| Date | Development | Significance |
|---|---|---|
| Jun 27 | Pro-Iranian hacktivist activity ceases — Day 0 of silence (Handala, Cyber Av3ngers, Banished Kitten) | Anomalous pause; historical cycles run 7–14 days |
| Jul 18 | Pioneer Kitten campaign data updated in threat feeds — multi-vertical targeting active | Access broker operation confirmed ongoing |
| Jul 21 | MuddyWater produces first defense-sector Hive ransomware sample (MuddyWater/Dalbit crossover) | Iranian MOIS APT using ransomware as espionage cover — complicates attribution and response |
| Jul 21 | Eight ICS/SCADA advisories published — Siemens RUGGEDCOM and Rockwell Automation PLCs | OT attack surface expanding; Rockwell advisory includes arbitrary file execution on PLCs |
| Jul 22 | CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to CISA KEV with confirmed in-the-wild exploitation | Auth bypass granting unauthenticated admin access to firewall policy management — fits Pioneer Kitten's exact playbook |
| Jul 22 | MuddyWater/Dalbit samples refreshed — targeting expanded to defense, manufacturing, healthcare, retail, construction | Pre-positioning acceleration across five sectors |
| Jul 22 | U.S. Cyber Command role in Operation Midnight Hammer publicly confirmed | Provides Iran propaganda justification for retaliatory cyber operations |
| Jul 23 | Fresh Remcos RAT C2 on Iranian academic infrastructure (IROST, port 43155); Cobalt Strike staging on Aria Shatel (ASN 31549) | Infrastructure diversification to academic networks evades commercial threat feeds |
| Jul 23 | Day 26 of hacktivist silence — all five retaliation indicators now triggered simultaneously | Unprecedented pause duration; structural pre-positioning assessment elevated to CRITICAL |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before Feb 28, 2026 | Baseline APT34/OilRig, MuddyWater, Pioneer Kitten operations — espionage, credential harvesting, access brokering |
| Military confrontation begins | Feb 28, 2026 | Iran-Israel/Western military confrontation initiated; Iranian cyber apparatus begins mobilization |
| HOLLOWGRAPH deployment | Jun 3, 2026 | APT34/OilRig deploys HOLLOWGRAPH implant using Microsoft 365 Graph API as covert C2 channel against Israeli targets |
| Kinetic escalation | Jun 26, 2026 | U.S. Operation Midnight Hammer strikes Iranian nuclear facilities; cyber component confirmed — significant retaliation trigger |
| Proxy silence begins | Jun 27, 2026 | Pro-Iranian hacktivist coalition goes operationally silent; infrastructure refresh and malware updates begin in parallel |
| Active retaliation window | Jul 18 – Jul 22, 2026 | Pioneer Kitten multi-vertical targeting active; MuddyWater/Dalbit samples updated; CVE-2026-16232 actively exploited; Midnight Hammer confirmed publicly — all retaliation triggers satisfied |
| Current (Day 26) | Jul 23, 2026 | Fresh Remcos C2 on academic infrastructure; Cobalt Strike staging on Aria Shatel; all five structural retaliation indicators triggered; HOLLOWGRAPH expanding beyond Israel |
Handala (UNC5203), Cyber Av3ngers, and Banished Kitten have been operationally silent since June 27 — Day 26 as of this report. Historical cycles for these groups run 7–14 days. A 26-day pause is unprecedented and, combined with the infrastructure indicators documented in this bulletin, is assessed as operational preparation for a coordinated retaliatory strike rather than capability degradation.
A five-point retaliation readiness model developed from historical Iranian operational patterns is now fully satisfied: (1) hacktivist silence exceeds 14 days — currently Day 26, nearly double the threshold; (2) C2 infrastructure actively refreshing across multiple Iranian ASNs; (3) fresh C2 provisioning confirmed — Remcos and Cobalt Strike; (4) ICS/OT vulnerability accumulation accelerating with eight new advisories; (5) geopolitical tension sustained with public escalation triggers including confirmed U.S. Cyber Command role in Operation Midnight Hammer.
Assessment: this is not inactivity. It is discipline. The convergence of silence and structural preparation is the pre-operational pattern.
A critical authentication bypass in Check Point SmartConsole was added to CISA's Known Exploited Vulnerabilities catalog on July 22 with confirmed in-the-wild exploitation. An unauthenticated attacker who gains access to the SmartConsole management interface can obtain admin-level access to firewall policy management — enabling silent modification of firewall rules to open pathways for subsequent operations.
