TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Operations Escalate:

MuddyWater Deploys Novel Backdoor as Critical Vulnerabilities Multiply

HIGH. Six months into the Iran conflict, the cyber dimension continues to intensify. Today's intelligence reveals a dangerous convergence: MuddyWater has evolved its backdoor toolkit with a novel evasion technique that renders entire kill chains invisible to signature-based detection, two critical vulnerability chains are being actively probed for exploitation, and the silence following this week's unprecedented sanctions package raises more questions than it answers. CISOs across financial services, defense, energy, and government sectors face a narrowing window to act.

I am a
My sector

DevelopmentWhy It Matters
MuddyWater's DinDoor backdoor now abuses the Deno JavaScript runtime — entire kill chain uses signed, legitimate binariesTraditional allowlisting and signature detection will miss this. Active C2 infrastructure confirmed targeting US financial sector.
Microsoft SharePoint unauthenticated RCE chain (CVE-2026-55040 + CVE-2026-63520) added to CISA KEV, active probing in honeypots~329,000 exposed instances. Iranian actors historically weaponize within 72 hours of PoC publication.
Gitea CVE-2026-60004 added to CISA KEV — active exploitation confirmedDefault configurations allow effectively unauthenticated RCE. Relevant to any organization with DevOps pipelines.
NVIDIA NemoClaw AI agent hijacking (CVE-2026-65105) disclosedA single website visit can permanently poison an AI agent's behavior — a genuinely novel attack class.
~48-hour sanctions retaliation window still open without detected responseAmbiguous silence: either Iran has deferred retaliation or pre-positioned below detection threshold. The 72-hour window has not yet elapsed; neither interpretation warrants complacency.
ASN 213790 Iranian APT/Cactus ransomware infrastructure crossover confirmedFour IPs serve dual state-espionage and criminal ransomware purposes, targeting healthcare and manufacturing simultaneously.
7 ICS advisories including Siemens SIMATIC IoT2050 and FURUNO AIS transpondersDirect relevance to critical infrastructure and maritime operations.

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran conflict begins — now ~180 days of sustained cyber-kinetic operations.
Cross-actor tooling convergenceAug 22–23, 2026MuddyWater deploys fresh malware across 15 countries; tooling convergence with North Korean actors confirmed — cross-actor collaboration expanding Iranian reach.
Sanctions announced — retaliation window opensAug 24, 2026US Treasury/OFAC announces Operation Economic Outcast — the most comprehensive Iran sanctions since 2018. Historical pattern: retaliatory cyber ops within 48–72 hours.
Water sabotage confirmed & KEV/ICS surgeAug 25, 2026CyberAv3ngers (IRGC) confirmed compromising water/wastewater facilities in 7–12 US states — public health consequences, automated chlorination systems targeted; CISA adds Gitea CVE-2026-60004 to KEV; 7 ICS advisories published (Siemens SIMATIC, FURUNO AIS).
Current — DinDoor/Deno pivot & AI hijacking disclosedAug 26, 2026Binary Defense publishes DinDoor/Deno analysis; SharePoint RCE chain probing confirmed; NemoClaw AI hijacking disclosed — multiple simultaneous escalation vectors.

Actor: MuddyWater (MOIS-affiliated, also tracked as TEMP.Zagros). Targets: US financial services, US software companies, Canadian non-profits. Malware: DinDoor (also referenced as "Tsundere" in some tracking).

MuddyWater has fundamentally changed how DinDoor operates. Previous variants relied on PowerShell and .NET — well-understood by defenders. The new variant chains three signed, legitimate Windows binaries: curl.exe downloads the Deno runtime from deno[.]land; deno.exe executes a Base64-encoded JavaScript payload; wscript.exe launches a VBScript persistence mechanism from AppData\Local\Serial\.

The payload performs sandbox detection (querying Win32_VideoController via WMI), establishes persistence via Registry Run Keys, and communicates with C2 infrastructure over TCP using Deno's native networking.

Why this matters: every binary in the chain is legitimately signed. Organizations that allowlist developer tools or rely on reputation-based detection will not catch this. The shift to Deno — a relatively obscure runtime outside web development — creates a detection gap that most EDR configurations are not tuned for.

T1059.007T1059.005T1547.001T1497.001T1071.001T1105

CVEs: CVE-2026-55040 (CVSS 9.1, JWT authentication bypass) + CVE-2026-63520 (CVSS 8.1, BCS deserialization RCE). Status: CVE-2026-55040 on CISA KEV since 18 Aug; active probing in honeypots; PoC chain publicly available.

