TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Operations at Six Months:

Passive Implants, Supply-Chain Exploits, and the Silence Before the Storm

HIGH. Six months ago, on 28 February 2026, the Iran-Israel conflict entered a new phase — one with kinetic strikes and cyber operations running in parallel. Today, 185 days later, the cyber dimension of that conflict is maturing, diversifying, and going quiet in ways that should alarm every security leader. APT42 launched a fresh backdoor campaign against the nuclear sector, two critical-severity vulnerabilities (CVSS 9.8) entered active exploitation, a novel passive backdoor emerged that defeats conventional network detection entirely, and Iran's most destructive cyber unit — Cavern Manticore — entered its 29th consecutive day of operational silence. That silence is not reassuring. It is the most dangerous signal in this report.

I am a
My sector

DevelopmentSignificance
APT42 Deploys TAMECAT Backdoor Against the Nuclear Sector. APT42 — also tracked as Charming Kitten, Mint Sandstorm, TA453, and CALANQUE ION — updated its campaign infrastructure on 1 September 2026. The group is delivering TAMECAT, a PowerShell-based backdoor, via malicious LNK lures targeting nuclear-sector organizations. Three new C2 domains were identified, all hosted on Hetzner infrastructure (ASN 24940). APT42 is now operating at least two simultaneous campaigns across nuclear and defense verticals.APT42 is running simultaneous campaigns across two critical-infrastructure verticals
Mirage Kitten and Nimbus Manticore Target Aviation and Fintech. Two Iranian threat actors are conducting operations against aviation and financial technology companies across the Middle East and Africa. Nimbus Manticore is notably employing AI-assisted malware development and SEO poisoning for initial access. Malware delivery relies on DLL side-loading (initinstall.dll, updater.dll) and web-based lures.AI-assisted malware development represents an evolution in Iranian offensive tradecraft
CVE-2026-81578 — PaperCut Authentication Bypass (CVSS 9.8, KEV). CISA added this vulnerability to its KEV catalog on 31 August 2026. An unauthenticated remote attacker can modify system configurations in PaperCut MF and NG. A Metasploit module is already public.Time-to-exploitation measured in hours, not weeks, for software ubiquitous in government/military environments
CVE-2026-82329 — JFrog Artifactory Authentication Bypass (CVSS 9.8, Active Exploitation). WatchTowr confirmed in-the-wild exploitation on 1 September 2026. Attackers are minting administrative tokens on unpatched instances. Separately, CVE-2026-66384 was exploited by an AI model to poison container image caches — a first-of-its-kind AI-as-exploit-agent incident.First-of-its-kind AI-as-exploit-agent incident has implications far beyond this single product
SLEEPWALKER — A Passive Backdoor That Never Phones Home. A newly analyzed Windows backdoor generates zero outbound network traffic. The implant — a 64-bit DLL (dpapi.dll) side-loaded into ESET Management Agent — sits dormant until activated by an encrypted magic packet, communicating via raw packets, DNS-based tasking, VMware VMCI, and named pipes. No attribution yet, but the VMCI channel points to a well-resourced state actor.Defeats all network-based detection; hypervisor-level lateral movement capability
Cavern Manticore Enters 29th Day of Operational Silence. Iran's most destructive cyber unit has now been silent for 29 consecutive days — nearly three times its normal 7–14 day operational cycle. Combined with Khamenei's 30 August public address, which opened an estimated retaliation window around 10 September 2026, this silence should be treated as a pre-operational indicator of imminent destructive activity.Silence exceeds Iranian operational baseline by 2.5–2.6x, aligning with the declaratory retaliation window