Pioneer Kitten (Fox Kitten/UNC757) has built its entire operational model around exploiting network security appliances — Fortinet, Pulse Secure, Citrix, Ivanti — for initial access. Check Point is a natural and predictable addition to this toolkit. Its Israeli origin means it is widely deployed in Middle Eastern government and military networks that Iranian APTs prioritize. An attacker with SmartConsole admin access effectively turns an organization's primary perimeter defense into an enabler of compromise.
Emergency action: verify SmartConsole Management Servers are not internet-accessible and apply vendor hotfix per SK185169 within 24 hours.
Intelligence confirms an active operational handoff between three Iranian threat actor clusters, with seven co-tagged malware samples evidencing the kill chain. CVE-2026-16232 is assessed as a likely next entry point feeding this pipeline, with Rockwell PLC vulnerabilities providing the OT pivot opportunity.
| Actor | Affiliation | Role | Status |
|---|---|---|---|
| Pioneer Kitten (Fox Kitten, UNC757) | IRGC | Initial access broker — network appliance exploitation (CVE-2026-16232) | Active — updated Jul 18 |
| Handala / Banished Kitten | IRGC | Destructive operators — wiper deployment, DDoS | Silent (Day 26) — assessed as pre-operational |
| Cyber Av3ngers | IRGC | ICS/OT specialists — PLC manipulation, water/energy targeting | Silent (Day 26) — ICS advisories accumulating |
The pipeline sequence: Pioneer Kitten exploits network appliances for initial access → access transferred to destructive operators → destructive operators deploy wipers or manipulate ICS/OT systems. Weeks to months may separate stages — absence of active Handala/Cyber Av3ngers activity does not indicate the pipeline is dormant.
MuddyWater (MOIS-affiliated) and its Dalbit crossover represent a sophisticated operational security technique: conducting espionage operations under the guise of criminal ransomware activity. New samples refreshed July 22 expand targeting to defense, manufacturing, healthcare, retail, and construction. Victims who believe they've been hit by ransomware may focus on recovery rather than investigating the full scope of data exfiltration.
The involvement of Dalbit (linked to North Korean Silent Chollima/DPRK) introduces a secondary concern: this may represent shared tooling marketplaces or deliberate operational partnerships between Iranian and DPRK actors. If confirmed, this complicates attribution and may represent an emerging multi-state threat model requiring updated threat modeling assumptions.
Key indicator: if ransomware deploys but exfiltration preceded it — this is espionage, not crime. Treat all ransomware incidents in affected sectors as presumptive espionage pending forensic confirmation.
The HOLLOWGRAPH implant, active since June 2026 against Israeli targets, uses Microsoft 365 Graph API — specifically calendar item creation and reading — as a covert command-and-control channel. This technique bypasses traditional C2 detection that monitors for connections to known malicious infrastructure; all traffic appears as legitimate Microsoft 365 API calls.
By July 21, APT34 expanded HOLLOWGRAPH targeting to Malaysia and Australia. Western expansion is assessed as the logical next step. Organizations relying on network-level C2 detection will have no visibility into this technique unless Entra ID OAuth grants and Graph API call volumes are actively monitored.
Detection focus: audit OAuth application grants with Mail.Read, Calendars.ReadWrite, or Files.Read.All permissions granted to unfamiliar applications. Monitor for calendar items being created or read by service principals rather than users.
Iranian C2 infrastructure has expanded from a single commercial hosting provider to four distinct networks this cycle, with two new techniques deployed to evade commercial threat feeds:
| ASN | Provider | Usage |
|---|---|---|
| 213790 | Limited Network | Primary C2 hosting — 3 active IPs, financial and government targeting |
| 34918 | Pishgaman Toseeh | Secondary C2 hosting |
| 31549 | Aria Shatel | Cobalt Strike beacon staging (port 9090) — third Iranian ISP added this cycle |
| Academic | IROST (Iranian Research Organization for Science & Technology) | Remcos RAT C2 on port 43155 — new academic infrastructure diversification |
The shift to Iranian academic infrastructure is a deliberate evasion tactic: commercial threat feeds are primarily keyed to known VPS providers and Iranian ISP ASNs. Academic network traffic is routinely permitted through enterprise firewalls. IP/ASN-based blocking alone now produces an increasingly incomplete picture — behavioral C2 detection is essential.