When chained, these two vulnerabilities deliver unauthenticated remote code execution on on-premises Microsoft SharePoint Server. Approximately 329,000 instances are internet-exposed, with ~21,000 showing version information that confirms vulnerability.

Iranian APT groups — particularly Pioneer Kitten (UNC757) and APT34 — have a documented pattern of weaponizing new KEV entries within 72 hours of proof-of-concept publication. This is not a patching cycle; it is a race condition.

T1190T1078T1134

CVE: CVE-2026-60004. Status: CISA KEV (added 25 Aug), active exploitation deploying cryptominers, FCEB patch deadline 28 Aug.

Gitea's diffpatch API contains a critical code injection vulnerability. Authenticated users with write access can execute arbitrary shell commands. The critical detail: default Gitea installations have self-registration enabled, meaning attackers can create accounts and exploit without any prior access.

While current exploitation is limited to cryptomining, this vulnerability sits squarely in Pioneer Kitten's operational playbook — they specialize in exploiting DevOps platforms for initial access, then broker that access to ransomware operators.

T1059T1190T1078

CVE: CVE-2026-65105. Product: NVIDIA NemoClaw (local Ollama configuration). Status: disclosed 26 Aug; no confirmed in-the-wild exploitation yet.

This vulnerability represents something genuinely new. NemoClaw's default Ollama configuration binds to 0.0.0.0:11434 without authentication. Through DNS rebinding, an attacker can inject hidden instructions into an AI agent's model template — permanently altering its behavior without changing the model's name, size, or metadata.

A compromised AI agent could generate backdoored code, suppress security warnings, or exfiltrate sensitive data — all while appearing completely normal to operators. No standard tooling exists to detect model template poisoning. This is a strategic gap.

T1564.001T1195.002T1016

Four IP addresses on ASN 213790 ("Limited Network," Tehran) continue to serve dual purposes: tagged for both Cactus ransomware operations and Iranian APT activity. This crossover between state-sponsored espionage and criminal ransomware operations — targeting healthcare and manufacturing — represents the blurring of lines between Iranian state objectives and financially-motivated cybercrime.

Seven CISA ICS advisories published on 25 August also affect systems directly relevant to critical infrastructure: Siemens SIMATIC IoT2050 Advanced (missing Node-RED authentication), FURUNO FA-50 Class B AIS Transponder (device setting manipulation, maritime domain awareness impact), Ebyte NE2-D11 (unauthorized admin access), and Bendix EC80 Brake ECU (loss of ABS/steering/speedometer functions).

T1486

ScenarioProbabilityTimeframeBasis
Pioneer Kitten (UNC757) begins scanning for SharePoint CVE-2026-5504070%Within 5 daysDocumented pattern of rapid KEV exploitation for initial access brokering
MuddyWater DinDoor campaign expands to defense/government targets50%Within 2 weeksHistorical pattern: financial-sector testing precedes high-value targeting
Iranian sanctions retaliation manifests as below-threshold activity (credential harvesting, pre-positioning)40%OngoingDiplomatic channels remain open; overt destruction risks escalation
SPECTRAL KITTEN/Agrius silence precedes destructive operation against Israeli energy infrastructure30%7–14 daysOperational pause pattern observed before previous destructive campaigns
AI model template poisoning exploited by state actor for intelligence collection25%3–6 monthsNovel technique; adoption lag expected but strategic value is high

DinDoor/Deno Runtime Abuse:

Alert on deno.exe launched with command-line arguments containing Base64 strings >500 characters on non-developer endpoints (T1059.007) Alert on curl.exe establishing connections to deno[.]land from non-developer workstations (T1105) Alert on wscript.exe invoking .vbs files under AppData\Local\Serial\ (T1059.005) Monitor for Win32_VideoController WMI queries from scripting engines — sandbox detection behavior (T1497.001)

SharePoint Exploitation:

Monitor SharePoint IIS logs for anomalous JWT token patterns and BCS deserialization payloads (T1190, T1078) Alert on System.Web.UI.LosFormatter deserialization attempts in SharePoint request bodies (T1203) Baseline normal SharePoint authentication patterns; alert on token forgery indicators (T1134)

Gitea Exploitation:

