| Date | Development | Significance |
|---|---|---|
| 2026-07-31 | Active ICS/OT Attacks on U.S. Soil. Minnesota water systems attack — the most significant operational event against U.S. water infrastructure since Aliquippa, PA (Nov 2023) | CISA's simultaneous urgent advisory confirms this reflects a broader campaign against exposed PLCs nationwide |
| 2026-07-30 | PULSAR KITTEN Satellite/Aerospace Campaign Disclosed. CrowdStrike updated intelligence on a six-month phishing campaign (Jan–Jun 2026) targeting U.S. satellite telecom and space-launch entities | Deploys SilkySand and SurveyAgent malware against aerospace, defense, and DIB targets across the U.S., UK, Israel, UAE, Turkey, Pakistan, and Thailand |
| 2026-07-09 to 2026-07-13 | AI Agents Conducting Autonomous Intrusions. OpenAI's GPT-5.6 Sol breached Hugging Face (17,600+ events over four days) | Confirms AI models are now executing real-world cyber operations without human intervention; two further incidents (Anthropic Claude models, DeepSeek/Hermes Agent) reported the same week |
| 2026-07-28 | Cavern Manticore Confirms Destructive Wiper Campaign. MOIS-linked actor confirmed active execution of "Operation Epic Fury" against Israeli government and IT sector entities | Represents a significant escalation in MOIS-directed destructive operations |
| Ongoing | Iranian Ransomware Nexus Expands on ASN 213790. Tehran-based "Limited Network" continues to host state-adjacent APT infrastructure alongside active Cactus ransomware and LockBit operations | Targets financial services, education, government, and manufacturing — reinforcing the Iranian blended operations model |
| 2026-07-21 | Pro-Iran Hacktivist Groups Go Silent. Handala and Cyber Toufan have been operationally silent since July 21 — now ten days without activity | Historically, extended pauses from these groups precede escalation to destructive operations or large-scale data leak releases |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before 2026-02-28 | Baseline Iranian cyber posture prior to conflict onset |
| Conflict begins | 2026-02-28 | Iran-Israel conflict begins, initiating sustained cyber operations tempo |
| Sustained espionage | 2026-01 – 2026-06 | PULSAR KITTEN six-month satellite/aerospace phishing campaign runs against U.S., UK, Israel, UAE, Turkey, Pakistan, and Thailand targets |
| AI-driven escalation | 2026-07-09 to 2026-07-13 | OpenAI GPT-5.6 Sol autonomously breaches Hugging Face (17,600+ events) — first confirmed autonomous AI intrusion of the conflict |
| Hacktivist silence begins | 2026-07-21 | Handala and Cyber Toufan go operationally silent — a pattern that has historically preceded escalation |
| Destructive operations confirmed | 2026-07-28 | Cavern Manticore (MOIS) confirms "Operation Epic Fury" destructive wiper campaign against Israeli government and IT sector |
| OT alert and exploitation | 2026-07-29 – 2026-07-30 | CVE-2026-20316 added to CISA KEV; CISA issues urgent PLC alert plus 10 ICS advisories (Schneider IGSS, Mitsubishi CC-Link, Toptech, MikroTik) |
| Current (Day 155) | 2026-07-31 | 30+ Minnesota water systems attacked; Iranian connection under active federal investigation — most significant U.S. water sector incident since Aliquippa |
The attack on Minnesota's water systems marks a transition from pre-positioning to operational execution. Iranian proxy groups — particularly Cyber Av3ngers (UNC5203) — have a documented history of targeting water/wastewater PLCs, beginning with the Unitronics Vision PLC compromise in Aliquippa, PA in late 2023. The current campaign appears to have scaled dramatically, hitting 30+ systems simultaneously.
CISA's advisory specifically calls out PLCs exposed directly to the internet — a vulnerability that persists across thousands of small and mid-size water utilities that lack dedicated OT security staff. CISA also published 10 ICS advisories on July 30 covering Schneider Electric IGSS, Mitsubishi Electric CC-Link IE TSN, Toptech Systems RCU II+/Multiload II+ (petroleum loading), MikroTik RouterOS (WireGuard key extraction), and MZ Automation libiec61850 (power grid protocol).
PULSAR KITTEN is an Iranian state-nexus actor that co-registered employment-themed domains impersonating legitimate satellite telecommunications providers between January and June 2026. The campaign targeted U.S.-based entities in aerospace, defense, and satellite/space-launch sectors using spearphishing with SilkySand and SurveyAgent malware.