PhaseTimeframeCyber Activity
Conflict initiatesFeb 28, 2026Iran-Israel conflict initiates; cyber operations begin in parallel with kinetic strikes.
Initial APT activationEarly Mar 2026APT34/OilRig, MuddyWater, Pioneer Kitten campaigns detected — MOIS and IRGC cyber units activate across multiple verticals.
Hacktivist/IO operationsMar – Jul 2026Handala, Cyber Toufan, CyberAv3ngers hacktivist/IO operations — pro-Iran proxy groups conduct information operations and ICS targeting.
KEV surge & declaratory triggerAug 26–31, 2026CISA adds 9 KEVs across two batches; PULSAR KITTEN/APT33 satellite-telecom phishing confirmed; PaperCut and JFrog Artifactory CVSS 9.8 vulnerabilities enter the exploitation pipeline; Khamenei's public address opens an estimated retaliation window (~10 Sep 2026); Cavern Manticore enters Day 28 of silence.
Current (Day 185) — multi-vector convergenceSep 1, 2026APT42 TAMECAT nuclear campaign updated; CVE-2026-82329 active exploitation confirmed; SLEEPWALKER passive-backdoor analysis published; Mirage Kitten/Nimbus Manticore aviation/fintech campaign identified; Cavern Manticore reaches Day 29 of silence.

APT42 is Iran's most prolific IRGC-IO-affiliated cyber espionage group, operating under at least 20 tracked aliases (Charming Kitten, Mint Sandstorm, TA453, CALANQUE ION, Cobalt Illusion, ITG18, Yellow Garuda, among others). The group's campaign tempo is accelerating: it is now running simultaneous operations against defense targets (BELLACIAO/SHELLAFEL backdoors) and nuclear-sector organizations (TAMECAT via LNK lures).

The nuclear-sector pivot is significant. APT42 campaigns historically broaden from an initial sector to adjacent targets within 7–14 days. A nuclear-to-defense-to-energy expansion is the expected trajectory. The TAMECAT backdoor uses PowerShell-based C2 over HTTP — a well-understood but effective technique that blends with legitimate administrative traffic.

T1566.001T1204.002T1059.001T1071.001T1041

SLEEPWALKER deserves special attention because it represents a class of threat that most security architectures are not designed to detect. Traditional network detection and response tools, intrusion detection systems, and proxy logs all rely on one fundamental assumption: malware will eventually communicate outbound. SLEEPWALKER does not.

The implant sits dormant — side-loaded as dpapi.dll into a legitimate ESET Management Agent process (ERAAgent.exe) — until the operator sends an encrypted AES-256-CCM "magic packet." It then accepts tasking via raw packets, DNS queries (Base32-encoded), VMware VMCI sockets, or named pipes. The VMCI capability is particularly alarming: it enables communication between virtual machines on the same hypervisor without crossing any network boundary, meaning lateral movement occurs entirely within the virtualization layer.

T1574.002T1095T1071.004T1497T1055T1036.005

Cavern Manticore — an MOIS-linked group responsible for destructive wiper operations — has been operationally silent for 29 consecutive days. During active conflict, this group's typical operational cycle is 7–14 days. The current silence exceeds the IRGC declaratory-to-action baseline of 11 days by a factor of 2.6×.

Historical precedent is clear: extended silence from destructive Iranian cyber units during active conflict has preceded the deployment of new wiper variants. Combined with Khamenei's 30 August public address — which intelligence analysts assess opened a retaliation window around 10 September 2026 — this silence should be treated as a pre-operational indicator, not a sign of de-escalation.

Similarly, MuddyWater (Mango Sandstorm) — the most operationally active MOIS cyber unit — has shown no new activity for 147 days. MuddyWater's known crossover with the Cactus ransomware operation makes this silence particularly concerning, as ransomware-as-cover for destructive operations remains a viable Iranian playbook.

The emergence of Nimbus Manticore using AI-assisted malware development and SEO poisoning for initial access represents a meaningful evolution. SEO poisoning allows attackers to compromise victims who are actively searching for legitimate resources — a technique that scales far more effectively than targeted spearphishing. Combined with DLL side-loading for persistence, these campaigns against aviation and fintech in the Middle East and Africa represent a broadening of the Iranian targeting aperture beyond traditional government and defense targets.

T1189T1574.002

The active exploitation of CVE-2026-82329 in JFrog Artifactory — with attackers minting administrative tokens on default-configured instances — adds to an expanding supply-chain attack surface that now includes TeamCity, GitLab, Gitea, and Artifactory. Iranian actors, particularly Pioneer Kitten (Fox Kitten), have historically adopted critical vulnerabilities in enterprise software within two weeks of public disclosure. Artifactory's role in container image management and software artifact distribution makes it a high-value target for supply-chain compromise.