Monitor Gitea audit logs for new account self-registrations followed by repository write operations (T1078) Alert on shell command execution originating from Gitea diffpatch API calls (T1059) Audit all Git hooks for unauthorized modifications

AI/Ollama Security:

Monitor network connections to port 11434 from external sources (T1016) Alert on DNS rebinding patterns targeting internal Ollama instances (T1564.001)

IOC Blocking Table:

Additional IOCs available via Anomali ThreatStream. ---

ThreatATT&CK
DinDoor/Deno Runtime AbuseT1059.007 T1105 T1059.005 T1497.001
SharePoint ExploitationT1190 T1078 T1203 T1134
Gitea ExploitationT1078 T1059
AI/Ollama SecurityT1016 T1564.001
IOC Blocking Table:
138.124.240[.]762.27.122[.]162.27.248[.]612.27.160[.]242.27.248[.]7245.153.34[.]14685.90.197[.]26185.236.25[.]11977.90.185[.]118185.93.89[.]4377.90.185[.]248192.253.248[.]65176.123.87[.]16

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01
Hunt for dormant MuddyWater beacons
Query network logs for any historical connections to ASN 213790 (77.90.185[.]0/24, 185.93.89[.]0/24) or MuddyWater EtherHiding C2 infrastructure. The sanctions retaliation window may trigger dormant implant activation before it closes.
HUNT 02
Hunt for Deno runtime on non-developer systems
Sweep endpoints for deno.exe presence outside approved development environments. Check for AppData\Local\Serial\ directory creation.
HUNT 03
Hunt for SharePoint pre-exploitation reconnaissance
Review WAF logs for scanning patterns against SharePoint endpoints — particularly requests probing /_api/ and BCS endpoints.
HUNT 04
Hunt for Pioneer Kitten initial access patterns
Review VPN and edge device logs for exploitation attempts against Fortinet, SonicWall, and now SharePoint/Gitea from previously documented Pioneer Kitten infrastructure.

Financial Services
SWIFT-Connected Segments, Trading Floors
Primary threat
MuddyWater's DinDoor campaign is actively targeting US banking institutions. The Deno runtime technique specifically evades financial-sector EDR configurations that allowlist developer tools for fintech operations.
Actions
  • Deploy behavioral detection for deno.exe with anomalous arguments on all endpoints, particularly those in trading floors, payment processing, and SWIFT-connected segments
  • Review JavaScript runtime policies — Deno may be legitimately present in some environments; detection must be context-aware (developer vs. non-developer endpoints)
  • Threat hunt for historical connections to DinDoor C2 infrastructure and ASN 213790
Energy
SCADA, Node-RED/IoT2050
Primary threats
SPECTRAL KITTEN/Agrius silence during an active conflict escalation period is a warning indicator, not a reassurance. Combined with new Siemens SIMATIC IoT2050 vulnerabilities (missing Node-RED authentication), energy sector OT environments face elevated risk.
Actions
  • Audit all Siemens SIMATIC IoT2050 deployments for Node-RED authentication status; apply ICSA-26-237-03 mitigations immediately
  • Segment OT networks to prevent lateral movement from IT compromise (SharePoint RCE) to ICS environments
  • Increase monitoring cadence on OT network traffic for anomalous command sequences
Healthcare
Clinical Coordination Systems
Primary threats
ASN 213790 infrastructure is explicitly tagged for healthcare sector targeting, with Cactus ransomware crossover confirmed. The dual-use nature of this infrastructure (state espionage + ransomware) means healthcare organizations face both data theft and operational disruption risks.
Actions
  • Block all traffic to/from ASN 213790 IP ranges at the perimeter
  • Ensure SharePoint instances used for clinical coordination are patched for CVE-2026-55040/CVE-2026-63520 or isolated from internet access
  • Validate backup integrity and ransomware recovery procedures given active Cactus campaign targeting
Government
SharePoint, DevSecOps Pipelines
Primary threat
On-premises SharePoint remains the backbone of many government coordination systems. The unauthenticated RCE chain (CVE-2026-55040 + CVE-2026-63520) represents a direct path to sensitive government data and communications.
Actions
  • Emergency patching of all SharePoint Server instances; if patching is not immediately possible, restrict internet-facing exposure via WAF rules blocking BCS deserialization payloads
  • Audit for Gitea instances in government DevSecOps pipelines; disable self-registration; patch to 1.27.1
  • Conduct a proactive hunt for Iranian pre-positioning — review 90-day network logs for connections to documented MuddyWater and Pioneer Kitten infrastructure
Aviation / Logistics
AIS Transponders, Fleet Management
Primary threats
FURUNO AIS transponder vulnerabilities (ICSA-26-237-07) directly threaten maritime domain awareness. Combined with previously identified CPDLC/ATN-B1 aviation concerns, the transportation sector faces expanding attack surface in safety-critical communications systems.
Actions
  • Audit FURUNO FA-50 Class B AIS transponder firmware and apply vendor mitigations
  • Implement integrity monitoring on AIS data feeds — alert on anomalous vessel position reports or configuration changes
  • Review Bendix EC80 brake ECU exposure in fleet management systems; apply ICSA-26-237-05 mitigations
No sector cards match the selected filters.

