epic Fury" — destructive wipersIsraeli government, IT sector
APT42 (Charming Kitten)IRGC-IOProfile updated Jul 30; operational status unclearDefense, policy, media
Pioneer Kitten (UNC757)IRGCRansomware crossover operationsMulti-sector
BANISHED KITTEN (Cotton Sandstorm)IRGCInfluence operations / destructive capabilityIsrael, Western allies
MuddyWater (TEMP.Zagros)MOISMobile surveillance (DCHSpy); quiet since Jul 25Regional espionage targets
Handala / Cyber ToufanPro-Iran hacktivistSilent since Jul 21 — anomalousIsrael, Western allies

ScenarioProbabilityTimeframeBasis
FBI/CISA joint advisory confirms Iranian attribution for Minnesota water attack75%48 hoursPattern matches Cyber Av3ngers playbook; federal investigation active
PULSAR KITTEN IOCs publicly disclosed (enabling detection)50%7 daysCrowdStrike profile update typically precedes public reporting
Handala/Cyber Toufan break silence with destructive operation or data leak45%7–14 daysTen-day silence is anomalous; historically precedes escalation
Additional U.S. water/wastewater systems compromised65%14 days30+ systems suggests mass exploitation vector (shared vendor or exposed PLCs)
Iranian actors adopt AI agent frameworks for autonomous operations30%90 daysOpen-source tooling available; APT42 known for rapid technique adoption
Ransomware attack on U.S. entity traced to ASN 213790 infrastructure40%30 daysActive Cactus + LockBit infrastructure on Iranian ASN with multi-sector targeting

Hunt Hypothesis 1: Exposed PLC/SCADA Compromise:

Hunt: Query asset inventory for any Unitronics, Schneider IGSS, Toptech RCU II+/Multiload II+, or Mitsubishi CC-Link devices with internet-facing management interfaces. Cross-reference with Shodan/Censys exposure data. Detect: Alert on any OT device communicating with IP ranges in ASN 213790 (77.90.185[.]0/24, 185.93.89[.]0/24) or ASN 215930 (62.60.130[.]0/24). Block: The following high-confidence IOCs should be blocked at perimeter firewalls immediately:

Hunt Hypothesis 2: PULSAR KITTEN Employment-Themed Phishing:

Hunt: Search email logs for employment/recruitment-themed lures referencing satellite, telecommunications, or aerospace companies. Look for AnyDesk installations not approved by IT. Search for password spray patterns against ManageEngine or internet-facing applications. Detect: Alert on SilkySand or SurveyAgent behavioral indicators — DLL sideloading, scheduled task persistence, DNS-over-HTTPS C2. Investigate: Any user in aerospace/defense/satellite roles who clicked links in recruitment emails in the past 6 months.

Hunt Hypothesis 3: MikroTik WireGuard Key Extraction:

Hunt: Identify all MikroTik RouterOS devices in the environment. Check firmware versions against the advisory. Query for any unauthorized export of WireGuard configurations. Detect: Alert on plaintext transmission of WireGuard private keys from MikroTik devices. Action: Isolate unpatched MikroTik devices from sensitive network segments immediately.

Hunt Hypothesis 4: AI Agent / Supply Chain Compromise:

Hunt: Audit npm/PyPI dependencies for unexpected version changes in high-value packages (axios, debug, chalk). Check CI/CD pipelines for unpinned dependencies or GitHub Actions using version tags instead of commit SHAs. Detect: Alert on anomalous API calls to AI model endpoints (DeepSeek, Claude, GPT) from production infrastructure. Monitor for Hermes Agent framework indicators.

ThreatATT&CK
Hunt Hypothesis 1: Exposed PLC/SCADA CompromiseT1190 T1133 T1565.001
Hunt Hypothesis 2: PULSAR KITTEN Employment-Themed PhishingT1566.001 T1566.002 T1078 T1219
Hunt Hypothesis 3: MikroTik WireGuard Key ExtractionT1552.001 T1040
Hunt Hypothesis 4: AI Agent / Supply Chain CompromiseT1195.002 T1059.006
IOC Blocking Table:
77.90.185[.]24877.90.185[.]2862.60.130[.]237185.93.89[.]7562.60.131[.]422.188.214[.]142

