| Date | Development | Significance |
|---|---|---|
| Jul 20 | HOLLOWGRAPH implant disclosed — Group-IB publishes research on M365 calendar C2 technique; 12 Israeli organisations compromised since Jun 3 | Novel living-off-cloud-services C2; invisible to traditional network monitoring |
| Jul 19 | 8th consecutive night of US strikes against IRGC targets | Active retaliation window now exceeds 96 hours |
| Jul 18 | Khamenei declares US-Iran MoU void; two US soldiers killed in Iranian strike (Jordan) | Political authorisation for retaliation; kinetic escalation trigger |
| Jul 17 | APT42, APT34, MuddyWater, UNC6496 actor profiles refreshed in threat feeds | Active tracking of new Iranian APT activity across four groups |
| Jul 16 | CVE-2026-25089 added to CISA KEV — FortiSandbox pre-auth OS command injection, CVSS 9.8 | Pioneer Kitten-aligned surface; Day 4 post-listing, historical exploitation within 24–72h |
| Jul 16 | Nine simultaneous CISA ICS advisories: Rockwell (×5), Siemens SICAM 8, SALTO, AutomationDirect, NASA cFS | Expanded OT attack surface coinciding with Cyber Av3ngers' operational silence |
| Jul 11–12 | ASN 213790 ("Limited Network," Tehran) C2 IPs refreshed — confidence 91–97%, Cactus/IcedID tagged | State-criminal crossover C2 infrastructure confirmed active during retaliation window |
| Jul 7 | POWERSTATS malware sample compiled — MuddyWater/TEMP.Zagros campaign preparation | MOIS-affiliated actor preparing backdoor deployment |
| Ongoing | Handala and Cyber Av3ngers maintain anomalous silence — no DDoS, defacement, or wiper activity | 96h+ silence during active strikes; historical pattern consistent with pre-operational pause |
| Ongoing | Rampant Kitten infrastructure (ASN 42337, 5.160.228[.]186) activated | MOIS domestic surveillance apparatus activating; historical pivot to external BDA collection |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before Feb 28, 2026 | Baseline Iranian espionage operations — APT42, APT34, Pioneer Kitten, MuddyWater active across global targets |
| Conflict onset | Feb 28, 2026 | US-Iran hostilities begin; cyber operations tempo begins escalating across all Iranian state and proxy actors |
| Clandestine implantation | Jun 3 – Jul 19, 2026 | HOLLOWGRAPH campaign begins against Israeli targets via M365 calendar C2; 12 organisations compromised silently over 47 days |
| Infrastructure activation | Jul 7–12, 2026 | POWERSTATS malware compiled (Jul 7); ASN 213790 C2 IPs refreshed (Jul 11–12); Rampant Kitten infrastructure (ASN 42337) activated |
| Vulnerability window opens | Jul 16, 2026 | CVE-2026-25089 added to CISA KEV; nine simultaneous ICS advisories across Rockwell, Siemens, SALTO, AutomationDirect, NASA cFS |
| Active retaliation window | Jul 18–19, 2026 | US soldiers killed in Jordan; Khamenei declares MoU void; 8th consecutive night of US strikes on IRGC; proxy forces maintain anomalous silence |
| Current (Day 142) | Jul 20, 2026 | HOLLOWGRAPH tradecraft exposed; CVE-2026-25089 exploitation window at Day 4; hacktivist proxies silent 96h+; ICS attack surface expanded |
HOLLOWGRAPH represents the first documented case of an Iranian-nexus actor using Microsoft 365 calendar events as a bidirectional command-and-control channel. Operators create calendar events with encoded instructions in the subject line — using patterns such as Event ID: or Boss{..}ID{..} — dated 2050-05-13, far enough in the future that users never see them in their calendar view. Stolen data is encrypted with RSA + AES-256-GCM and attached to calendar events as File{n}.txt. DNS tunneling via cloudlanecdn[.]com refreshes Entra ID OAuth credentials, maintaining access even after token expiration. The on-disk configuration file masquerades as a legitimate Azure log: logAzure.txt.
