TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Apparatus Reaches Pre-Strike Posture:

What CISOs Must Do Now

CRITICAL. Nearly five months into the Iran-Western confrontation, Iranian state cyber operations have reached their highest concentration of pre-positioning indicators since tracking began. A 26-day hacktivist operational silence, active C2 infrastructure refresh across four Iranian ASNs, a new critical Check Point firewall authentication bypass (CVE-2026-16232), and a confirmed access-to-destruction pipeline linking Pioneer Kitten, Handala, and Cyber Av3ngers together create conditions consistent with imminent coordinated retaliation. All five structural indicators are now triggered. This is not a theoretical warning.

I am a
My sector

DateDevelopmentSignificance
Jun 27Pro-Iranian hacktivist activity ceases — Day 0 of silence (Handala, Cyber Av3ngers, Banished Kitten)Anomalous pause; historical cycles run 7–14 days
Jul 18Pioneer Kitten campaign data updated in threat feeds — multi-vertical targeting activeAccess broker operation confirmed ongoing
Jul 21MuddyWater produces first defense-sector Hive ransomware sample (MuddyWater/Dalbit crossover)Iranian MOIS APT using ransomware as espionage cover — complicates attribution and response
Jul 21Eight ICS/SCADA advisories published — Siemens RUGGEDCOM and Rockwell Automation PLCsOT attack surface expanding; Rockwell advisory includes arbitrary file execution on PLCs
Jul 22CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to CISA KEV with confirmed in-the-wild exploitationAuth bypass granting unauthenticated admin access to firewall policy management — fits Pioneer Kitten's exact playbook
Jul 22MuddyWater/Dalbit samples refreshed — targeting expanded to defense, manufacturing, healthcare, retail, constructionPre-positioning acceleration across five sectors
Jul 22U.S. Cyber Command role in Operation Midnight Hammer publicly confirmedProvides Iran propaganda justification for retaliatory cyber operations
Jul 23Fresh Remcos RAT C2 on Iranian academic infrastructure (IROST, port 43155); Cobalt Strike staging on Aria Shatel (ASN 31549)Infrastructure diversification to academic networks evades commercial threat feeds
Jul 23Day 26 of hacktivist silence — all five retaliation indicators now triggered simultaneouslyUnprecedented pause duration; structural pre-positioning assessment elevated to CRITICAL

PhaseTimeframeCyber Activity
Pre-escalationBefore Feb 28, 2026Baseline APT34/OilRig, MuddyWater, Pioneer Kitten operations — espionage, credential harvesting, access brokering
Military confrontation beginsFeb 28, 2026Iran-Israel/Western military confrontation initiated; Iranian cyber apparatus begins mobilization
HOLLOWGRAPH deploymentJun 3, 2026APT34/OilRig deploys HOLLOWGRAPH implant using Microsoft 365 Graph API as covert C2 channel against Israeli targets
Kinetic escalationJun 26, 2026U.S. Operation Midnight Hammer strikes Iranian nuclear facilities; cyber component confirmed — significant retaliation trigger
Proxy silence beginsJun 27, 2026Pro-Iranian hacktivist coalition goes operationally silent; infrastructure refresh and malware updates begin in parallel
Active retaliation windowJul 18 – Jul 22, 2026Pioneer Kitten multi-vertical targeting active; MuddyWater/Dalbit samples updated; CVE-2026-16232 actively exploited; Midnight Hammer confirmed publicly — all retaliation triggers satisfied
Current (Day 26)Jul 23, 2026Fresh Remcos C2 on academic infrastructure; Cobalt Strike staging on Aria Shatel; all five structural retaliation indicators triggered; HOLLOWGRAPH expanding beyond Israel

Handala (UNC5203), Cyber Av3ngers, and Banished Kitten have been operationally silent since June 27 — Day 26 as of this report. Historical cycles for these groups run 7–14 days. A 26-day pause is unprecedented and, combined with the infrastructure indicators documented in this bulletin, is assessed as operational preparation for a coordinated retaliatory strike rather than capability degradation.

A five-point retaliation readiness model developed from historical Iranian operational patterns is now fully satisfied: (1) hacktivist silence exceeds 14 days — currently Day 26, nearly double the threshold; (2) C2 infrastructure actively refreshing across multiple Iranian ASNs; (3) fresh C2 provisioning confirmed — Remcos and Cobalt Strike; (4) ICS/OT vulnerability accumulation accelerating with eight new advisories; (5) geopolitical tension sustained with public escalation triggers including confirmed U.S. Cyber Command role in Operation Midnight Hammer.

