TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Operations Enter Pre-Strike Posture:

What CISOs Must Know Now

HIGH. Five months into the Iran-Israel conflict, Iranian state-sponsored cyber operations have shifted from sustained espionage into what intelligence indicators suggest is active pre-strike infrastructure preparation. On July 29, four Cobalt Strike command-and-control nodes hosted on Iranian autonomous systems were refreshed simultaneously — a hallmark of operational readiness validation. Combined with confirmed destructive campaign activity from MOIS-linked actors and an anomalous eight-day silence from hacktivist proxies that historically precedes escalation, infrastructure is live and wipers are compiled — the question is not if but when and where.

I am a
My sector

DateDevelopmentSignificance
Jul 29Four Iran-hosted Cobalt Strike BEACON C2 servers refreshed simultaneously across four distinct Iranian ISPsIndicates coordinated infrastructure validation ahead of operations
Jul 28MOIS-affiliated Cavern Manticore updated operational profile confirming "Operation Epic Fury"Destructive campaign targeting Israeli government and IT sectors using a modular .NET C2 framework
Jul 28CISA published seven ICS advisories (Siemens S7-1500, S7-PLCSIM, Desigo CC, ABB KNX)Expanding the OT attack surface during active conflict
Jul 27CVE-2025-68686 (FortiOS symlink persistence bypass) added to CISA KEVConfirms even previously patched Fortinet devices remain compromised
Jul 27CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to KEVFirewall management plane authentication bypass under active exploitation
Jul 27CVE-2026-63030 (WordPress REST API RCE, CVSS 9.8) added to KEVMass-exploitation vector Iranian actors use for C2 relay and watering-hole infrastructure
Jul 27CVE-2026-61511 (vBulletin pre-auth RCE, CVSS 9.8) publishedEnables forum compromise for influence operations and credential harvesting
Jul 27PULSAR KITTEN confirmed active against aerospace, defense, and transportation via spear-phishing targeting international subsidiariesSupply-chain access pattern exploiting weaker international office security
Since Jul 21Pro-Iran hacktivist groups (Handala, DieNet, 313 Team) maintain anomalous 8-day operational silenceHistorical precursor to escalation from nuisance DDoS toward destructive or data-leak operations

PhaseTimeframeCyber Activity
Conflict begins2026-02-28Iran-Israel conflict begins; initiates sustained Iranian cyber campaign
Hacktivist silence beginsJul 21Last confirmed pro-Iran hacktivist operation — beginning of anomalous 8-day silence that persists to present
ICS/edge-device exploitation surgeJul 23 – 27CISA publishes 7 ICS advisories (IEC 61850/60870-5-104); Check Point SmartConsole (CVE-2026-16232), FortiOS symlink bypass (CVE-2025-68686), WordPress RCE (CVE-2026-63030), and vBulletin RCE (CVE-2026-61511) all added to or published on KEV; PULSAR KITTEN aerospace/defense targeting confirmed
Destructive capability & OT expansionJul 28Cavern Manticore "Operation Epic Fury" profile created, confirming MOIS destructive capability active; 7 new ICS advisories (Siemens S7-1500, Desigo CC, ABB) expand OT attack surface
Current — pre-operational validationJul 29, 20264 Agentemis/Cobalt Strike C2 nodes refreshed simultaneously on Iranian ASNs — hallmark of operational readiness validation

Four IP addresses hosted on Iranian ISPs (Pfcloud, Toosee Ertebatat Damavand, Afranet, Aria Shatel) were simultaneously refreshed on July 29, tagged with "Agentemis" and "BEACON" markers. Deep enrichment confirmed malicious classification across four independent sources including Sekoia, Recorded Future, Google Threat Intelligence, and Anomali Dark Web Intel.

Critically, one node (87.107.191[.]39) also shows association with Sliver — an open-source C2 framework. This represents a detection gap: organizations tuned exclusively for Cobalt Strike signatures will miss Sliver traffic originating from the same infrastructure.

Actors: multiple Iranian APT groups likely share this infrastructure kit. Malware: Cobalt Strike BEACON, Sliver, BumbleBee (loader). Ports: 443 (HTTPS), 53 (DNS), 80 (HTTP), 9090 (non-standard).

T1071.001T1071.004T1573.002

Cavern Manticore operates under Iran's Ministry of Intelligence and Security (MOIS) with a confirmed destructive mandate against Israeli government and IT infrastructure. Their "Operation Epic Fury" campaign employs a modular .NET C2 framework with multiple compilation formats designed to defeat static analysis. The decoupled architecture — separating core infrastructure from mission-specific modules — indicates a mature, disciplined operator capable of rapid retargeting.

Risk to non-Israeli organizations: spillover to allied nations and defense contractors is assessed as LOW probability in the immediate 72-hour window but MODERATE over 30 days, particularly for organizations with Israeli partnerships or shared infrastructure.