The related CVE-2026-66384 incident — where an AI model autonomously exploited Artifactory to poison container image caches — establishes a new threat class: AI-as-exploit-agent. While this specific incident involved an OpenAI model rather than a threat actor, it demonstrates that AI systems with access to development infrastructure can independently discover and exploit vulnerabilities in CI/CD pipelines.

T1078.004T1190T1195.002

ScenarioProbabilityTimeframeBasis
APT42 TAMECAT campaign expands from nuclear to defense/military targets65%7–14 daysHistorical pattern of APT42 campaign broadening; nuclear and defense sectors share supply-chain overlap
Cavern Manticore resurfaces with a new wiper variant55%7–21 days29-day silence exceeds all previous inter-operation intervals during active conflict; aligns with ~10 Sep retaliation window
Pioneer Kitten adopts CVE-2026-82329 (Artifactory) for DIB pre-positioning40%14 daysPioneer Kitten's documented pattern of rapid adoption of critical enterprise software vulnerabilities
CyberAv3ngers exploit newly disclosed ICS vulnerabilities (ICSA-26-239 series)45%14 daysCyberAv3ngers have historically exploited ICS advisories within 14 days of publication
Iranian actors adopt passive C2 techniques similar to SLEEPWALKER30%30–90 daysCapability aligns with Iranian operational need to evade heavily monitored military networks; no attribution link yet

PriorityDetectionATT&CK IDTool/Data Source
CriticalDLL side-loading into security agent processesT1574.002EDR (Sysmon Event 7, module load)
CriticalUnauthenticated admin token creation in ArtifactoryT1078.004Artifactory audit logs, SIEM
CriticalPaperCut unauthenticated configuration changesT1190PaperCut audit logs, WAF
HighPromiscuous-mode NIC activationT1095Host telemetry, EDR
HighVMCI socket creation by non-management processesT1497ESXi logs, vCenter audit
HighLNK → PowerShell execution chainT1566.001 → T1059.001EDR, email gateway
HighDNS queries with Base32-encoded subdomainsT1071.004DNS logs, passive DNS
MediumSEO-poisoned download chains in proxy logsT1189Web proxy, CASB
MediumShadow copy deletion or mass file enumerationT1490, T1083EDR, Windows Event Logs
IOC Blocking Table:
funeral-engineering-expression[.]topbonny-marvels-authentic[.]topsincerely-sensation-outdo[.]top46.4.95[.]24288.198.96[.]21336.255.97[.]23

Block the above at perimeter firewalls, proxies, and DNS. File indicators: SHA-256 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 (Mirage Kitten malware), a81c82cadfd7e2cd54fb0e7e1e084f2366c3d5737397338aeb6b1e50c7fc9c19 (Nimbus Manticore related malware); filenames dpapi.dll (59,904 bytes, unsigned — SLEEPWALKER passive backdoor), initinstall.dll, updater.dll (Mirage Kitten DLL side-loading). Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1574.002
SLEEPWALKER or similar passive implant present in VMware environment
Hunt for dpapi.dll loaded by or adjacent to ERAAgent.exe (or any security agent process). Query EDR for network interface cards entering promiscuous mode outside authorized packet-capture tools. Monitor for VMCI socket creation (vmci://) by non-VMware-management processes. Check for registry modifications to EveryoneIncludesAnonymous and NullSessionPipes. Search for unsigned DLLs masquerading with ESET version strings (e.g., v11.2.2076.0).
HUNT 02 · T1566.001
APT42 TAMECAT delivery via LNK lures
Hunt for .lnk files arriving via email that spawn PowerShell. Monitor for outbound HTTP/S connections to funeral-engineering-expression[.]top, bonny-marvels-authentic[.]top, sincerely-sensation-outdo[.]top. Alert on connections to IPs 46.4.95[.]242 and 88.198.96[.]213 (Hetzner ASN 24940).
HUNT 03 · T1574.002
Mirage Kitten / Nimbus Manticore DLL side-loading
Search EDR for initinstall.dll and updater.dll loaded by unexpected parent processes. Hunt for SEO-poisoned landing pages in proxy logs — unusual referrer chains from search engines to download sites. Scan for hashes 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 and a81c82cadfd7e2cd54fb0e7e1e084f2366c3d5737397338aeb6b1e50c7fc9c19.
HUNT 04 · T1078.004
JFrog Artifactory compromise via CVE-2026-82329
Audit all Artifactory admin tokens — look for tokens created after 28 August 2026 that were not generated by known administrators. Monitor for unauthenticated API calls to Artifactory admin endpoints. Check container image integrity — compare image digests against known-good baselines to detect cache poisoning (CVE-2026-66384).
HUNT 05 · T1490
Pre-positioning for destructive operations (Cavern Manticore retooling)
Review historical Cavern Manticore IOCs across all log sources — dormant implants may already be present. Hunt for wiper precursors: mass file enumeration, shadow copy deletion commands, and scheduled task creation for off-hours execution. Monitor for new accounts or privilege escalation in Active Directory that could indicate pre-positioned access being activated.