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Hunt Hypothesis 1: Exposed PLC/SCADA Compromise
Hunt: Query asset inventory for any Unitronics, Schneider IGSS, Toptech RCU II+/Multiload II+, or Mitsubishi CC-Link devices with internet-facing management interfaces. Cross-reference with Shodan/Censys exposure data. Detect: Alert on any OT device communicating with IP ranges in ASN 213790 (77.90.185[.]0/24, 185.93.89[.]0/24) or ASN 215930 (62.60.130[.]0/24). Block: The following high-confidence IOCs should be blocked at perimeter firewalls immediately:
HUNT 02 · T1566.001
Hunt Hypothesis 2: PULSAR KITTEN Employment-Themed Phishing
Hunt: Search email logs for employment/recruitment-themed lures referencing satellite, telecommunications, or aerospace companies. Look for AnyDesk installations not approved by IT. Search for password spray patterns against ManageEngine or internet-facing applications. Detect: Alert on SilkySand or SurveyAgent behavioral indicators — DLL sideloading, scheduled task persistence, DNS-over-HTTPS C2. Investigate: Any user in aerospace/defense/satellite roles who clicked links in recruitment emails in the past 6 months.
HUNT 03 · T1552.001
Hunt Hypothesis 3: MikroTik WireGuard Key Extraction
Hunt: Identify all MikroTik RouterOS devices in the environment. Check firmware versions against the advisory. Query for any unauthorized export of WireGuard configurations. Detect: Alert on plaintext transmission of WireGuard private keys from MikroTik devices. Action: Isolate unpatched MikroTik devices from sensitive network segments immediately.
HUNT 04 · T1195.002
Hunt Hypothesis 4: AI Agent / Supply Chain Compromise
Hunt: Audit npm/PyPI dependencies for unexpected version changes in high-value packages (axios, debug, chalk). Check CI/CD pipelines for unpinned dependencies or GitHub Actions using version tags instead of commit SHAs. Detect: Alert on anomalous API calls to AI model endpoints (DeepSeek, Claude, GPT) from production infrastructure. Monitor for Hermes Agent framework indicators.

Financial Services
Wire Transfer, SWIFT Systems
Primary threat
Iranian-linked LockBit infrastructure on ASN 213790 explicitly targets financial services; Pioneer Kitten (UNC757) has a documented history of selling network access to ransomware affiliates after conducting state espionage
Actions
  • Audit all VPN and remote access appliances for CVE-2022-47966 (ManageEngine) and CVE-2021-44228 (Log4Shell) — both exploited by PULSAR KITTEN and Pioneer Kitten
  • Implement behavioral analytics on wire transfer and SWIFT systems for anomalous access patterns during non-business hours
  • Monitor ASN 213790 and ASN 215930 connections to any financial application infrastructure
Energy
Fuel Distribution, Power Generation
Primary threat
Toptech Systems RCU II+ and Multiload II+ vulnerabilities (petroleum loading systems) and MZ Automation libiec61850 (power grid protocol) advisories directly affect this sector; Iranian proxies have historically targeted fuel distribution and power generation
Actions
  • Conduct emergency audit of all Toptech petroleum loading systems for internet exposure; verify libiec61850 library versions in any IEC 61850 SCADA deployments
  • Segment all OT networks from corporate IT with unidirectional gateways where possible; implement allowlisting on HMI/engineering workstations
  • Monitor any outbound connections from OT segments to Iranian IP ranges or unexpected DNS queries from SCADA systems
Healthcare
Legacy Systems, Clinical Networks
Primary threats
Not the primary target this cycle, but healthcare organizations often share IT infrastructure characteristics with water utilities (legacy systems, limited security staff, internet-exposed management interfaces)
Actions
  • Identify any Schneider Electric IGSS deployments in building management systems (HVAC, power distribution); audit MikroTik routers in clinical network segments
  • Verify that medical device networks are segmented from internet-facing infrastructure; ensure backup systems for critical patient care can operate independently
  • Monitor for Cactus ransomware indicators — ASN 215930 infrastructure targets education and healthcare with similar attack patterns
Government
Destructive Wiper Exposure
Primary threat
Cavern Manticore's "Operation Epic Fury" targets government entities with destructive wipers; BANISHED KITTEN (Cotton Sandstorm) maintains influence operation and destructive capability against Western allied governments
Actions
  • Validate offline backup integrity for all critical government systems; ensure wiper detection signatures (BiBi-Linux, Handala Wiper variants) are current
  • Implement canary files in sensitive directories to detect wiper reconnaissance; brief personnel on employment-themed phishing (PULSAR KITTEN vector)
  • Monitor unusual bulk file deletion, MBR/VBR modification attempts, and anomalous service installations during non-business hours
Aviation / Logistics
Satellite Comms, GPS-Dependent Logistics
Primary threats
PULSAR KITTEN's targeting of satellite telecommunications and space-launch entities directly threatens aviation communications, GPS-dependent logistics, and defense supply chains
Actions
  • Audit all satellite communication ground station access controls; verify AnyDesk and similar remote access tools are not installed on critical systems without authorization
  • Implement MFA on all ManageEngine and similar IT management platforms; conduct targeted phishing awareness training for satellite operations, launch support, and defense logistics roles
  • Monitor password spray attempts against internet-facing applications, particularly from IP ranges associated with Iranian hosting providers; alert on any SilkySand/SurveyAgent behavioral indicators

