| Date | Development | Significance |
|---|---|---|
| Jul 29 | Four Iran-hosted Cobalt Strike BEACON C2 servers refreshed simultaneously across four distinct Iranian ISPs | Indicates coordinated infrastructure validation ahead of operations |
| Jul 28 | MOIS-affiliated Cavern Manticore updated operational profile confirming "Operation Epic Fury" | Destructive campaign targeting Israeli government and IT sectors using a modular .NET C2 framework |
| Jul 28 | CISA published seven ICS advisories (Siemens S7-1500, S7-PLCSIM, Desigo CC, ABB KNX) | Expanding the OT attack surface during active conflict |
| Jul 27 | CVE-2025-68686 (FortiOS symlink persistence bypass) added to CISA KEV | Confirms even previously patched Fortinet devices remain compromised |
| Jul 27 | CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to KEV | Firewall management plane authentication bypass under active exploitation |
| Jul 27 | CVE-2026-63030 (WordPress REST API RCE, CVSS 9.8) added to KEV | Mass-exploitation vector Iranian actors use for C2 relay and watering-hole infrastructure |
| Jul 27 | CVE-2026-61511 (vBulletin pre-auth RCE, CVSS 9.8) published | Enables forum compromise for influence operations and credential harvesting |
| Jul 27 | PULSAR KITTEN confirmed active against aerospace, defense, and transportation via spear-phishing targeting international subsidiaries | Supply-chain access pattern exploiting weaker international office security |
| Since Jul 21 | Pro-Iran hacktivist groups (Handala, DieNet, 313 Team) maintain anomalous 8-day operational silence | Historical precursor to escalation from nuisance DDoS toward destructive or data-leak operations |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | 2026-02-28 | Iran-Israel conflict begins; initiates sustained Iranian cyber campaign |
| Hacktivist silence begins | Jul 21 | Last confirmed pro-Iran hacktivist operation — beginning of anomalous 8-day silence that persists to present |
| ICS/edge-device exploitation surge | Jul 23 – 27 | CISA publishes 7 ICS advisories (IEC 61850/60870-5-104); Check Point SmartConsole (CVE-2026-16232), FortiOS symlink bypass (CVE-2025-68686), WordPress RCE (CVE-2026-63030), and vBulletin RCE (CVE-2026-61511) all added to or published on KEV; PULSAR KITTEN aerospace/defense targeting confirmed |
| Destructive capability & OT expansion | Jul 28 | Cavern Manticore "Operation Epic Fury" profile created, confirming MOIS destructive capability active; 7 new ICS advisories (Siemens S7-1500, Desigo CC, ABB) expand OT attack surface |
| Current — pre-operational validation | Jul 29, 2026 | 4 Agentemis/Cobalt Strike C2 nodes refreshed simultaneously on Iranian ASNs — hallmark of operational readiness validation |
Four IP addresses hosted on Iranian ISPs (Pfcloud, Toosee Ertebatat Damavand, Afranet, Aria Shatel) were simultaneously refreshed on July 29, tagged with "Agentemis" and "BEACON" markers. Deep enrichment confirmed malicious classification across four independent sources including Sekoia, Recorded Future, Google Threat Intelligence, and Anomali Dark Web Intel.
Critically, one node (87.107.191[.]39) also shows association with Sliver — an open-source C2 framework. This represents a detection gap: organizations tuned exclusively for Cobalt Strike signatures will miss Sliver traffic originating from the same infrastructure.
Actors: multiple Iranian APT groups likely share this infrastructure kit. Malware: Cobalt Strike BEACON, Sliver, BumbleBee (loader). Ports: 443 (HTTPS), 53 (DNS), 80 (HTTP), 9090 (non-standard).
Cavern Manticore operates under Iran's Ministry of Intelligence and Security (MOIS) with a confirmed destructive mandate against Israeli government and IT infrastructure. Their "Operation Epic Fury" campaign employs a modular .NET C2 framework with multiple compilation formats designed to defeat static analysis. The decoupled architecture — separating core infrastructure from mission-specific modules — indicates a mature, disciplined operator capable of rapid retargeting.