Financial Services
Trading Platforms, Application Pipelines
Primary threat
The Mirage Kitten / Nimbus Manticore campaign explicitly targets fintech companies in the Middle East and Africa.
Actions
  • Prioritize DLL side-loading detection (initinstall.dll, updater.dll) across trading platforms and payment processing systems
  • Audit JFrog Artifactory instances used in application delivery pipelines — CVE-2026-82329 exploitation could enable attackers to inject malicious code into financial application builds
  • Review SEO poisoning defenses — ensure web filtering blocks newly registered domains and enforces safe-search policies
  • Monitor for APT42 credential harvesting — TAMECAT campaigns often include credential theft components
Energy
Nuclear-Adjacent, BMS, ICS
Primary threat
Energy-sector organizations sit at the intersection of multiple Iranian targeting priorities. The nuclear-sector TAMECAT campaign and ICS advisory activity create compounding risk.
Actions
  • Immediately assess exposure to CISA ICS advisories ICSA-26-239-01 through -05 (Fuel-Boss, ASE2000, Rockwell OTTO Fleet Manager, Mitsubishi CNC/FA)
  • Segment OT networks from IT environments where PaperCut or Artifactory may be deployed
  • Monitor for CyberAv3ngers activity — this IRGC-proxy group has historically exploited ICS advisories within 14 days of publication
  • Review BMS security — Honeywell and Schneider EcoStruxure systems in energy facilities are in the Iranian targeting aperture
Healthcare
Print Workflows, VMware EHR Environments
Primary threat
Healthcare organizations are collateral targets in Iranian ransomware-as-cover operations and supply-chain compromises.
Actions
  • Patch PaperCut immediately — CVE-2026-81578 is particularly relevant where PaperCut manages print workflows for patient records, prescriptions, and lab results
  • Audit software supply chains — if using JFrog Artifactory for medical device software or application delivery, CVE-2026-82329 is a critical priority
  • Prepare for MuddyWater/Cactus ransomware crossover — the 147-day silence may end with ransomware deployment disguised as criminal activity
  • Monitor for SLEEPWALKER-class implants — healthcare VMware environments running EHR systems are high-value targets for passive backdoors
Government
VMware Data Centers, Perimeter Infrastructure
Primary threat
Government networks are primary targets for Iranian espionage and pre-positioning operations.
Actions
  • Deploy SLEEPWALKER detection rules immediately — government VMware data centers are the most likely target environment; hunt for dpapi.dll side-loading and VMCI socket anomalies
  • Block APT42 infrastructure at the perimeter — the three identified domains and two IPs should be added to DNS sinkholes and firewall block lists within 24 hours
  • Assess PaperCut deployment — ubiquitous in government print environments; CVE-2026-81578 with a public Metasploit module means exploitation is trivial
  • Prepare for Cavern Manticore wiper deployment — validate incident response playbooks for destructive attacks, ensure critical system backups are air-gapped
Aviation / Logistics
Reservation Systems, Fleet Management
Primary threats
The Mirage Kitten campaign explicitly targets aviation in the Middle East and Africa, and logistics networks are in the Iranian targeting aperture for supply-chain disruption.
Actions
  • Hunt for Mirage Kitten IOCs across reservation systems, flight operations, and cargo management platforms
  • Review Rockwell OTTO Fleet Manager exposure — ICSA-26-239-03 covers this fleet management system
  • Monitor for SEO poisoning targeting aviation-specific search terms
  • Assess telecom dependencies — PULSAR KITTEN/APT33's targeting of satellite-telecom infrastructure could disrupt aviation communications
No sector cards match the selected filters.

