| Development | Why It Matters |
|---|---|
| MuddyWater's DinDoor backdoor now abuses the Deno JavaScript runtime — entire kill chain uses signed, legitimate binaries | Traditional allowlisting and signature detection will miss this. Active C2 infrastructure confirmed targeting US financial sector. |
| Microsoft SharePoint unauthenticated RCE chain (CVE-2026-55040 + CVE-2026-63520) added to CISA KEV, active probing in honeypots | ~329,000 exposed instances. Iranian actors historically weaponize within 72 hours of PoC publication. |
| Gitea CVE-2026-60004 added to CISA KEV — active exploitation confirmed | Default configurations allow effectively unauthenticated RCE. Relevant to any organization with DevOps pipelines. |
| NVIDIA NemoClaw AI agent hijacking (CVE-2026-65105) disclosed | A single website visit can permanently poison an AI agent's behavior — a genuinely novel attack class. |
| ~48-hour sanctions retaliation window still open without detected response | Ambiguous silence: either Iran has deferred retaliation or pre-positioned below detection threshold. The 72-hour window has not yet elapsed; neither interpretation warrants complacency. |
| ASN 213790 Iranian APT/Cactus ransomware infrastructure crossover confirmed | Four IPs serve dual state-espionage and criminal ransomware purposes, targeting healthcare and manufacturing simultaneously. |
| 7 ICS advisories including Siemens SIMATIC IoT2050 and FURUNO AIS transponders | Direct relevance to critical infrastructure and maritime operations. |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | Iran conflict begins — now ~180 days of sustained cyber-kinetic operations. |
| Cross-actor tooling convergence | Aug 22–23, 2026 | MuddyWater deploys fresh malware across 15 countries; tooling convergence with North Korean actors confirmed — cross-actor collaboration expanding Iranian reach. |
| Sanctions announced — retaliation window opens | Aug 24, 2026 | US Treasury/OFAC announces Operation Economic Outcast — the most comprehensive Iran sanctions since 2018. Historical pattern: retaliatory cyber ops within 48–72 hours. |
| Water sabotage confirmed & KEV/ICS surge | Aug 25, 2026 | CyberAv3ngers (IRGC) confirmed compromising water/wastewater facilities in 7–12 US states — public health consequences, automated chlorination systems targeted; CISA adds Gitea CVE-2026-60004 to KEV; 7 ICS advisories published (Siemens SIMATIC, FURUNO AIS). |
| Current — DinDoor/Deno pivot & AI hijacking disclosed | Aug 26, 2026 | Binary Defense publishes DinDoor/Deno analysis; SharePoint RCE chain probing confirmed; NemoClaw AI hijacking disclosed — multiple simultaneous escalation vectors. |
Actor: MuddyWater (MOIS-affiliated, also tracked as TEMP.Zagros). Targets: US financial services, US software companies, Canadian non-profits. Malware: DinDoor (also referenced as "Tsundere" in some tracking).
MuddyWater has fundamentally changed how DinDoor operates. Previous variants relied on PowerShell and .NET — well-understood by defenders. The new variant chains three signed, legitimate Windows binaries: curl.exe downloads the Deno runtime from deno[.]land; deno.exe executes a Base64-encoded JavaScript payload; wscript.exe launches a VBScript persistence mechanism from AppData\Local\Serial\.
The payload performs sandbox detection (querying Win32_VideoController via WMI), establishes persistence via Registry Run Keys, and communicates with C2 infrastructure over TCP using Deno's native networking.
Why this matters: every binary in the chain is legitimately signed. Organizations that allowlist developer tools or rely on reputation-based detection will not catch this. The shift to Deno — a relatively obscure runtime outside web development — creates a detection gap that most EDR configurations are not tuned for.
CVEs: CVE-2026-55040 (CVSS 9.1, JWT authentication bypass) + CVE-2026-63520 (CVSS 8.1, BCS deserialization RCE). Status: CVE-2026-55040 on CISA KEV since 18 Aug; active probing in honeypots; PoC chain publicly available.