Risk to non-Israeli organizations: spillover to allied nations and defense contractors is assessed as LOW probability in the immediate 72-hour window but MODERATE over 30 days, particularly for organizations with Israeli partnerships or shared infrastructure.
This IRGC-affiliated group targets aerospace, defense, energy, healthcare, and transportation sectors with a focus on satellite and space-launch intelligence. Their confirmed tradecraft includes spear-phishing employees at German branches of U.S. companies — exploiting the softer security posture of international subsidiaries to gain access to parent organization networks.
Malware: SilkySand, SurveyAgent, AnyDesk (legitimate tool abuse). Historical CVEs exploited: CVE-2022-47966 (ManageEngine), CVE-2021-44228 (Log4Shell), CVE-2022-26134 (Confluence), CVE-2021-34473 (ProxyShell), CVE-2018-13379 (FortiGate).
CVE-2025-68686 is particularly insidious: it bypasses the remediation for a previous symbolic link persistence mechanism in FortiOS. Organizations that patched and believed themselves secure may still harbor attacker-planted symlinks in /data/config/. Pioneer Kitten (UNC757), an IRGC-affiliated group, has historically exploited FortiGate devices and is the most likely actor leveraging this bypass.
Affected versions: FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2.x, 7.0.x, and 6.4.x.
Pro-Iran hacktivist groups (Handala, DieNet, 313 Team) have been silent for eight days. These groups historically operate in burst patterns and claim operations on Telegram within 24 hours. During an active conflict, this silence is anomalous. Historical precedent suggests operational pauses precede escalation — a shift from nuisance DDoS to destructive wiper deployment or coordinated data leak operations.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Additional Cobalt Strike/Sliver C2 infrastructure appears on Iranian ASNs | 75% | 72 hours | New IPs on ASN 44436, 25184, 31549, 51396 with BEACON/Sliver signatures |
| Mass exploitation of CVE-2026-63030 (WordPress) for Iranian C2/watering-hole infrastructure | 70% | 14 days | Compromised WordPress sites redirecting to Iranian-controlled domains; REST API batch endpoint exploitation in web logs |
| Pro-Iran hacktivists break silence with wiper or destructive operation | 50% | 7 days | Telegram channel activity from Handala/DieNet; shift from DDoS claims to data leak/wiper announcements |
| Pioneer Kitten exploits CVE-2025-68686 against previously-patched FortiGate devices | 45% | 7 days | Anomalous symlink creation in FortiOS filesystem; unexpected outbound connections from FortiGate management interfaces |
| Cavern Manticore "Epic Fury" expands beyond Israel to allied nations (UAE, U.S. DIB) | 20% | 30 days | .NET modular implant signatures in non-Israeli networks; MOIS targeting expansion historically follows 30–60 day cycles |
Alert on outbound connections to ASN 44436, 25184, 31549, 51396 on ports 53, 80, 443, 9090. Cross-reference with Cobalt Strike JARM hash 07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1 and Sliver default JARM signatures. Log sources: firewall, DNS, proxy, NDR.
Audit FortiGate filesystem for symbolic links in /data/config/ and /data2/ directories. Check for unexpected SSL VPN language files that may contain webshell code. Monitor for outbound connections from FortiGate management interfaces to non-Fortinet IPs. Log sources: FortiGate system logs, filesystem integrity monitoring.
Alert on AnyDesk installations not deployed via corporate software management. Monitor for AnyDesk.exe spawning from temp directories or user Downloads folders. Check for AnyDesk connections to IPs outside corporate-approved remote access ranges. Log sources: EDR, application whitelisting, proxy.
Monitor web application logs for unusual POST requests to /wp-json/wp/v2/batch endpoint with SQL injection patterns. Alert on new PHP files created in WordPress upload directories post-exploitation. Log sources: WAF, web server access logs, file integrity monitoring.