Twelve Israeli organisations have been compromised since 3 June 2026. Attribution carries low confidence linkage to Lyceum (an OilRig/APT34 sub-cluster), with moderate confidence the operation is Iranian-nexus based on victimology and infrastructure patterns. Why this matters for your organisation: if your environment runs Microsoft 365, traditional network-based C2 detection is blind to this technique. The traffic is legitimate Graph API calls to Microsoft infrastructure. Only API-level audit logging will detect it.
CVE-2026-25089 is a pre-authentication OS command injection vulnerability in Fortinet FortiSandbox, rated CVSS 9.8. Affected versions span 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2.x versions, and Cloud/PaaS editions. It was added to the CISA Known Exploited Vulnerabilities catalogue on 16 July 2026 — and we are now at Day 4 post-listing. Pioneer Kitten, an IRGC-affiliated group, has a documented pattern of exploiting Fortinet vulnerabilities within 24–72 hours of KEV listing.
The irony is acute: FortiSandbox is a security tool. Compromising it gives attackers the ability to disable malware analysis, understand what an organisation can and cannot detect, and pivot deeper into the network from a trusted security appliance. Any organisation running a vulnerable version that has not yet patched must treat this as an active emergency — not a scheduled maintenance item.
Three IPs on Tehran-based ASN 213790 ("Limited Network") continue operating as confirmed APT command-and-control infrastructure, with confidence scores of 91–97%:
| IP | Confidence | Associated Malware | Target Sectors |
|---|---|---|---|
77.90.185[.]118 | 91% | Cactus, IcedID | Government, Healthcare, Technology |
185.93.89[.]43 | 97% | Cactus, IcedID | Healthcare, Manufacturing, Technology |
192.253.248[.]180 | 91% | Scanner, Phishing | Retail, Telecommunications |
The co-occurrence of Cactus ransomware and IcedID (a known initial-access-broker tool) on Iranian state infrastructure signals a blurring of state and criminal operations. A "ransomware" incident originating from this infrastructure may actually be state-sponsored espionage using ransomware as cover — or revenue generation funding further operations.
Iran's most destructive hacktivist proxies — Handala and Cyber Av3ngers — have been silent throughout the active retaliation window. Historical patterns show these groups typically launch DDoS, defacement, or wiper attacks within 24–48 hours of kinetic strikes against Iranian targets. We are now past 96 hours of silence during the 8th consecutive strike night.
This is not consistent with a decision not to retaliate. It is consistent with preparation for a larger, coordinated operation. The precedent: after the Soleimani assassination, Iranian cyber retaliation (Pay2Key campaign) lagged kinetic events by approximately 10 days. Cyber Av3ngers' current silence, combined with the expanded ICS attack surface from nine new advisories, creates a particularly high-risk window for OT-targeting operations.
Assessment: this is not cessation. It is preparation.
IP 5.160.228[.]186 on ASN 42337 (Respina Networks, Iran) has been confirmed active with ties to Rampant Kitten — an MOIS-linked group primarily known for domestic dissident surveillance using the TeleSpy mobile implant. During military escalation, MOIS surveillance actors historically pivot from internal dissident monitoring to external battle damage assessment (BDA) collection.
This activation should be monitored for crossover into external espionage operations. Rampant Kitten's existing tradecraft — mobile implant deployment, credential phishing, and covert communication interception — is directly transferable to external intelligence collection targeting diaspora communities, opposition figures, and government personnel with Iranian-origin connections.