Eight ICS/SCADA advisories from CISA published this cycle cover Siemens RUGGEDCOM APE1808 and Rockwell Automation products. The most critical: a Rockwell Studio 5000 Logix Designer advisory (ICSA-26-202-10) allowing arbitrary file execution and configuration alteration on PLCs — directly aligning with Cyber Av3ngers' documented capability set and operational interests in water and energy infrastructure.
Also of note: Rockwell 1734 POINT I/O and 1718/1719-AENTR modules with denial-of-service vulnerabilities; and Siemens SIDIS Secured SmartPlug with OpenSSL/OpenSSH vulnerabilities in industrial firewall contexts. Cyber Av3ngers' demonstrated history of PLC manipulation (Unitronics, Rockwell targets in prior cycles) makes these high-priority patches for OT defenders, particularly in energy and water utilities.
The MuddyWater/Dalbit crossover — with Dalbit linked to North Korean Silent Chollima — represents a potentially significant development in Iranian cyber operations. Whether this reflects shared tooling marketplaces (where Iranian and DPRK actors independently acquire similar capabilities) or deliberate operational partnerships, the practical consequence is the same: ransomware deployed against organizations in the threat aperture may simultaneously serve Iranian espionage objectives and North Korean financial objectives.
Why it matters: standard ransomware response procedures assume a financially-motivated criminal adversary with no persistent access interest. If MuddyWater is the true operator using Dalbit tooling as cover, the incident scope extends to full espionage investigation protocols — network forensics, long-term access review, and breach notification obligations that a criminal ransomware incident would not trigger. This emerging model requires updated IR playbook assumptions for any affected sector.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Coordinated hacktivist operation breaks 26-day silence — Handala/Cyber Toufan targeting Israeli CI, U.S. utilities, or Gulf financial sector | 70% | 7 days | New Handala/Banished Kitten Telegram channels; infrastructure overlap with known IOCs; DDoS traffic to Israeli or U.S. targets |
| CVE-2026-16232 weaponized by Iranian actors for SmartConsole initial access | 50% | 14 days | Check Point incident reports; CISA KEV exploitation confirmation; Middle East government network compromise disclosures |
| ICS/OT disruption attempt against water or energy utility | 45% | 14 days | ICS-CERT incident reports; Cyber Av3ngers claims; Rockwell PLC anomaly events in energy/water sectors |
| HOLLOWGRAPH M365 C2 technique deployed against Western (non-Israeli) targets | 40% | 21 days | APT34 IOC overlap in Western enterprise tenants; Entra ID OAuth grant anomalies; Graph API call spike patterns |
| MuddyWater/DPRK partnership produces novel combined operation | 30% | 30 days | New crossover malware samples; shared C2 infrastructure between Iranian and DPRK IOC sets; ransomware incidents with concurrent exfiltration indicators |
| Rule | Data Source | ATT&CK | Priority |
|---|---|---|---|
| SmartConsole management interface auth events from unexpected source IPs; admin token issuance or firewall rule modification outside change windows (CVE-2026-16232) | Check Point logs / SIEM | T1190 | CRITICAL |
Outbound connections to 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (ASN 213790); 62.60.226[.]42 port 43155 (Remcos); 151.239.25[.]40 port 9090 (Cobalt Strike) | Firewall / Netflow | T1071.001 | CRITICAL |
| SHA-256 match on MuddyWater/Dalbit crossover hashes across endpoint telemetry (see IOC block below) | EDR | T1486 | HIGH |
| OAuth application grants with Mail.Read, Calendars.ReadWrite, or Files.Read.All permissions granted to unrecognized apps; Graph API call volume anomalies; calendar items created/read by service principals | Entra ID / Microsoft 365 | T1550.001 | HIGH |
| PowerShell execution chains preceding encryption activity; data staging (file archiving, large internal transfers) before encryption begins | EDR / Sysmon | T1059.001 | HIGH |
| Rockwell Studio 5000 Logix Designer project file modifications from non-engineering workstations; PLC configuration downloads outside scheduled maintenance windows | ICS / OT logs | T1495 | MEDIUM |
| Beaconing patterns to Iranian ASNs 213790, 34918, 31549 — detect via JA3/JA4 Cobalt Strike and Remcos fingerprinting rather than IP-only blocking | Firewall / NDR | T1071.001 | MEDIUM |
ASN 213790 cluster (Limited Network) — C2, financial and government targeting, HIGH confidence. Remcos RAT C2 on Iranian academic infrastructure (IROST), port 43155, HIGH confidence. Cobalt Strike beacon staging on Aria Shatel (ASN 31549), port 9090. MuddyWater/Dalbit crossover hashes: cd11e8baec2f5254a2ce9f236b5091968b950c172e6fdce25b140347b7d787ac (defense/healthcare/retail), e977e8d48c8725dec2dde597eb4faca321bafd4faf3932dca5f07f09e847b705 (defense/manufacturing), 1ca62a560ee6885b9c9187ade5c8933ec28a52323ffbc39f8e2ba9c9fb151247 (commercial/construction). Additional IOCs available via Anomali ThreatStream and partner feeds.