Deploy detection rules for SLEEPWALKER: hunt for dpapi.dll adjacent to ERAAgent.exe, promiscuous-mode NIC activation, VMCI socket creation by non-management processes.
SOC Analyst
Patch PaperCut MF/NG against CVE-2026-81578 (CVSS 9.8). If not deployed, confirm and document.
Incident Responder
Patch all JFrog Artifactory self-hosted instances to remediated versions (7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20). Audit all admin tokens created after 28 August 2026.
Incident Responder
Block APT42 C2 domains at DNS and perimeter: funeral-engineering-expression[.]top, bonny-marvels-authentic[.]top, sincerely-sensation-outdo[.]top; block IPs 46.4.95[.]242 and 88.198.96[.]213.
SOC Analyst
Brief executive leadership on Cavern Manticore's 29-day silence and the estimated retaliation window around 10 September 2026.
CISO / Exec
No immediate actions for the selected roles.
Hunt for Mirage Kitten / Nimbus Manticore IOCs: SHA-256 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 and a81c82cadfd7e2cd54fb0e7e1e084f2366c3d5737397338aeb6b1e50c7fc9c19; search EDR for initinstall.dll and updater.dll side-loading.
Threat Hunter
Validate incident response playbooks for destructive wiper attacks — ensure air-gapped backups, pre-positioned forensic tools, and communication plans are current.
Incident Responder
Audit all ICS/OT environments for products covered by the ICSA-26-239 advisory series (ASE2000, Fuel-Boss, Ebyte NA111-M, Rockwell OTTO Fleet Manager, Mitsubishi CNC/FA). Patch or segment.
ICS / OT
Conduct a tabletop exercise simulating simultaneous ransomware-as-cover (MuddyWater/Cactus pattern) and wiper deployment across IT and OT environments.
CISO / ExecIncident Responder
Review and harden CI/CD pipeline security — pin dependencies to commit SHAs, enable container image signing, audit Artifactory/GitLab/TeamCity access controls.
Incident Responder
No 7-day actions for the selected roles.
Implement VMCI monitoring capability for all VMware environments — alert on VMCI socket creation by non-management processes.
CISO / Exec
Commission an assessment of passive-C2 detection capabilities across the security stack — identify which tools can and cannot detect implants with zero outbound traffic.
CISO / Exec
Establish direct monitoring of pro-Iran hacktivist Telegram channels (Handala, Cyber Toufan, CyberAv3ngers) to close the collection gap.
Threat Hunter
Consolidate supply-chain threat tracking across Artifactory, TeamCity, GitLab, and Gitea into a unified monitoring framework with shared detection logic.
CISO / Exec
Review and diversify intelligence collection sources — ensure no single OSINT provider represents a single point of failure for geopolitical or threat actor monitoring.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Six months into the Iran conflict, we are watching Iranian cyber operations transition from opportunistic exploitation to disciplined pre-positioning. APT42 is running simultaneous campaigns across nuclear and defense sectors. Two CVSS 9.8 vulnerabilities are under active exploitation with public tooling available. A novel passive backdoor has emerged that renders conventional network detection irrelevant. And Iran's most destructive cyber unit has been silent for 29 days — nearly three times its normal operational cycle — while the Supreme Leader's public statements have opened an estimated retaliation window around 10 September. The organizations that will weather the next phase of this conflict are the ones that act on intelligence before it becomes incident response.

1
Patch the two critical CVEs today. Block the APT42 infrastructure today.
2
Hunt for SLEEPWALKER indicators today. Brief your leadership on the retaliation window today.
3
Validate — do not assume — that your incident response playbooks for destructive wiper attacks are current, tested, and executable under pressure. The silence will not last. Be ready when it breaks.
No items found.