| Date | Development | Significance |
|---|---|---|
| Aug 4, 2026 | CyberAv3ngers (IRGC-CEC) confirmed responsible for attacks on 36+ Minnesota water utilities and facilities in 6 additional states | Largest confirmed Iranian ICS attack on U.S. soil — physical outages achieved |
| Aug 11, 2026 | CVE-2026-20349 (Cisco ASA/FTD SSL VPN DoS) added to CISA Known Exploited Vulnerabilities catalog | Active exploitation confirmed; unauthenticated remote device crash |
| Aug 11, 2026 | Fresh Cactus ransomware sample dropped on Iranian infrastructure (ASN 213790) | MuddyWater/Cactus nexus continues daily infrastructure refresh — active campaign |
| Aug 12, 2026 | Pioneer Kitten (UNC757/Fox Kitten) actor profile updated | Renewed activity signals after Fortinet/Cisco exploitation history |
| Aug 13, 2026 | Fortinet patches FortiWeb and FortiManager authentication bypass flaws | Login with random credentials possible — Pioneer Kitten exploits Fortinet within days of disclosure historically |
| Aug 13, 2026 | TRACER KITTEN (Greenbug/MOIS) profile refreshed after months of silence | Telecom CDR espionage campaign with kinetic targeting implications |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict escalation begins | Feb 28, 2026 | U.S.-Iran kinetic conflict escalation begins; cyber retaliation cycle initiated. |
| New malware against Israeli targets | Mar–Apr 2026 | HYDRO KITTEN (CyberAv3ngers) deploys ZodiacRAT and ScratchWiper against an Israeli engineering firm — new malware families confirmed. |
| U.S. water utility campaign begins | Jul 26, 2026 | Coordinated cyberattacks begin against U.S. water facilities — PLC manipulation, service disruptions. |
| Physical outages confirmed & corroborated | Aug 1–6, 2026 | Political attribution denial despite IC consensus (Aug 1); FBI/EPA joint alert confirms 36 Minnesota utilities compromised, physical water outages across 6+ states (Aug 4); CSIS publishes open-source corroboration of IRGC-CEC attribution (Aug 6). |
| Infrastructure refresh & VPN exploitation | Aug 10–13, 2026 | ASN 213790 (Tehran) infrastructure refreshed with new malware hash, healthcare/manufacturing targeting (Aug 10–12); CVE-2026-20349 added to CISA KEV, Cisco ASA/FTD actively exploited (Aug 11); Fortinet patches FortiWeb/FortiManager auth bypass, critical patch window opens (Aug 13). |
This is the most operationally significant Iranian cyber unit currently active against U.S. targets. Tracked by CrowdStrike as HYDRO KITTEN, by Dragos as BAUXITE, and publicly known as CyberAv3ngers, this IRGC-CEC unit has compromised 36+ water utilities in Minnesota alone, with additional facilities in at least 6 other states, and manipulated PLCs (historically Unitronics Vision series, Allen-Bradley/Rockwell) to alter water treatment parameters.
The group has deployed new malware — ZodiacRAT (Go-based RAT with HTTP/HTTPS C2) and ScratchWiper (C++ destructive wiper) — and exploited 20+ CVEs including CVE-2024-41713, CVE-2024-47575, CVE-2025-0282, CVE-2024-53704, CVE-2024-55591, and CVE-2021-22681 (Rockwell PLC authentication bypass). Additional tooling includes IOControl (custom ICS backdoor) and Crucio (ransomware).
Critical escalation indicator: HYDRO KITTEN possesses confirmed wiper capability (ScratchWiper) but has so far limited U.S. operations to disruption rather than destruction. This restraint may not hold if kinetic escalation continues. Wiper deployment against U.S. critical infrastructure would represent a significant threshold crossing.
Infrastructure on ASN 213790 ("Limited Network," Tehran) continues daily refresh cycles. This convergence of state-sponsored tooling and ransomware operations targets healthcare, manufacturing, and technology sectors. The operational model: MuddyWater provides initial access; Cactus ransomware operators monetize or destroy.
Key infrastructure nodes remain active as of August 12, 2026, with a fresh Cactus sample created August 11.
Updated August 12, this actor has a documented pattern of exploiting Fortinet and Cisco vulnerabilities within days of public disclosure. The August 13 Fortinet FortiWeb/FortiManager authentication bypass — which allows login with random usernames and passwords — falls squarely within Pioneer Kitten's exploitation playbook. Historical precedent: CVE-2024-55591 (Fortinet) and CVE-2024-53704 (SonicWall) were weaponized rapidly.