When chained, these two vulnerabilities deliver unauthenticated remote code execution on on-premises Microsoft SharePoint Server. Approximately 329,000 instances are internet-exposed, with ~21,000 showing version information that confirms vulnerability.
Iranian APT groups — particularly Pioneer Kitten (UNC757) and APT34 — have a documented pattern of weaponizing new KEV entries within 72 hours of proof-of-concept publication. This is not a patching cycle; it is a race condition.
CVE: CVE-2026-60004. Status: CISA KEV (added 25 Aug), active exploitation deploying cryptominers, FCEB patch deadline 28 Aug.
Gitea's diffpatch API contains a critical code injection vulnerability. Authenticated users with write access can execute arbitrary shell commands. The critical detail: default Gitea installations have self-registration enabled, meaning attackers can create accounts and exploit without any prior access.
While current exploitation is limited to cryptomining, this vulnerability sits squarely in Pioneer Kitten's operational playbook — they specialize in exploiting DevOps platforms for initial access, then broker that access to ransomware operators.
CVE: CVE-2026-65105. Product: NVIDIA NemoClaw (local Ollama configuration). Status: disclosed 26 Aug; no confirmed in-the-wild exploitation yet.
This vulnerability represents something genuinely new. NemoClaw's default Ollama configuration binds to 0.0.0.0:11434 without authentication. Through DNS rebinding, an attacker can inject hidden instructions into an AI agent's model template — permanently altering its behavior without changing the model's name, size, or metadata.
A compromised AI agent could generate backdoored code, suppress security warnings, or exfiltrate sensitive data — all while appearing completely normal to operators. No standard tooling exists to detect model template poisoning. This is a strategic gap.
Four IP addresses on ASN 213790 ("Limited Network," Tehran) continue to serve dual purposes: tagged for both Cactus ransomware operations and Iranian APT activity. This crossover between state-sponsored espionage and criminal ransomware operations — targeting healthcare and manufacturing — represents the blurring of lines between Iranian state objectives and financially-motivated cybercrime.
Seven CISA ICS advisories published on 25 August also affect systems directly relevant to critical infrastructure: Siemens SIMATIC IoT2050 Advanced (missing Node-RED authentication), FURUNO FA-50 Class B AIS Transponder (device setting manipulation, maritime domain awareness impact), Ebyte NE2-D11 (unauthorized admin access), and Bendix EC80 Brake ECU (loss of ABS/steering/speedometer functions).
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Pioneer Kitten (UNC757) begins scanning for SharePoint CVE-2026-55040 | 70% | Within 5 days | Documented pattern of rapid KEV exploitation for initial access brokering |
| MuddyWater DinDoor campaign expands to defense/government targets | 50% | Within 2 weeks | Historical pattern: financial-sector testing precedes high-value targeting |
| Iranian sanctions retaliation manifests as below-threshold activity (credential harvesting, pre-positioning) | 40% | Ongoing | Diplomatic channels remain open; overt destruction risks escalation |
| SPECTRAL KITTEN/Agrius silence precedes destructive operation against Israeli energy infrastructure | 30% | 7–14 days | Operational pause pattern observed before previous destructive campaigns |
| AI model template poisoning exploited by state actor for intelligence collection | 25% | 3–6 months | Novel technique; adoption lag expected but strategic value is high |
Alert on deno.exe launched with command-line arguments containing Base64 strings >500 characters on non-developer endpoints (T1059.007) Alert on curl.exe establishing connections to deno[.]land from non-developer workstations (T1105) Alert on wscript.exe invoking .vbs files under AppData\Local\Serial\ (T1059.005) Monitor for Win32_VideoController WMI queries from scripting engines — sandbox detection behavior (T1497.001)