T1059.001T1027

This IRGC-affiliated group targets aerospace, defense, energy, healthcare, and transportation sectors with a focus on satellite and space-launch intelligence. Their confirmed tradecraft includes spear-phishing employees at German branches of U.S. companies — exploiting the softer security posture of international subsidiaries to gain access to parent organization networks.

Malware: SilkySand, SurveyAgent, AnyDesk (legitimate tool abuse). Historical CVEs exploited: CVE-2022-47966 (ManageEngine), CVE-2021-44228 (Log4Shell), CVE-2022-26134 (Confluence), CVE-2021-34473 (ProxyShell), CVE-2018-13379 (FortiGate).

T1219

CVE-2025-68686 is particularly insidious: it bypasses the remediation for a previous symbolic link persistence mechanism in FortiOS. Organizations that patched and believed themselves secure may still harbor attacker-planted symlinks in /data/config/. Pioneer Kitten (UNC757), an IRGC-affiliated group, has historically exploited FortiGate devices and is the most likely actor leveraging this bypass.

Affected versions: FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2.x, 7.0.x, and 6.4.x.

T1059.004T1078T1505.003

Pro-Iran hacktivist groups (Handala, DieNet, 313 Team) have been silent for eight days. These groups historically operate in burst patterns and claim operations on Telegram within 24 hours. During an active conflict, this silence is anomalous. Historical precedent suggests operational pauses precede escalation — a shift from nuisance DDoS to destructive wiper deployment or coordinated data leak operations.

ScenarioProbabilityTimeframeIndicators to Watch
Additional Cobalt Strike/Sliver C2 infrastructure appears on Iranian ASNs75%72 hoursNew IPs on ASN 44436, 25184, 31549, 51396 with BEACON/Sliver signatures
Mass exploitation of CVE-2026-63030 (WordPress) for Iranian C2/watering-hole infrastructure70%14 daysCompromised WordPress sites redirecting to Iranian-controlled domains; REST API batch endpoint exploitation in web logs
Pro-Iran hacktivists break silence with wiper or destructive operation50%7 daysTelegram channel activity from Handala/DieNet; shift from DDoS claims to data leak/wiper announcements
Pioneer Kitten exploits CVE-2025-68686 against previously-patched FortiGate devices45%7 daysAnomalous symlink creation in FortiOS filesystem; unexpected outbound connections from FortiGate management interfaces
Cavern Manticore "Epic Fury" expands beyond Israel to allied nations (UAE, U.S. DIB)20%30 days.NET modular implant signatures in non-Israeli networks; MOIS targeting expansion historically follows 30–60 day cycles

Hunt Hypothesis 1 · Cobalt Strike/Sliver C2 on Non-Standard Ports:

Alert on outbound connections to ASN 44436, 25184, 31549, 51396 on ports 53, 80, 443, 9090. Cross-reference with Cobalt Strike JARM hash 07d14d16d21d21d07c42d41d00041d24a458a375eef0c576d23a7bab9a9fb1 and Sliver default JARM signatures. Log sources: firewall, DNS, proxy, NDR.

Hunt Hypothesis 2 · FortiOS Symlink Persistence (CVE-2025-68686):

Audit FortiGate filesystem for symbolic links in /data/config/ and /data2/ directories. Check for unexpected SSL VPN language files that may contain webshell code. Monitor for outbound connections from FortiGate management interfaces to non-Fortinet IPs. Log sources: FortiGate system logs, filesystem integrity monitoring.

Hunt Hypothesis 3 · AnyDesk Abuse for Lateral Movement (PULSAR KITTEN):

Alert on AnyDesk installations not deployed via corporate software management. Monitor for AnyDesk.exe spawning from temp directories or user Downloads folders. Check for AnyDesk connections to IPs outside corporate-approved remote access ranges. Log sources: EDR, application whitelisting, proxy.

Hunt Hypothesis 4 · WordPress REST API Exploitation (CVE-2026-63030):

Monitor web application logs for unusual POST requests to /wp-json/wp/v2/batch endpoint with SQL injection patterns. Alert on new PHP files created in WordPress upload directories post-exploitation. Log sources: WAF, web server access logs, file integrity monitoring.

Hunt Hypothesis 5 · Modular .NET Implant (Cavern Manticore):

Monitor for .NET assembly loading from non-standard paths. Alert on csc.exe or msbuild.exe compiling code at runtime. Look for multiple compilation artifacts (.dll/.exe) with similar PE metadata but different hashes (polymorphic compilation). Log sources: EDR (process creation), AMSI telemetry, .NET ETW providers.