After months of silence, this MOIS-affiliated actor's profile was refreshed August 13, signaling renewed telecom Call Data Record (CDR) espionage operations. CDR collection has kinetic targeting implications — identifying the physical locations and communication patterns of military and intelligence personnel.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Continued water sector targeting in additional U.S. states | >75% (HIGH) | 7 days | New state-level utility outage reports; Unitronics/Rockwell PLC scanning |
| Fortinet FortiWeb/FortiManager auth bypass exploited by Iranian actors | 50–60% (MODERATE-HIGH) | 72 hours | Anomalous FortiWeb logins; FortiManager device impersonation |
| Cactus ransomware deployment against healthcare organizations via ASN 213790 infrastructure | 60–70% (MODERATE-HIGH) | 14 days | Connections to 77.90.185.x or 185.93.89.x ranges; Cactus TTP patterns |
| ScratchWiper destructive attack against U.S. critical infrastructure | 30–40% (LOW-MODERATE) | 30 days | ScratchWiper or Crucio samples targeting non-Israeli infrastructure |
| CVE-2026-20349 exploitation by Iranian actors for VPN access denial | >65% (MODERATE-HIGH) | 7 days | Cisco ASA/FTD unexpected reloads; crafted HTTP to VPN portals |
| APT42 credential phishing campaign resurgence targeting policy makers | 40–50% (MODERATE) | 14 days | NICECURL/TAMECAT/AnvilEcho deployment; spear-phishing from spoofed think tanks |
Hunt for any historical or active connections to confirmed Iranian C2 nodes. These IPs are associated with SystemBC (SOCKS5 proxy), DarkComet RAT, and Cactus ransomware operations: Query SIEM/NDR for connections to ASN 213790 ("Limited Network," Tehran) and ASN 214351 ("Femo IT Solutions") Alert on any beaconing patterns to the IOCs listed in the blocking table below
Monitor Cisco ASA/FTD devices for unexpected reloads or crash dumps — indicator of CVE-2026-20349 exploitation Monitor FortiWeb for logins from unknown usernames; monitor FortiManager for unregistered FortiGate device connections
Alert on any internet-originating traffic to PLC management ports (TCP 502/Modbus, TCP 44818/EtherNet/IP, TCP 20256/Unitronics PCOM) Monitor for PLC logic changes outside maintenance windows Detect batch script execution or service creation on HMI/engineering workstations
Hunt for Cactus ransomware TTPs: command injection via web applications, service execution for payload deployment, non-standard port C2 Alert on new Windows services created via sc.exe or schtasks on servers with healthcare/manufacturing data
| Threat | ATT&CK |
|---|---|
| 1. Iranian C2 Infrastructure Monitoring | T1071.001 T1573 T1090.002 T1219 |
| 2. VPN Infrastructure Integrity | T1190 T1078 T1499.004 |
| 3. ICS/OT Anomaly Detection | T1190 T0831 T0836 |
| 4. Ransomware Pre-Cursor Activity | T1195.002 T1059 T1569.002 |
Block the above at perimeter firewalls, proxies, and DNS. Hashes: 90b89a6dc4565c9817e7db8323702006860cb2b49f352863f2b18ba21c66b435, 6729c71328ce8498c26e6a46b7ba2fe84c611814d92703bdc2c1ebb7339d43fd, 0179ad14c9df5141b4479688d0135aa2132e1605dbd7852a2fac7ed543e53138, 70a779123b6faca3cec3fc8872717e55. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Audit all Fortinet and Cisco VPN appliances for patch currency
- Implement conditional access policies that detect impossible-travel logins to treasury and wire transfer systems
- Monitor for SystemBC SOCKS5 proxy traffic that could indicate lateral movement toward SWIFT or payment processing systems
- Segment all OT networks from IT with unidirectional gateways where possible
- Audit ABB Zenon HMI installations per CISA ICS advisory
- Verify no Rockwell/Allen-Bradley PLCs are internet-accessible
- Implement OT-specific anomaly detection for Modbus/EtherNet-IP protocol deviations
- Block all ASN 213790 IP ranges at the network edge
- Ensure offline backups of EHR systems are current and tested
- Deploy EDR rules for the Cactus hashes listed in the IOC blocking table
- Conduct tabletop exercise for ransomware scenario affecting patient care systems
- Emergency patch Cisco ASA/FTD (CVE-2026-20349) and Fortinet appliances
- Implement phishing-resistant MFA (FIDO2) for all privileged accounts
- Audit telecom provider security for CDR protection
- Hunt for anomalous OAuth token grants in M365/Azure AD environments
- Assess exposure of Controller-Pilot Data Link Communications systems
- Verify integrity of flight management system update chains
- Monitor for anomalous ADS-B or ACARS traffic patterns
- Ensure air-gapped backup navigation procedures are exercised
We are 165 days into a sustained Iranian cyber offensive against U.S. and allied infrastructure. The IRGC has demonstrated both the capability and the intent to cause physical disruption to civilian services. The current operational pattern — PLC manipulation causing water outages without permanent physical destruction — represents a deliberate calibration of escalation. But the tools for destruction (ScratchWiper, Crucio) are built, tested, and deployed. The distance between "disruption" and "destruction" is a single command. Your Cisco ASA and Fortinet appliances need to be patched today. Your OT networks need to be audited this week. Your board needs to understand that this is not a hypothetical risk — it is an active military operation being conducted against civilian infrastructure.