Monitor for .NET assembly loading from non-standard paths. Alert on csc.exe or msbuild.exe compiling code at runtime. Look for multiple compilation artifacts (.dll/.exe) with similar PE metadata but different hashes (polymorphic compilation). Log sources: EDR (process creation), AMSI telemetry, .NET ETW providers.
| Hypothesis | ATT&CK |
|---|---|
| Cobalt Strike/Sliver C2 on Non-Standard Ports | T1071.001 T1071.004 T1573.002 |
| FortiOS Symlink Persistence | T1059.004 T1078 T1505.003 |
| AnyDesk Abuse for Lateral Movement | T1219 |
| WordPress REST API Exploitation | T1190 |
| Modular .NET Implant (Cavern Manticore) | T1059.001 T1027 |
Agentemis/Cobalt Strike C2 nodes: 217.60.241[.]17 (port 443, ASN 51396), 87.107.191[.]39 (port 53, ASN 44436 — also Sliver), 79.175.189[.]207 (port 80, ASN 25184), 151.239.24[.]160 (port 9090, ASN 31549). Add to perimeter deny lists and SIEM watchlists immediately; run retroactive searches for any historical connections. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
/data/config/ or /data2/ on any FortiGate device, including those previously patched? The KEV confirms bypass of earlier remediations./wp-json/wp/v2/batch with SQL injection patterns, or new PHP files created in upload directories?csc.exe/msbuild.exe outside development environments?- Audit all externally-facing WordPress and vBulletin instances; patch to WordPress 7.0.2+ and vBulletin 6.2.2+ immediately
- Enable conditional access policies blocking authentication from Iranian ASN ranges (44436, 25184, 31549, 51396)
- Review SWIFT/payment system network segmentation — ensure no path exists from internet-facing web infrastructure to transaction processing systems
- Monitor for spear-phishing lures themed around sanctions, trade finance, or correspondent banking relationships
- Verify Siemens S7-1500 CPU 1518(F)-4 firmware is current; isolate GNU/Linux subsystem from untrusted networks per ICSA-26-209-04
- Audit Desigo CC building management systems for OpenSSL vulnerability exposure (ICSA-26-209-01) — these systems often bridge IT/OT boundaries
- Implement network monitoring at IEC 61850 and IEC 60870-5-104 protocol boundaries for unauthenticated command injection attempts
- Review and test OT incident response playbooks specifically for wiper scenarios — Cavern Manticore's destructive capability could target energy infrastructure
- Audit remote access tools (AnyDesk, SimpleHelp) across clinical environments — unauthorized installations are a PULSAR KITTEN hallmark
- Ensure medical device networks are segmented from corporate IT where Cobalt Strike BEACON would initially land
- Patch ManageEngine instances (CVE-2022-47966 remains in PULSAR KITTEN's active exploit kit) — healthcare organizations frequently run legacy ManageEngine deployments
- Pre-position ransomware response playbooks — MuddyWater (MOIS) has historically handed off healthcare access to ransomware affiliates (Qilin, Cactus)
- Deploy enhanced monitoring for .NET assembly side-loading and runtime compilation (T1059.001, T1027) across government endpoints
- Audit all Fortinet edge devices for CVE-2025-68686 symlink persistence — government networks are primary Pioneer Kitten targets
- Implement out-of-band communication plans that do not depend on potentially compromised IT infrastructure
- Review and exercise continuity-of-operations (COOP) plans assuming simultaneous IT destruction and OT disruption
- Conduct security posture assessment of international subsidiaries and branch offices, particularly in Turkey, UAE, Thailand, and Pakistan (confirmed PULSAR KITTEN target nations)
- Implement conditional access policies requiring device compliance for all cross-subsidiary authentication
- Monitor for SilkySand and SurveyAgent malware families in EDR telemetry
- Audit satellite communications and space-launch related data repositories for unauthorized access — this is PULSAR KITTEN's primary intelligence collection objective
217.60.241[.]17:443, 87.107.191[.]39:53, 79.175.189[.]207:80, 151.239.24[.]160:9090. Run 90-day retroactive search for any historical connections./data/config/ on ALL FortiGate devices, including those previously patched — the KEV confirms bypass of earlier remediations.We are five months into a conflict that has transformed Iranian cyber operations from opportunistic espionage into a coordinated, multi-domain offensive capability. The simultaneous refresh of C2 infrastructure, confirmation of destructive campaign tooling, active exploitation of edge device vulnerabilities, and anomalous hacktivist silence collectively paint a picture of an adversary preparing for escalation. The defenders' advantage is narrow but real: we can see the infrastructure being staged. Do not wait for the wiper to execute to validate the threat. The infrastructure is live. Act now.