Assessment: this is not inactivity. It is discipline. The convergence of silence and structural preparation is the pre-operational pattern.

A critical authentication bypass in Check Point SmartConsole was added to CISA's Known Exploited Vulnerabilities catalog on July 22 with confirmed in-the-wild exploitation. An unauthenticated attacker who gains access to the SmartConsole management interface can obtain admin-level access to firewall policy management — enabling silent modification of firewall rules to open pathways for subsequent operations.

Pioneer Kitten (Fox Kitten/UNC757) has built its entire operational model around exploiting network security appliances — Fortinet, Pulse Secure, Citrix, Ivanti — for initial access. Check Point is a natural and predictable addition to this toolkit. Its Israeli origin means it is widely deployed in Middle Eastern government and military networks that Iranian APTs prioritize. An attacker with SmartConsole admin access effectively turns an organization's primary perimeter defense into an enabler of compromise.

Emergency action: verify SmartConsole Management Servers are not internet-accessible and apply vendor hotfix per SK185169 within 24 hours.

T1190T1078T1562.001

Intelligence confirms an active operational handoff between three Iranian threat actor clusters, with seven co-tagged malware samples evidencing the kill chain. CVE-2026-16232 is assessed as a likely next entry point feeding this pipeline, with Rockwell PLC vulnerabilities providing the OT pivot opportunity.

ActorAffiliationRoleStatus
Pioneer Kitten (Fox Kitten, UNC757)IRGCInitial access broker — network appliance exploitation (CVE-2026-16232)Active — updated Jul 18
Handala / Banished KittenIRGCDestructive operators — wiper deployment, DDoSSilent (Day 26) — assessed as pre-operational
Cyber Av3ngersIRGCICS/OT specialists — PLC manipulation, water/energy targetingSilent (Day 26) — ICS advisories accumulating

The pipeline sequence: Pioneer Kitten exploits network appliances for initial access → access transferred to destructive operators → destructive operators deploy wipers or manipulate ICS/OT systems. Weeks to months may separate stages — absence of active Handala/Cyber Av3ngers activity does not indicate the pipeline is dormant.

T1190T1486T1495

MuddyWater (MOIS-affiliated) and its Dalbit crossover represent a sophisticated operational security technique: conducting espionage operations under the guise of criminal ransomware activity. New samples refreshed July 22 expand targeting to defense, manufacturing, healthcare, retail, and construction. Victims who believe they've been hit by ransomware may focus on recovery rather than investigating the full scope of data exfiltration.

The involvement of Dalbit (linked to North Korean Silent Chollima/DPRK) introduces a secondary concern: this may represent shared tooling marketplaces or deliberate operational partnerships between Iranian and DPRK actors. If confirmed, this complicates attribution and may represent an emerging multi-state threat model requiring updated threat modeling assumptions.

Key indicator: if ransomware deploys but exfiltration preceded it — this is espionage, not crime. Treat all ransomware incidents in affected sectors as presumptive espionage pending forensic confirmation.

T1059.001T1588.002T1486T1074

The HOLLOWGRAPH implant, active since June 2026 against Israeli targets, uses Microsoft 365 Graph API — specifically calendar item creation and reading — as a covert command-and-control channel. This technique bypasses traditional C2 detection that monitors for connections to known malicious infrastructure; all traffic appears as legitimate Microsoft 365 API calls.

By July 21, APT34 expanded HOLLOWGRAPH targeting to Malaysia and Australia. Western expansion is assessed as the logical next step. Organizations relying on network-level C2 detection will have no visibility into this technique unless Entra ID OAuth grants and Graph API call volumes are actively monitored.

Detection focus: audit OAuth application grants with Mail.Read, Calendars.ReadWrite, or Files.Read.All permissions granted to unfamiliar applications. Monitor for calendar items being created or read by service principals rather than users.