Monitor SharePoint IIS logs for anomalous JWT token patterns and BCS deserialization payloads (T1190, T1078) Alert on System.Web.UI.LosFormatter deserialization attempts in SharePoint request bodies (T1203) Baseline normal SharePoint authentication patterns; alert on token forgery indicators (T1134)
Monitor Gitea audit logs for new account self-registrations followed by repository write operations (T1078) Alert on shell command execution originating from Gitea diffpatch API calls (T1059) Audit all Git hooks for unauthorized modifications
Monitor network connections to port 11434 from external sources (T1016) Alert on DNS rebinding patterns targeting internal Ollama instances (T1564.001)
Additional IOCs available via Anomali ThreatStream. ---
| Threat | ATT&CK |
|---|---|
| DinDoor/Deno Runtime Abuse | T1059.007 T1105 T1059.005 T1497.001 |
| SharePoint Exploitation | T1190 T1078 T1203 T1134 |
| Gitea Exploitation | T1078 T1059 |
| AI/Ollama Security | T1016 T1564.001 |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
77.90.185[.]0/24, 185.93.89[.]0/24) or MuddyWater EtherHiding C2 infrastructure. The sanctions retaliation window may trigger dormant implant activation before it closes.deno.exe presence outside approved development environments. Check for AppData\Local\Serial\ directory creation./_api/ and BCS endpoints.- Deploy behavioral detection for deno.exe with anomalous arguments on all endpoints, particularly those in trading floors, payment processing, and SWIFT-connected segments
- Review JavaScript runtime policies — Deno may be legitimately present in some environments; detection must be context-aware (developer vs. non-developer endpoints)
- Threat hunt for historical connections to DinDoor C2 infrastructure and ASN 213790
- Audit all Siemens SIMATIC IoT2050 deployments for Node-RED authentication status; apply ICSA-26-237-03 mitigations immediately
- Segment OT networks to prevent lateral movement from IT compromise (SharePoint RCE) to ICS environments
- Increase monitoring cadence on OT network traffic for anomalous command sequences
- Block all traffic to/from ASN 213790 IP ranges at the perimeter
- Ensure SharePoint instances used for clinical coordination are patched for CVE-2026-55040/CVE-2026-63520 or isolated from internet access
- Validate backup integrity and ransomware recovery procedures given active Cactus campaign targeting
- Emergency patching of all SharePoint Server instances; if patching is not immediately possible, restrict internet-facing exposure via WAF rules blocking BCS deserialization payloads
- Audit for Gitea instances in government DevSecOps pipelines; disable self-registration; patch to 1.27.1
- Conduct a proactive hunt for Iranian pre-positioning — review 90-day network logs for connections to documented MuddyWater and Pioneer Kitten infrastructure
- Audit FURUNO FA-50 Class B AIS transponder firmware and apply vendor mitigations
- Implement integrity monitoring on AIS data feeds — alert on anomalous vessel position reports or configuration changes
- Review Bendix EC80 brake ECU exposure in fleet management systems; apply ICSA-26-237-05 mitigations
deno.exe with Base64 arguments >500 chars on non-developer endpoints; curl.exe to deno[.]land; wscript.exe invoking VBS under AppData\Local\Serial\.We are 180 days into a conflict that shows no signs of cyber de-escalation. Today's intelligence reveals Iranian operators investing in increasingly sophisticated evasion — signed-binary kill chains, AI agent poisoning, and rapid exploitation of newly disclosed vulnerabilities. The silence following Operation Economic Outcast sanctions is not peace; the 72-hour retaliation window has not yet elapsed, and the absence of detected activity reflects either restraint or concealment — neither warrants complacency. The convergence of MuddyWater's financial-sector campaign, critical SharePoint and Gitea vulnerabilities entering active exploitation, and ICS advisories affecting allied infrastructure creates a threat environment where multiple attack paths are simultaneously viable. Pioneer Kitten's historical 72-hour exploitation window for new KEVs means the SharePoint RCE chain is likely already being weaponized.