Nine simultaneous CISA ICS advisories published on 16 July 2026 affect systems directly relevant to Iranian ICS targeting patterns — particularly Cyber Av3ngers' documented history of rapid post-advisory exploitation:
- Rockwell CompactLogix/ControlLogix/GuardLogix (ICSA-26-197-06) — Denial of service affecting water and energy sectors
- Siemens SICAM 8/A8000 (ICSA-26-197-05) — Multiple DoS vulnerabilities in grid protection systems
- SALTO ProAccess Space — Privilege escalation in physical access control systems
- Rockwell Arena — Arbitrary code execution
- Rockwell FactoryTalk DataMosaix — Script injection
- AutomationDirect, NASA cFS — Additional OT/aerospace system vulnerabilities
The combination of Cyber Av3ngers' anomalous silence and this expanded ICS attack surface is the highest-risk OT scenario since this conflict began. Cyber Av3ngers exploited newly disclosed ICS vulnerabilities within days of advisory publication in previous cycles.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Pioneer Kitten exploits CVE-2026-25089 against exposed FortiSandbox instances | 75% | 24–48 hours | FortiSandbox access log anomalies, unexpected outbound connections from appliances, threat feed C2 hits on IRGC infrastructure |
| Coordinated hacktivist wave (Handala / Cyber Av3ngers) breaks silence with DDoS or wiper operation | 50% | 48–96 hours | Telegram channel posts, DDoS alert spikes, Handala wiper IOC matches on endpoint telemetry |
| Cyber Av3ngers exploit newly disclosed Rockwell / Siemens ICS vulnerabilities | 40% | 7–21 days | ICS-CERT incident reports, anomalous CIP traffic to PLCs, Cyber Av3ngers Telegram claims |
| HOLLOWGRAPH campaign expands beyond 12 current victims to additional Israeli or Gulf targets | 45% | 7–14 days | New M365 API audit anomalies, Cavern framework IOC matches, additional Group-IB reporting |
| Dormant Iranian access in defence-industrial base networks activates for exfiltration | 35% | 7–14 days | Off-hours authentication spikes, anomalous data staging on PTC Windchill or engineering data repositories |
| HOLLOWGRAPH technique adopted by MuddyWater or APT42 for broader campaigns | 30% | 30–60 days | Similar M365 calendar C2 patterns attributed to different actor infrastructure; modular Cavern framework reuse |
| Rule | Data Source | ATT&CK | Priority |
|---|---|---|---|
CalendarEvent.Create operations in M365 Unified Audit Log initiated by applications (not interactive users) | M365 Unified Audit Log | T1102.002 | CRITICAL |
Calendar events with dates beyond 2030; subjects matching Event ID:.* or Boss\{.*\}ID\{.*\} | M365 Unified Audit Log | T1102.002 | CRITICAL |
DNS queries to cloudlanecdn[.]com or AAAA query rate > 50/hour to a single domain with subdomain entropy > 3.5 bits | DNS / Passive DNS | T1071.004 | CRITICAL |
| Anomalous HTTP requests to FortiSandbox management interface — crafted payloads indicative of OS command injection (CVE-2026-25089) | WAF / FortiSandbox logs | T1190 | CRITICAL |
| Unexpected outbound connections from FortiSandbox appliances to non-Fortinet IP space | Firewall / Netflow | T1059.004 | HIGH |
| OAuth client credential grants from service principals absent from approved application inventory | Entra ID / Azure AD | T1528 | HIGH |
Any traffic to/from 77.90.185[.]118, 185.93.89[.]43, 192.253.248[.]180, 5.160.228[.]186 | Firewall / Netflow | T1071.001 | HIGH |
Creation of logAzure.txt in non-standard directories on Windows endpoints | EDR / Sysmon | T1036 | HIGH |
| Changes to FortiSandbox analysis policies or scan exclusions not initiated by authorised administrators | FortiSandbox audit logs | T1562.001 | MEDIUM |
| Anomalous CIP (Common Industrial Protocol) traffic to Rockwell CompactLogix/ControlLogix/GuardLogix controllers | ICS network monitoring | T1499 | MEDIUM |
| Unexpected firmware update attempts or configuration changes on Siemens SICAM 8 devices | OT asset monitoring | T0816 | MEDIUM |
IPv4s: 77.90.185[.]118 and 185.93.89[.]43 on ASN 213790 — Iranian APT C2, Cactus/IcedID, confidence 91–97%. 192.253.248[.]180 (ASN 213790) — scanner/phishing infrastructure. 5.160.228[.]186 (ASN 42337 / Respina Networks) — Rampant Kitten surveillance infrastructure. Domain: cloudlanecdn[.]com — HOLLOWGRAPH DNS tunneling C2 for Entra ID credential refresh. File artifact: logAzure.txt — HOLLOWGRAPH on-disk credential configuration, non-standard directory placement. CVE: CVE-2026-25089 — FortiSandbox pre-auth RCE, CVSS 9.8, CISA KEV confirmed. Additional IOCs available via Anomali ThreatStream and partner feeds.