T1550.001T1114.002T1071.001

Iranian C2 infrastructure has expanded from a single commercial hosting provider to four distinct networks this cycle, with two new techniques deployed to evade commercial threat feeds:

ASNProviderUsage
213790Limited NetworkPrimary C2 hosting — 3 active IPs, financial and government targeting
34918Pishgaman ToseehSecondary C2 hosting
31549Aria ShatelCobalt Strike beacon staging (port 9090) — third Iranian ISP added this cycle
AcademicIROST (Iranian Research Organization for Science & Technology)Remcos RAT C2 on port 43155 — new academic infrastructure diversification

The shift to Iranian academic infrastructure is a deliberate evasion tactic: commercial threat feeds are primarily keyed to known VPS providers and Iranian ISP ASNs. Academic network traffic is routinely permitted through enterprise firewalls. IP/ASN-based blocking alone now produces an increasingly incomplete picture — behavioral C2 detection is essential.

T1071.001T1219T1105

Eight ICS/SCADA advisories from CISA published this cycle cover Siemens RUGGEDCOM APE1808 and Rockwell Automation products. The most critical: a Rockwell Studio 5000 Logix Designer advisory (ICSA-26-202-10) allowing arbitrary file execution and configuration alteration on PLCs — directly aligning with Cyber Av3ngers' documented capability set and operational interests in water and energy infrastructure.

Also of note: Rockwell 1734 POINT I/O and 1718/1719-AENTR modules with denial-of-service vulnerabilities; and Siemens SIDIS Secured SmartPlug with OpenSSL/OpenSSH vulnerabilities in industrial firewall contexts. Cyber Av3ngers' demonstrated history of PLC manipulation (Unitronics, Rockwell targets in prior cycles) makes these high-priority patches for OT defenders, particularly in energy and water utilities.

T1495T1499

The MuddyWater/Dalbit crossover — with Dalbit linked to North Korean Silent Chollima — represents a potentially significant development in Iranian cyber operations. Whether this reflects shared tooling marketplaces (where Iranian and DPRK actors independently acquire similar capabilities) or deliberate operational partnerships, the practical consequence is the same: ransomware deployed against organizations in the threat aperture may simultaneously serve Iranian espionage objectives and North Korean financial objectives.

Why it matters: standard ransomware response procedures assume a financially-motivated criminal adversary with no persistent access interest. If MuddyWater is the true operator using Dalbit tooling as cover, the incident scope extends to full espionage investigation protocols — network forensics, long-term access review, and breach notification obligations that a criminal ransomware incident would not trigger. This emerging model requires updated IR playbook assumptions for any affected sector.

ScenarioProbabilityTimeframeIndicators to Watch
Coordinated hacktivist operation breaks 26-day silence — Handala/Cyber Toufan targeting Israeli CI, U.S. utilities, or Gulf financial sector70%7 daysNew Handala/Banished Kitten Telegram channels; infrastructure overlap with known IOCs; DDoS traffic to Israeli or U.S. targets
CVE-2026-16232 weaponized by Iranian actors for SmartConsole initial access50%14 daysCheck Point incident reports; CISA KEV exploitation confirmation; Middle East government network compromise disclosures
ICS/OT disruption attempt against water or energy utility45%14 daysICS-CERT incident reports; Cyber Av3ngers claims; Rockwell PLC anomaly events in energy/water sectors
HOLLOWGRAPH M365 C2 technique deployed against Western (non-Israeli) targets40%21 daysAPT34 IOC overlap in Western enterprise tenants; Entra ID OAuth grant anomalies; Graph API call spike patterns
MuddyWater/DPRK partnership produces novel combined operation30%30 daysNew crossover malware samples; shared C2 infrastructure between Iranian and DPRK IOC sets; ransomware incidents with concurrent exfiltration indicators

RuleData SourceATT&CKPriority
SmartConsole management interface auth events from unexpected source IPs; admin token issuance or firewall rule modification outside change windows (CVE-2026-16232)Check Point logs / SIEMT1190CRITICAL
Outbound connections to 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (ASN 213790); 62.60.226[.]42 port 43155 (Remcos); 151.239.25[.]40 port 9090 (Cobalt Strike)Firewall / NetflowT1071.001CRITICAL
SHA-256 match on MuddyWater/Dalbit crossover hashes across endpoint telemetry (see IOC block below)EDRT1486HIGH
OAuth application grants with Mail.Read, Calendars.ReadWrite, or Files.Read.All permissions granted to unrecognized apps; Graph API call volume anomalies; calendar items created/read by service principalsEntra ID / Microsoft 365T1550.001HIGH
PowerShell execution chains preceding encryption activity; data staging (file archiving, large internal transfers) before encryption beginsEDR / SysmonT1059.001HIGH
Rockwell Studio 5000 Logix Designer project file modifications from non-engineering workstations; PLC configuration downloads outside scheduled maintenance windowsICS / OT logsT1495MEDIUM
Beaconing patterns to Iranian ASNs 213790, 34918, 31549 — detect via JA3/JA4 Cobalt Strike and Remcos fingerprinting rather than IP-only blockingFirewall / NDRT1071.001MEDIUM
IOC Blocking Table:
185.93.89[.]7577.90.185[.]118185.93.89[.]4362.60.226[.]42:43155151.239.25[.]40:9090

