| Date | Development | Significance |
|---|---|---|
| Jul 9 | Fake resume / GitHub campaign targeting DIB aerospace contractors updated | Trojanized coding challenges pre-position access across the defense industrial base |
| Jul 10–12 | Iranian C2 on ASN 213790 ("Limited Network," Tehran) refreshed with Cactus ransomware + IcedID loader tags | State infrastructure now actively hosting criminal ransomware operations (confidence 91–97) |
| Jul 12 | MuddyWater / TEMP.Zagros infrastructure refreshed, then went operationally silent | Pattern historically consistent with retooling before a new campaign |
| Jul 14 | CVE-2026-15409 (SonicWall SMA1000, CVSS 10.0) added to CISA KEV | Unauthenticated SSRF confirmed actively exploited — internal network pivot without credentials |
| Jul 14 | CISA SharePoint hardening alert — CVE-2026-45659 + CVE-2026-32201 chain confirmed exploited | Same pattern as the DHS HSIN breach disclosed Jul 8 |
| Jul 14 | New ABB (Edgenius, Advant Master, T-MAC Plus) + Rockwell 1715-AENTR ICS advisories | OT attack surface expands for Iranian proxy groups with demonstrated ICS capability |
| Jul 14–15 | US CENTCOM strikes Iranian coastal infrastructure; Iran retaliates across six Gulf states | Kinetic escalation historically parallels cyber acceleration |
| Jul 15 | CVE-2026-46817 (Oracle E-Business Suite, CVSS 9.8) added to KEV with 3-day deadline | Unauthenticated RCE against Oracle Payments; remediation due Jul 18 |
| Jul 15 | APT34 / OilRig reactivates tooling | MOIS-affiliated espionage group operational again, coinciding with kinetic escalation |
| Ongoing | Handala / Banished Kitten silent four months since the Stryker wiper attack | Extended quiet assessed as destructive pre-positioning, not retirement |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before Feb 28 | Baseline Iranian espionage (APT34, MuddyWater, Pioneer Kitten) |
| Initial escalation | Feb 28 – Mar 2026 | US-Iran kinetic conflict begins (Day 0); Handala/Banished Kitten deploys Stryker wiper — 200,000 endpoints destroyed |
| Sustained operations | May – Jul 9 2026 | MuddyWater credential harvesting; DHS HSIN network breach disclosed (Jul 8); fake resume/GitHub campaign targets aerospace (Jul 9) |
| Active retaliation window | Jul 10 – 15 | ASN 213790 C2 refresh (Cactus + IcedID); SonicWall, SharePoint, and Oracle KEV additions; US CENTCOM strikes and Iranian retaliation across six Gulf states; APT34 reactivation |
| Current (Day 138) | Jul 16, 2026 | Three confirmed active exploits; Iranian infrastructure live; MuddyWater and Handala silent in assessed retooling |
Four formally attributed Iranian groups are operating in a coordinated posture, with reactivations and silences aligning directly to the July 14–15 kinetic escalation:
| Actor | Affiliation | Role | Status |
|---|---|---|---|
| Pioneer Kitten (Fox Kitten, UNC757) | IRGC | VPN/edge appliance exploitation; access handoff to ransomware operators | Target set directly affected by SonicWall CVE; possible persistence already achieved |
| Handala / Banished Kitten (Cyber Av3ngers) | IRGC | Destructive wiper operations | Silent four months — assessed as destructive pre-positioning |
| APT34 / OilRig | MOIS | Espionage against government, energy, financial sectors | Reactivated tooling Jul 15 |
| MuddyWater / TEMP.Zagros | MOIS | DinDoor backdoor, Microsoft Teams-based phishing | Silent since Jul 12 after infrastructure refresh — assessed retooling |
The reactivations track the conflict tempo; the silences from Handala and MuddyWater are assessed not as cessation but as preparation for the next operational phase.
The most concerning development this cycle is the convergence of Iranian state infrastructure with criminal ransomware operations. Four IPs on AS213790 — a Tehran-based hosting provider — carry simultaneous tags for Cactus ransomware, IcedID (a common ransomware precursor loader), and APT-level classification at confidence scores above 90.
This mirrors the documented Pioneer Kitten model: Iranian state actors compromise networks through VPN/edge exploitation, establish persistence, then hand off access to ransomware affiliates for monetization. The new element is Cactus replacing previously tracked INC and BlackCat partnerships. The targeting profile — healthcare, technology, government, and manufacturing — aligns precisely with Iranian strategic interests during the conflict.