CalendarEvent.Create operations triggered by application credentials rather than interactive user sessions. Filter for calendar events dated beyond 2030 and for subject lines matching Event ID:.* or Boss{..}ID{..} patterns. Any application-initiated calendar creation outside your approved application inventory is a high-fidelity indicator.Calendars.ReadWrite and Files.ReadWrite permissions that were not provisioned through your standard IAM workflow.cloudlanecdn[.]com or its subdomains. Additionally, build a detection for AAAA query volume anomalies: any single domain receiving more than 50 AAAA queries per hour with high subdomain entropy (> 3.5 bits) warrants immediate investigation as a DNS tunneling indicator.- Immediate: Audit all OAuth application registrations in Entra ID; revoke any client secrets created in the last 90 days that cannot be attributed to known development teams
- 7-Day: Implement Conditional Access policies requiring admin consent for all new OAuth application grants; deploy Microsoft Defender for Cloud Apps anomalous token detection
- Monitor for IcedID delivery attempts via malicious Office documents or HTML smuggling — confirmed on Iranian APT infrastructure and serves as Cactus ransomware initial access vector
- Immediate: Validate that Rockwell CompactLogix/ControlLogix/GuardLogix controllers (ICSA-26-197-06) and Siemens SICAM 8 grid protection systems (ICSA-26-197-05) are not reachable from IT networks
- 7-Day: Apply firmware patches to affected Rockwell and Siemens devices in maintenance windows; deploy CIP protocol monitoring for anomalous command sequences
- 30-Day: Conduct tabletop exercise simulating Cyber Av3ngers-style ICS disruption during kinetic escalation; test communication between OT security teams and corporate SOC
- Immediate: Block
185.93.89[.]43and77.90.185[.]118— both carry explicit healthcare targeting tags; verify backup integrity and test restoration procedures for critical clinical systems - 7-Day: Hunt for IcedID indicators across the environment; review all VPN authentication logs for connections from Iranian IP ranges since 28 February 2026
- 30-Day: Segment clinical systems from administrative networks; ensure medical device networks cannot reach internet-facing infrastructure directly
- Immediate: Enable Graph API audit logging across all M365 Government Cloud tenants; hunt for calendar events dated 2050-05-13,
logAzure.txtfile artifacts, and DNS queries tocloudlanecdn[.]com - 7-Day: Emergency vulnerability scan for FortiSandbox instances — any version prior to 5.0.6 or 4.4.9 is vulnerable to CVE-2026-25089; government agencies are primary Pioneer Kitten targets
- 30-Day: Review all Entra ID service principal permissions; implement zero-trust for application-to-application authentication; commission red team assessment targeting Graph API abuse paths
- Immediate: Alert recruiting and HR teams to DPRK/Iranian fake-job interview TTPs — TA455 uses fake aerospace postings to deliver malware; verify all recent contractor onboarding for anomalous patterns
- 7-Day: Audit PTC Windchill access logs for dormant accounts that have authenticated during the current conflict period (since 28 February 2026); review GitHub repository access for aerospace/logistics codebases
- 30-Day: Implement enhanced monitoring for data exfiltration from engineering systems; deploy DLP rules for CAD files, technical specifications, and logistics routing data leaving via unusual channels
Event ID: or Boss{..}ID{..} patterns, and application-initiated CalendarEvent.Create operations.cloudlanecdn[.]com at all recursive resolvers. Monitor for high-entropy subdomain AAAA queries (> 50/hour to a single domain, entropy > 3.5 bits) indicating active DNS tunneling.77.90.185[.]118, 185.93.89[.]43, 192.253.248[.]180, 5.160.228[.]186. Even failed connection attempts indicate a possible compromise reaching out to C2.logAzure.txt creation in non-standard directories and on anomalous OAuth client credential grants from service principals not in your approved application inventory.