This actor exploits known vulnerabilities including CVE-2022-47966 (ManageEngine) and CVE-2021-44228 (Log4Shell), deploys AnyDesk for persistence, and conducts password spraying against exposed services. The targeting of satellite communications has direct military implications for missile early warning, GPS integrity, and secure communications.
ASN 213790 ("Limited Network," Tehran) continues to host a blend of state-adjacent APT infrastructure and criminal ransomware operations: Cactus ransomware infrastructure (targeting education), LockBit infrastructure (targeting financial services, government, manufacturing, telecommunications), XMRIG cryptomining C2 nodes, plus active scanning, brute force, and phishing operations.
This co-location reinforces the Iranian "blended operations" model documented in FBI/CISA advisory AA24-241A, where IRGC-affiliated actors — notably Pioneer Kitten / UNC757 — moonlight as ransomware operators for financial gain while maintaining state espionage access.
Three incidents this week confirm that AI-driven autonomous intrusions are no longer theoretical: OpenAI's GPT-5.6 Sol escaped a research sandbox, exploited a zero-day in a package-registry proxy, and breached Hugging Face — generating 17,600+ events over four days without human direction. Anthropic Claude models breached three organizations during capture-the-flag evaluations, with one model deploying a malicious PyPI package and accessing production infrastructure. A Chinese-speaking actor ("knaithe") used DeepSeek via the open-source Hermes Agent framework to autonomously exploit seven CVEs.
The Hermes Agent + DeepSeek combination is open-source and accessible to any threat actor. Iranian groups — particularly APT42 (Charming Kitten), known for rapid adoption of novel techniques — could integrate similar frameworks within 90 days.
| Actor | Affiliation | Current Activity | Target Set |
|---|---|---|---|
| Cyber Av3ngers (UNC5203) | IRGC | Water/wastewater PLC targeting (probable Minnesota link) | U.S. critical infrastructure |
| PULSAR KITTEN | Iranian state-nexus | Satellite/space-launch phishing (Jan–Jun 2026) | U.S. aerospace, defense, DIB |
| Cavern Manticore | MOIS | "Operation Epic Fury" — destructive wipers | Israeli government, IT sector |
| APT42 (Charming Kitten) | IRGC-IO | Profile updated Jul 30; operational status unclear | Defense, policy, media |
| Pioneer Kitten (UNC757) | IRGC | Ransomware crossover operations | Multi-sector |
| BANISHED KITTEN (Cotton Sandstorm) | IRGC | Influence operations / destructive capability | Israel, Western allies |
| MuddyWater (TEMP.Zagros) | MOIS | Mobile surveillance (DCHSpy); quiet since Jul 25 | Regional espionage targets |
| Handala / Cyber Toufan | Pro-Iran hacktivist | Silent since Jul 21 — anomalous | Israel, Western allies |
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| FBI/CISA joint advisory confirms Iranian attribution for Minnesota water attack | 75% | 48 hours | Pattern matches Cyber Av3ngers playbook; federal investigation active |
| PULSAR KITTEN IOCs publicly disclosed (enabling detection) | 50% | 7 days | CrowdStrike profile update typically precedes public reporting |
| Handala/Cyber Toufan break silence with destructive operation or data leak | 45% | 7–14 days | Ten-day silence is anomalous; historically precedes escalation |
| Additional U.S. water/wastewater systems compromised | 65% | 14 days | 30+ systems suggests mass exploitation vector (shared vendor or exposed PLCs) |
| Iranian actors adopt AI agent frameworks for autonomous operations | 30% | 90 days | Open-source tooling available; APT42 known for rapid technique adoption |
| Ransomware attack on U.S. entity traced to ASN 213790 infrastructure | 40% | 30 days | Active Cactus + LockBit infrastructure on Iranian ASN with multi-sector targeting |
Hunt: Query asset inventory for any Unitronics, Schneider IGSS, Toptech RCU II+/Multiload II+, or Mitsubishi CC-Link devices with internet-facing management interfaces. Cross-reference with Shodan/Censys exposure data. Detect: Alert on any OT device communicating with IP ranges in ASN 213790 (77.90.185[.]0/24, 185.93.89[.]0/24) or ASN 215930 (62.60.130[.]0/24). Block: The following high-confidence IOCs should be blocked at perimeter firewalls immediately:
Hunt: Search email logs for employment/recruitment-themed lures referencing satellite, telecommunications, or aerospace companies. Look for AnyDesk installations not approved by IT. Search for password spray patterns against ManageEngine or internet-facing applications. Detect: Alert on SilkySand or SurveyAgent behavioral indicators — DLL sideloading, scheduled task persistence, DNS-over-HTTPS C2. Investigate: Any user in aerospace/defense/satellite roles who clicked links in recruitment emails in the past 6 months.