Block all 13 IOCs listed above at perimeter firewalls, DNS sinkholes, and proxy systems.
SOC Analyst
Deploy detection rules for Deno runtime abuse: deno.exe with Base64 arguments >500 chars on non-developer endpoints; curl.exe to deno[.]land; wscript.exe invoking VBS under AppData\Local\Serial\.
SOC Analyst
Initiate emergency patching for Microsoft SharePoint Server (CVE-2026-55040, CVE-2026-63520). If a patch window is unavailable within 24h, implement WAF rules blocking BCS deserialization payloads and restrict external access.
Incident Responder
Patch Gitea to version 1.27.1 (CVE-2026-60004). Disable self-registration on ALL internet-facing instances immediately.
Incident Responder
Launch a proactive threat hunt for connections to ASN 213790 and MuddyWater EtherHiding C2 infrastructure — the open sanctions retaliation window demands active investigation before it closes.
Threat Hunter
No immediate actions for the selected roles.
Audit all Ollama/NemoClaw deployments: ensure the bind address is 127.0.0.1, restrict port 11434, audit model templates for unauthorized system prompt injections.
Incident Responder
Review Siemens SIMATIC IoT2050 Node-RED authentication configuration; apply ICSA-26-237-03 mitigations. Audit FURUNO AIS transponder firmware per ICSA-26-237-07.
ICS / OT
Conduct an enterprise-wide sweep for deno.exe on non-developer endpoints; investigate any instances found.
SOC Analyst
Establish monitoring for Pioneer Kitten (UNC757) scanning patterns against SharePoint and Gitea — expected within 5 days based on historical behavior.
Threat Hunter
Brief executive leadership on sanctions retaliation risk and the ambiguous silence from Iranian actors — ensure incident response plans are current and tested.
CISO / Exec
No 7-day actions for the selected roles.
Commission an assessment of AI agent security posture: inventory all local LLM inference deployments, evaluate DNS rebinding exposure, establish model template integrity monitoring.
CISO / Exec
Establish Telegram channel monitoring for Handala, Cyber Toufan, and DieNet to close intelligence collection gaps on Iranian hacktivist operations.
Threat Hunter
Evaluate ASN-based blocking policies for known Iranian bulletproof hosting (ASN 213790, ASN 206134, ASN 207043) as a persistent defensive measure.
CISO / Exec
Conduct a tabletop exercise simulating simultaneous SharePoint compromise + ransomware deployment + ICS manipulation — the convergence scenario this intelligence supports.
CISO / ExecIncident Responder
Review and update JavaScript runtime allowlisting policies enterprise-wide — the Deno technique will be adopted by other actors.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

We are 180 days into a conflict that shows no signs of cyber de-escalation. Today's intelligence reveals Iranian operators investing in increasingly sophisticated evasion — signed-binary kill chains, AI agent poisoning, and rapid exploitation of newly disclosed vulnerabilities. The silence following Operation Economic Outcast sanctions is not peace; the 72-hour retaliation window has not yet elapsed, and the absence of detected activity reflects either restraint or concealment — neither warrants complacency. The convergence of MuddyWater's financial-sector campaign, critical SharePoint and Gitea vulnerabilities entering active exploitation, and ICS advisories affecting allied infrastructure creates a threat environment where multiple attack paths are simultaneously viable. Pioneer Kitten's historical 72-hour exploitation window for new KEVs means the SharePoint RCE chain is likely already being weaponized.

1
Block the confirmed C2 infrastructure.
2
Patch SharePoint and Gitea as emergency actions, not scheduled maintenance.
3
Hunt for pre-positioning on Iranian APT infrastructure — the adversary is not waiting, neither should you.
No items found.