ASN 213790 cluster (Limited Network) — C2, financial and government targeting, HIGH confidence. Remcos RAT C2 on Iranian academic infrastructure (IROST), port 43155, HIGH confidence. Cobalt Strike beacon staging on Aria Shatel (ASN 31549), port 9090. MuddyWater/Dalbit crossover hashes: cd11e8baec2f5254a2ce9f236b5091968b950c172e6fdce25b140347b7d787ac (defense/healthcare/retail), e977e8d48c8725dec2dde597eb4faca321bafd4faf3932dca5f07f09e847b705 (defense/manufacturing), 1ca62a560ee6885b9c9187ade5c8933ec28a52323ffbc39f8e2ba9c9fb151247 (commercial/construction). Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Network appliance compromise via CVE-2026-16232
Are any Check Point SmartConsole Management Servers accessible from the internet? Review SmartConsole API access logs for authentication from unexpected source IPs, new admin tokens issued, and firewall rule modifications in the last 72 hours. Cross-reference with Pioneer Kitten IOC sets.
HUNT 02 · T1071.001
C2 communications to Iranian infrastructure
Are any internal hosts communicating with ASN 213790 (Limited Network), 34918 (Pishgaman Toseeh), or 31549 (Aria Shatel) infrastructure? Deploy JA3/JA4 fingerprinting for Cobalt Strike BEACON and Remcos signatures — do not rely on IP-only blocking given confirmed infrastructure diversification to academic networks.
HUNT 03 · T1486
Ransomware-as-cover espionage (MuddyWater/Dalbit)
Are the three MuddyWater/Dalbit SHA-256 hashes present in any endpoint telemetry? If ransomware has deployed — was data staged or exfiltrated before encryption began? PowerShell execution chains (T1059.001) on non-developer workstations in targeted sectors are a strong pre-indicator.
HUNT 04 · T1550.001
M365/OAuth abuse — HOLLOWGRAPH pattern
Are there OAuth application grants in Entra ID with Mail.Read, Calendars.ReadWrite, or Files.Read.All permissions granted to applications not recognized by IT? Monitor Graph API call volumes for anomalous spikes. Key indicator: calendar items being created or read by service principals rather than user accounts.
HUNT 05 · T1495
ICS/OT lateral movement toward Rockwell PLCs
Are Rockwell Studio 5000 Logix Designer project files being modified from non-engineering workstations? Validate firmware integrity on 1734 POINT I/O and 1718/1719-AENTR modules. Confirm no network path exists from internet-facing systems (SmartConsole, VPN) to OT/ICS networks.