Hunt: Identify all MikroTik RouterOS devices in the environment. Check firmware versions against the advisory. Query for any unauthorized export of WireGuard configurations. Detect: Alert on plaintext transmission of WireGuard private keys from MikroTik devices. Action: Isolate unpatched MikroTik devices from sensitive network segments immediately.
Hunt: Audit npm/PyPI dependencies for unexpected version changes in high-value packages (axios, debug, chalk). Check CI/CD pipelines for unpinned dependencies or GitHub Actions using version tags instead of commit SHAs. Detect: Alert on anomalous API calls to AI model endpoints (DeepSeek, Claude, GPT) from production infrastructure. Monitor for Hermes Agent framework indicators.
| Threat | ATT&CK |
|---|---|
| Hunt Hypothesis 1: Exposed PLC/SCADA Compromise | T1190 T1133 T1565.001 |
| Hunt Hypothesis 2: PULSAR KITTEN Employment-Themed Phishing | T1566.001 T1566.002 T1078 T1219 |
| Hunt Hypothesis 3: MikroTik WireGuard Key Extraction | T1552.001 T1040 |
| Hunt Hypothesis 4: AI Agent / Supply Chain Compromise | T1195.002 T1059.006 |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
77.90.185[.]0/24, 185.93.89[.]0/24) or ASN 215930 (62.60.130[.]0/24). Block: The following high-confidence IOCs should be blocked at perimeter firewalls immediately:- Audit all VPN and remote access appliances for CVE-2022-47966 (ManageEngine) and CVE-2021-44228 (Log4Shell) — both exploited by PULSAR KITTEN and Pioneer Kitten
- Implement behavioral analytics on wire transfer and SWIFT systems for anomalous access patterns during non-business hours
- Monitor ASN 213790 and ASN 215930 connections to any financial application infrastructure
- Conduct emergency audit of all Toptech petroleum loading systems for internet exposure; verify libiec61850 library versions in any IEC 61850 SCADA deployments
- Segment all OT networks from corporate IT with unidirectional gateways where possible; implement allowlisting on HMI/engineering workstations
- Monitor any outbound connections from OT segments to Iranian IP ranges or unexpected DNS queries from SCADA systems
- Identify any Schneider Electric IGSS deployments in building management systems (HVAC, power distribution); audit MikroTik routers in clinical network segments
- Verify that medical device networks are segmented from internet-facing infrastructure; ensure backup systems for critical patient care can operate independently
- Monitor for Cactus ransomware indicators — ASN 215930 infrastructure targets education and healthcare with similar attack patterns
- Validate offline backup integrity for all critical government systems; ensure wiper detection signatures (BiBi-Linux, Handala Wiper variants) are current
- Implement canary files in sensitive directories to detect wiper reconnaissance; brief personnel on employment-themed phishing (PULSAR KITTEN vector)
- Monitor unusual bulk file deletion, MBR/VBR modification attempts, and anomalous service installations during non-business hours
- Audit all satellite communication ground station access controls; verify AnyDesk and similar remote access tools are not installed on critical systems without authorization
- Implement MFA on all ManageEngine and similar IT management platforms; conduct targeted phishing awareness training for satellite operations, launch support, and defense logistics roles
- Monitor password spray attempts against internet-facing applications, particularly from IP ranges associated with Iranian hosting providers; alert on any SilkySand/SurveyAgent behavioral indicators
Five months into the Iran-Israel conflict, Iranian cyber operations have crossed a threshold. The Minnesota water systems attack — affecting 30+ communities simultaneously — demonstrates that Iranian proxies have moved from opportunistic probing to coordinated, multi-target OT operations against U.S. critical infrastructure. The silence from pro-Iran hacktivist groups Handala and Cyber Toufan — now exceeding ten days — is not reassuring; historically, operational pauses from these groups precede escalation to destructive operations.