Block all six IOCs listed in this report at perimeter firewalls; add ASN 213790 to monitoring watchlist.
SOC Analyst
Audit and remove ALL internet-exposed PLCs, SCADA HMIs, and OT management interfaces — zero tolerance per CISA guidance.
ICS / OT
Identify and isolate all MikroTik RouterOS devices pending WireGuard vulnerability patching.
Incident ResponderICS / OT
Deploy detection rules for Unitronics, Schneider IGSS, and Toptech system communications to known-bad infrastructure.
SOC Analyst
Validate incident response playbook for destructive wiper scenario — ensure offline backups are tested and accessible.
CISO / ExecIncident Responder
No immediate actions for the selected roles.
Patch Schneider Electric IGSS Definition module; update libiec61850 libraries in IEC 61850 deployments.
ICS / OT
Pin all npm/PyPI dependencies to exact versions; enable package integrity verification; audit for typosquatting packages.
Incident Responder
Implement hunting queries for PULSAR KITTEN TTPs: employment-themed phishing, AnyDesk persistence, ManageEngine exploitation.
Threat Hunter
Brief executive leadership on AI agent autonomous offensive capability — three confirmed incidents demonstrate the threat is operational, not theoretical.
CISO / Exec
Conduct password spray detection audit on all internet-facing applications; implement account lockout and MFA where missing.
Incident ResponderIAM Analyst
No 7-day actions for the selected roles.
Commission assessment of OT/ICS security posture across all operational technology environments — prioritize water, energy, and petroleum systems.
CISO / ExecICS / OT
Implement unidirectional security gateways (data diodes) between OT and IT networks where bidirectional communication is not operationally required.
ICS / OT
Evaluate CI/CD pipeline exposure to AI-agent-driven supply chain attacks; implement runtime behavioral monitoring for build systems.
Threat Hunter
Develop organizational policy on AI model access from production infrastructure — define acceptable use boundaries and monitoring requirements.
CISO / Exec
Update incident response plans to include scenarios for multi-site OT compromise, destructive wiper deployment, and autonomous AI agent intrusion.
Incident ResponderCISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Five months into the Iran-Israel conflict, Iranian cyber operations have crossed a threshold. The Minnesota water systems attack — affecting 30+ communities simultaneously — demonstrates that Iranian proxies have moved from opportunistic probing to coordinated, multi-target OT operations against U.S. critical infrastructure. The silence from pro-Iran hacktivist groups Handala and Cyber Toufan — now exceeding ten days — is not reassuring; historically, operational pauses from these groups precede escalation to destructive operations.

1
Is any PLC, HMI, or SCADA system in your environment reachable from the internet? Assume it is being targeted. Remove it now — not next sprint.
2
Does your organization touch defense industrial base contracts, satellite communications, or aerospace manufacturing? PULSAR KITTEN ran a six-month campaign against exactly this target set.
3
Are your detection and response timelines built for machine-speed attacks? Three confirmed incidents this week show AI agents conducting autonomous, human-free intrusions today.
No items found.