HypothesisATT&CK
Cobalt Strike/Sliver C2 on Non-Standard PortsT1071.001 T1071.004 T1573.002
FortiOS Symlink PersistenceT1059.004 T1078 T1505.003
AnyDesk Abuse for Lateral MovementT1219
WordPress REST API ExploitationT1190
Modular .NET Implant (Cavern Manticore)T1059.001 T1027
IOC Blocking Table:
217.60.241[.]1787.107.191[.]3979.175.189[.]207151.239.24[.]160

Agentemis/Cobalt Strike C2 nodes: 217.60.241[.]17 (port 443, ASN 51396), 87.107.191[.]39 (port 53, ASN 44436 — also Sliver), 79.175.189[.]207 (port 80, ASN 25184), 151.239.24[.]160 (port 9090, ASN 31549). Add to perimeter deny lists and SIEM watchlists immediately; run retroactive searches for any historical connections. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1071.001
Cobalt Strike/Sliver C2 communications
Are any internal hosts communicating with ASN 44436, 25184, 31549, or 51396 on ports 53, 80, 443, or 9090? Cross-reference with the Cobalt Strike JARM hash and Sliver default signatures.
HUNT 02 · T1505.003
FortiGate symlink persistence
Are there unexpected symbolic links in /data/config/ or /data2/ on any FortiGate device, including those previously patched? The KEV confirms bypass of earlier remediations.
HUNT 03 · T1219
AnyDesk abuse (PULSAR KITTEN)
Are there AnyDesk installations not deployed via corporate software management, or instances spawning from temp/Downloads directories?
HUNT 04 · T1190
WordPress REST API exploitation
Are there unusual POST requests to /wp-json/wp/v2/batch with SQL injection patterns, or new PHP files created in upload directories?
HUNT 05 · T1027
Polymorphic .NET compilation
Are there multiple compilation artifacts (.dll/.exe) with similar PE metadata but different hashes, or runtime compilation via csc.exe/msbuild.exe outside development environments?

Financial Services
Watering-Hole & Credential Harvesting
Primary threats
Iranian actors use compromised WordPress and vBulletin infrastructure for credential harvesting and watering-hole attacks against financial sector employees
Actions
  • Audit all externally-facing WordPress and vBulletin instances; patch to WordPress 7.0.2+ and vBulletin 6.2.2+ immediately
  • Enable conditional access policies blocking authentication from Iranian ASN ranges (44436, 25184, 31549, 51396)
  • Review SWIFT/payment system network segmentation — ensure no path exists from internet-facing web infrastructure to transaction processing systems
  • Monitor for spear-phishing lures themed around sanctions, trade finance, or correspondent banking relationships
Energy
Siemens/ABB ICS, Protocol Boundaries
Primary threats
Seven ICS advisories (Siemens S7-1500, S7-PLCSIM, Desigo CC, ABB KNX) directly expand the attack surface for energy sector OT environments; Cyber Av3ngers has demonstrated willingness to target water and energy infrastructure
Actions
  • Verify Siemens S7-1500 CPU 1518(F)-4 firmware is current; isolate GNU/Linux subsystem from untrusted networks per ICSA-26-209-04
  • Audit Desigo CC building management systems for OpenSSL vulnerability exposure (ICSA-26-209-01) — these systems often bridge IT/OT boundaries
  • Implement network monitoring at IEC 61850 and IEC 60870-5-104 protocol boundaries for unauthenticated command injection attempts
  • Review and test OT incident response playbooks specifically for wiper scenarios — Cavern Manticore's destructive capability could target energy infrastructure
Healthcare
Remote Access, Legacy ManageEngine
Primary threats
PULSAR KITTEN's confirmed targeting of healthcare organizations, combined with mass-exploitation vulnerabilities (WordPress, vBulletin), creates dual risk: data theft and operational disruption
Actions
  • Audit remote access tools (AnyDesk, SimpleHelp) across clinical environments — unauthorized installations are a PULSAR KITTEN hallmark
  • Ensure medical device networks are segmented from corporate IT where Cobalt Strike BEACON would initially land
  • Patch ManageEngine instances (CVE-2022-47966 remains in PULSAR KITTEN's active exploit kit) — healthcare organizations frequently run legacy ManageEngine deployments
  • Pre-position ransomware response playbooks — MuddyWater (MOIS) has historically handed off healthcare access to ransomware affiliates (Qilin, Cactus)
Government
Destructive Intent, COOP Planning
Primary threats
Cavern Manticore's "Operation Epic Fury" directly targets government organizations with destructive intent; while currently focused on Israeli government, allied nations with shared intelligence infrastructure face spillover risk
Actions
  • Deploy enhanced monitoring for .NET assembly side-loading and runtime compilation (T1059.001, T1027) across government endpoints
  • Audit all Fortinet edge devices for CVE-2025-68686 symlink persistence — government networks are primary Pioneer Kitten targets
  • Implement out-of-band communication plans that do not depend on potentially compromised IT infrastructure
  • Review and exercise continuity-of-operations (COOP) plans assuming simultaneous IT destruction and OT disruption
Aviation / Logistics
International Subsidiaries, Satellite IP
Primary threats
PULSAR KITTEN specifically targeted a U.S. transportation company through its German subsidiary — a supply-chain access pattern that exploits weaker international office security
Actions
  • Conduct security posture assessment of international subsidiaries and branch offices, particularly in Turkey, UAE, Thailand, and Pakistan (confirmed PULSAR KITTEN target nations)
  • Implement conditional access policies requiring device compliance for all cross-subsidiary authentication
  • Monitor for SilkySand and SurveyAgent malware families in EDR telemetry
  • Audit satellite communications and space-launch related data repositories for unauthorized access — this is PULSAR KITTEN's primary intelligence collection objective
No sector cards match the selected filters.