185.93.89[.]75, 77.90.185[.]118) explicitly tagged for financial sector targeting; Gulf state financial institutions assessed as likely hacktivist retaliation targets; Check Point SmartConsole exposure in payment processing environments- Validate DDoS mitigation capacity for sustained volumetric attacks — Cyber Av3ngers' preferred hacktivist tactic targeting financial sector
- Audit SWIFT/payment system network segmentation — ensure no path from internet-facing systems to transaction infrastructure
- Monitor for credential harvesting campaigns (T1566 phishing tags on all ASN 213790 IPs) targeting financial sector employees
- Emergency review of Check Point firewall exposure in payment processing environments; apply SK185169 hotfix within 24 hours
- Prioritize patching Rockwell Studio 5000 Logix Designer (ICSA-26-202-10) — highest-severity OT advisory this cycle
- Validate IT/OT air-gap integrity; audit jump hosts and data diodes for misconfiguration enabling lateral movement
- Deploy integrity monitoring on PLC project files — alert on any modification outside scheduled maintenance windows
- Conduct tabletop exercise: "Adversary gains SmartConsole admin access and opens firewall rules to OT network"
cd11e8baec2f5254a2ce9f236b5091968b950c172e6fdce25b140347b7d787ac explicitly targets healthcare; ASN 213790 IP 77.90.185[.]118 also tagged for healthcare; ransomware-as-cover model means initial response may miss underlying espionage- Hunt for the three MuddyWater/Dalbit SHA-256 hashes across all endpoint telemetry immediately
- Ensure backup isolation — if ransomware deploys, assume exfiltration has already occurred and initiate breach notification assessment in parallel with recovery
- Monitor for PowerShell execution chains (T1059.001) on clinical workstations — anomalous in healthcare and a strong pre-indicator
- Audit medical device network segmentation for Rockwell DoS vulnerability exposure
- Emergency priority: verify all Check Point SmartConsole Management Servers are not internet-accessible; apply hotfix SK185169 within 24 hours
- Audit all Check Point admin accounts for unauthorized additions or token issuance in the past 30 days
- Audit Entra ID for OAuth grants with Mail.Read or Calendar permissions — HOLLOWGRAPH uses calendar API for covert C2
- Monitor for access-to-destruction handoff: network appliance compromise → lateral movement → destructive payload (weeks to months between stages)
e977e8d48c8725dec2dde597eb4faca321bafd4faf3932dca5f07f09e847b705 targets manufacturing; Siemens SIDIS Secured SmartPlug vulnerabilities in airport/logistics industrial firewall contexts; Rockwell 1718/1719-AENTR DoS in logistics automation environments- Audit PTC Windchill and PLM systems for unauthorized access — Iranian DIB espionage priority
- Review Siemens SIDIS Secured SmartPlug deployments in airport and logistics infrastructure for OpenSSL/OpenSSH vulnerabilities
- Monitor for Cobalt Strike beacon traffic (port 9090 staging pattern) from operational technology segments
- Validate cargo handling and baggage system PLCs are not accessible from corporate IT networks
62.60.226[.]42:43155 (Remcos C2), 151.239.25[.]40:9090 (Cobalt Strike), 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (ASN 213790 C2 cluster). Hunt historical connections in 90-day netflow.cd11e8baec2f5254... (defense/healthcare/retail), e977e8d48c8725de... (defense/manufacturing), 1ca62a560ee6885b... (commercial/construction).We are watching an adversary prepare. The 26-day hacktivist silence is not inactivity — it is discipline. The C2 infrastructure refresh across four Iranian ASNs is not routine maintenance — it is staging. The malware updates targeting your sector specifically are not academic exercises — they are targeting your sector specifically. The Iranian cyber apparatus has historically used periods of apparent quiet to pre-position for coordinated operations combining destructive attacks, espionage, ICS disruption, and information operations simultaneously. Every structural indicator suggests we are in that pre-positioning window now. The window for defensive preparation is measured in days, not weeks.