Financial Services
Banking Infrastructure, Gulf Financial Sector
Primary threats
ASN 213790 IPs (185.93.89[.]75, 77.90.185[.]118) explicitly tagged for financial sector targeting; Gulf state financial institutions assessed as likely hacktivist retaliation targets; Check Point SmartConsole exposure in payment processing environments
Secondary threat
Credential harvesting phishing campaigns tagged on all ASN 213790 IPs — financial sector employees a high-value targeting cohort
Actions
  • Validate DDoS mitigation capacity for sustained volumetric attacks — Cyber Av3ngers' preferred hacktivist tactic targeting financial sector
  • Audit SWIFT/payment system network segmentation — ensure no path from internet-facing systems to transaction infrastructure
  • Monitor for credential harvesting campaigns (T1566 phishing tags on all ASN 213790 IPs) targeting financial sector employees
  • Emergency review of Check Point firewall exposure in payment processing environments; apply SK185169 hotfix within 24 hours
Energy
Grid, PLCs, OT Networks
Primary threats
Rockwell Studio 5000 Logix Designer arbitrary file execution and PLC configuration alteration (ICSA-26-202-10) combined with Cyber Av3ngers' documented PLC manipulation capabilities; eight new ICS advisories expanding OT attack surface
Secondary threat
Siemens RUGGEDCOM APE1808 PAN-OS vulnerabilities in industrial firewall contexts; access-to-destruction pipeline if Pioneer Kitten initial access reaches OT-adjacent networks
Actions
  • Prioritize patching Rockwell Studio 5000 Logix Designer (ICSA-26-202-10) — highest-severity OT advisory this cycle
  • Validate IT/OT air-gap integrity; audit jump hosts and data diodes for misconfiguration enabling lateral movement
  • Deploy integrity monitoring on PLC project files — alert on any modification outside scheduled maintenance windows
  • Conduct tabletop exercise: "Adversary gains SmartConsole admin access and opens firewall rules to OT network"
Healthcare
Patient Systems, Medical Devices
Primary threats
MuddyWater/Dalbit crossover sample cd11e8baec2f5254a2ce9f236b5091968b950c172e6fdce25b140347b7d787ac explicitly targets healthcare; ASN 213790 IP 77.90.185[.]118 also tagged for healthcare; ransomware-as-cover model means initial response may miss underlying espionage
Secondary threat
Rockwell 1734 POINT I/O DoS vulnerabilities may affect connected medical devices in networked healthcare environments
Actions
  • Hunt for the three MuddyWater/Dalbit SHA-256 hashes across all endpoint telemetry immediately
  • Ensure backup isolation — if ransomware deploys, assume exfiltration has already occurred and initiate breach notification assessment in parallel with recovery
  • Monitor for PowerShell execution chains (T1059.001) on clinical workstations — anomalous in healthcare and a strong pre-indicator
  • Audit medical device network segmentation for Rockwell DoS vulnerability exposure
Government
Middle East & Allied Nations
Primary threats
CVE-2026-16232 (Check Point SmartConsole) — government networks in the Middle East and allied nations heavily deploy Check Point; Pioneer Kitten access-broker model means initial compromise will be handed off to destructive operators; HOLLOWGRAPH M365 C2 expanding beyond Israeli targets
Secondary threat
MuddyWater/Dalbit espionage-as-ransomware targeting government procurement and administrative systems
Actions
  • Emergency priority: verify all Check Point SmartConsole Management Servers are not internet-accessible; apply hotfix SK185169 within 24 hours
  • Audit all Check Point admin accounts for unauthorized additions or token issuance in the past 30 days
  • Audit Entra ID for OAuth grants with Mail.Read or Calendar permissions — HOLLOWGRAPH uses calendar API for covert C2
  • Monitor for access-to-destruction handoff: network appliance compromise → lateral movement → destructive payload (weeks to months between stages)
Aviation / Logistics
Supply Chain, Industrial Automation
Primary threats
MuddyWater/Dalbit crossover e977e8d48c8725dec2dde597eb4faca321bafd4faf3932dca5f07f09e847b705 targets manufacturing; Siemens SIDIS Secured SmartPlug vulnerabilities in airport/logistics industrial firewall contexts; Rockwell 1718/1719-AENTR DoS in logistics automation environments
Secondary threat
Cobalt Strike beacon staging (port 9090) from OT segments; supply chain and PLM system espionage consistent with Iranian DIB targeting priorities
Actions
  • Audit PTC Windchill and PLM systems for unauthorized access — Iranian DIB espionage priority
  • Review Siemens SIDIS Secured SmartPlug deployments in airport and logistics infrastructure for OpenSSL/OpenSSH vulnerabilities
  • Monitor for Cobalt Strike beacon traffic (port 9090 staging pattern) from operational technology segments
  • Validate cargo handling and baggage system PLCs are not accessible from corporate IT networks
No sector cards match the selected filters.