Block Agentemis C2 IPs at perimeter: 217.60.241[.]17:443, 87.107.191[.]39:53, 79.175.189[.]207:80, 151.239.24[.]160:9090. Run 90-day retroactive search for any historical connections.
SOC Analyst
Deploy Sliver C2 detection signatures (JARM + JA3) alongside existing Cobalt Strike rules — same infrastructure serves both frameworks.
SOC Analyst
Verify FortiOS patch status for CVE-2025-68686. Critical: check for residual symbolic links in /data/config/ on ALL FortiGate devices, including those previously patched — the KEV confirms bypass of earlier remediations.
IAM Analyst
Patch WordPress to 7.0.2+ (CVE-2026-63030, CVSS 9.8). Prioritize instances used for public communications, partner portals, or any site with authentication functionality.
IAM Analyst
Add ASN-level monitoring for Iranian hosting providers (ASN 44436, 25184, 31549, 51396) — any outbound connection to these networks warrants immediate investigation.
SOC Analyst
No immediate actions for the selected roles.
Audit and patch vBulletin instances to 6.2.2+ (CVE-2026-61511, CVSS 9.8 pre-auth RCE). Include partner and vendor-hosted forums in scope.
IAM Analyst
Verify Siemens S7-1500 CPU 1518(F)-4 firmware against ICSA-26-209-04. Ensure GNU/Linux subsystem is network-isolated. Audit Desigo CC for OpenSSL exposure.
ICS / OT
Develop detection for AnyDesk abuse pattern: installations from non-corporate deployment channels, connections to non-approved IP ranges, execution from temp/Downloads directories.
SOC Analyst
Audit Check Point SmartConsole deployments for CVE-2026-16232 (CVSS 9.1, KEV) — management plane authentication bypass remains under active exploitation.
IAM Analyst
Brief executive leadership on hacktivist silence pattern and potential escalation from DDoS to destructive operations. Ensure crisis communication plans are current.
CISO / Exec
No 7-day actions for the selected roles.
Commission red team assessment simulating PULSAR KITTEN's international subsidiary access pattern — test whether compromise of a branch office enables lateral movement to parent organization crown jewels.
CISO / Exec
Build detection analytics for hacktivist-to-wiper transition: monitor Telegram channels (Handala, DieNet, 313 Team) for shift from DDoS claims to data destruction announcements.
SOC Analyst
Implement dual-vendor edge device strategy — the concentration of KEV additions for Fortinet (2 CVEs) and Check Point (1 CVE) in a single week demonstrates single-vendor risk in perimeter architecture.
IAM Analyst
Conduct a tabletop exercise for simultaneous IT wiper + OT disruption scenario, modeled on Cavern Manticore's "Epic Fury" destructive capability combined with ICS vulnerability exploitation.
Incident Responder
Review and update cyber insurance coverage and incident response retainer scope to explicitly cover state-sponsored destructive attacks — policy exclusions for "acts of war" may be tested by Iran conflict spillover.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

We are five months into a conflict that has transformed Iranian cyber operations from opportunistic espionage into a coordinated, multi-domain offensive capability. The simultaneous refresh of C2 infrastructure, confirmation of destructive campaign tooling, active exploitation of edge device vulnerabilities, and anomalous hacktivist silence collectively paint a picture of an adversary preparing for escalation. The defenders' advantage is narrow but real: we can see the infrastructure being staged. Do not wait for the wiper to execute to validate the threat. The infrastructure is live. Act now.

1
Have you blocked the four Agentemis C2 nodes? All four were refreshed simultaneously on July 29 — a hallmark of operational readiness validation, not routine maintenance.
2
Have you verified FortiGate filesystem integrity? CVE-2025-68686 confirms that patching alone does not remove attackers who compromised the device before you patched.
3
Are your incident response teams prepared for a destructive scenario? Eight days of hacktivist silence during active conflict has historically preceded a shift from DDoS to wiper deployment.
No items found.