Emergency: Verify Check Point SmartConsole Management Servers are NOT internet-accessible. Apply hotfix per SK185169 within 24 hours. CVE-2026-16232 (CVSS 9.1) is actively exploited and grants unauthenticated admin access to firewall policy management — fits Pioneer Kitten's documented network appliance playbook exactly.
Incident ResponderSOC Analyst
Block at perimeter and add to SIEM watchlist: 62.60.226[.]42:43155 (Remcos C2), 151.239.25[.]40:9090 (Cobalt Strike), 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (ASN 213790 C2 cluster). Hunt historical connections in 90-day netflow.
SOC Analyst
Deploy the three MuddyWater/Dalbit SHA-256 hashes to EDR block/alert policies across all endpoints: cd11e8baec2f5254... (defense/healthcare/retail), e977e8d48c8725de... (defense/manufacturing), 1ca62a560ee6885b... (commercial/construction).
SOC Analyst
Elevate organizational threat posture to CRITICAL. Ensure incident response retainers are active and IR playbooks for destructive/wiper attacks are current. Confirm offline backups are verified and restorable.
CISO / Exec
No immediate actions for the selected roles.
Hunt across endpoint telemetry for the three MuddyWater/Dalbit SHA-256 hashes. Presence indicates active compromise with espionage and destructive potential — treat as confirmed breach and initiate full IR, not ransomware-only response.
Threat Hunter
Audit and patch all Rockwell Studio 5000 Logix Designer installations (ICSA-26-202-10). Arbitrary file execution and PLC configuration alteration directly enables Cyber Av3ngers' operational playbook against energy and water infrastructure.
ICS / OT
Commission M365/Entra ID audit for anomalous OAuth application grants — focus on Mail.Read, Calendars.ReadWrite, and Files.Read.All permissions. HOLLOWGRAPH uses calendar API for covert C2 communication; Graph API call volume spikes are a detection proxy.
IAM AnalystSOC Analyst
Audit all network security appliances (Fortinet, Ivanti, Citrix, Check Point) for indicators of prior compromise. Pioneer Kitten may be operating through pre-established access rather than new exploitation — absence of new IOC activity is not absence of threat.
Incident Responder
Implement behavioral detection for C2 beaconing to Iranian ASNs (213790, 34918, 31549) using JA3/JA4 fingerprinting rather than IP-only blocking. Infrastructure diversification to academic networks (IROST) means IP/ASN rules now produce an incomplete picture.
Threat HunterSOC Analyst
No 7-day actions for the selected roles.
Develop contingency plan for "firewall policy manipulation" attack scenario: adversary with SmartConsole admin access silently opens rules enabling lateral movement to OT/critical systems. This is not hypothetical — it is consistent with Pioneer Kitten's handoff to destructive operators.
CISO / Exec
Commission threat hunt for dormant Pioneer Kitten access across the full network appliance fleet (Fortinet, Ivanti, Citrix, Check Point). Absence of new IOCs may indicate operation through pre-established footholds rather than new exploitation activity.
CISO / ExecThreat Hunter
Implement ASN-agnostic behavioral C2 detection. Iranian infrastructure is now confirmed across four+ provider types including academic networks — IP and ASN-based blocking alone is no longer a sufficient detection posture.
SOC Analyst
Conduct board-level tabletop exercise for coordinated Iranian cyber retaliation scenario: simultaneous DDoS, wiper deployment, ICS manipulation, and data leak operations across multiple business units — the historical Iranian multi-domain coordination model.
CISO / Exec
Evaluate whether MuddyWater/DPRK operational partnership model requires updated threat modeling. Ransomware incidents in affected sectors should now trigger espionage investigation protocols — standard criminal ransomware response procedures are insufficient if MuddyWater is the true operator.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
Bottom Line

We are watching an adversary prepare. The 26-day hacktivist silence is not inactivity — it is discipline. The C2 infrastructure refresh across four Iranian ASNs is not routine maintenance — it is staging. The malware updates targeting your sector specifically are not academic exercises — they are targeting your sector specifically. The Iranian cyber apparatus has historically used periods of apparent quiet to pre-position for coordinated operations combining destructive attacks, espionage, ICS disruption, and information operations simultaneously. Every structural indicator suggests we are in that pre-positioning window now. The window for defensive preparation is measured in days, not weeks.

1
Is your Check Point SmartConsole Management Server internet-accessible? If you don't know the answer in the next hour, assume yes and act accordingly. Apply SK185169 today.
2
Have you blocked the five IOCs and deployed the three MuddyWater/Dalbit hashes to EDR? These are the minimum. Do not wait for the silence to break.
3
Do you have a wiper response plan? The groups responsible for the most destructive Iranian attacks in this conflict cycle are quiet. That should concern you far more than if they were loud.
No items found.