Three actively exploited vulnerabilities create a compounding risk across the exact attack surface Iranian APTs have historically favored:
| CVE | Product | CVSS | Attack Vector | Impact |
|---|---|---|---|---|
CVE-2026-15409 | SonicWall SMA1000 | 10.0 | Unauthenticated SSRF | Internal network pivot |
CVE-2026-46817 | Oracle E-Business Suite | 9.8 | Unauthenticated RCE | Payment workflow takeover |
CVE-2026-45659 | Microsoft SharePoint | 8.8 | Deserialization RCE | Web shell deployment |
CVE-2026-32201 | Microsoft SharePoint | 6.5 | Input validation spoofing | Credential theft chain |
The DHS HSIN breach (disclosed Jul 8) used SharePoint exploitation patterns; Pioneer Kitten's entire model centers on edge appliance compromise; and Oracle E-Business Suite serves DIB contractors for financial operations.
New advisories for ABB Ability Edgenius (CVE-2026-31431, CVSS 7.8), ABB Advant Master, ABB T-MAC Plus, and Rockwell 1715-AENTR EtherNet/IP adapters expand the operational technology attack surface. The Rockwell vulnerability is particularly concerning — it allows an attacker to read/delete files, stop tasks, modify memory, and change I/O on industrial control systems.
Iranian proxy groups (Cyber Av3ngers) have previously demonstrated both willingness and capability to target ICS/OT systems. These advisories represent new potential entry points.
A CISA advisory (AA26-194A) on Russian FSB Center 16 exploitation of poorly configured routers adds another dimension. IPs on Iranian AS213790 carry APT28 (Russian) tags alongside Iranian APT indicators.
While the Russia-Iran cyber relationship remains circumstantial, shared infrastructure between Russian and Iranian operations creates attribution challenges and expands the threat surface for defenders.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Pioneer Kitten exploits CVE-2026-15409 against allied networks | 75% | 7 days | Edge-appliance web shells; CVSS 10.0 confirmed exploited; 72-hour window |
| MuddyWater / TEMP.Zagros launches a new campaign | 65% | 7 days | Infrastructure refresh + operational silence; historical weekly tempo |
| Cactus ransomware incident with an Iranian infrastructure nexus | 40% | 7 days | High-confidence IOCs active on Iranian ASN; healthcare/technology targeting |
| Handala / Cyber Av3ngers destructive (wiper) operation | 30–40% | 7 days | Four-month silence consistent with pre-positioning; kinetic escalation provides motive |
| Oracle E-Business Suite exploitation against DIB financial systems | 35% | 7 days | KEV-confirmed; DIB contractors use Oracle Payments; no actor attribution yet |
| ICS/OT targeted attack against energy infrastructure | 25% | 7 days | New ABB/Rockwell vulns expand surface; Cyber Av3ngers has demonstrated ICS capability |
Note: hacktivist activity probability is currently unassessable due to a 6-day intelligence collection gap affecting Telegram channel monitoring — the primary communication medium for pro-Iran hacktivist groups.
| Rule | Data Source | ATT&CK | Priority |
|---|---|---|---|
| SonicWall SMA1000 SSRF — internal network requests originating from the appliance management interface | Firewall/Web logs | T1190 | CRITICAL |
Outbound to confirmed Iranian C2 (AS213790) — any communication to this ASN | Firewall/Netflow | T1071 | CRITICAL |
New .aspx web shells in non-standard SharePoint directories created after Jun 2026 | File integrity/Web logs | T1505.003 | CRITICAL |
| Oracle E-Business Suite HTTP requests to the Payments module from unexpected source IPs | WAF/Web logs | T1190 | HIGH |
| IcedID loader activity — documented precursor to Cactus ransomware deployment | EDR | T1105 | HIGH |
| Rockwell 1715-AENTR unauthorized file operations, task modifications, or memory changes | ICS monitoring | T0839 | MEDIUM |
First four IPs are Iranian C2 on AS213790 ("Limited Network," Tehran); 5.160.228[.]186 and 2.188.214[.]142 on AS42337 (Rampant Kitten/TeleSpy); remaining IPs on AS215930 and AS205647. Verified SHA-256 hashes for Iranian APT tooling tracked this cycle have been withheld pending source verification — query Anomali ThreatStream and partner feeds for the latest confirmed indicators tagged to AS213790, MuddyWater/TEMP.Zagros, Pioneer Kitten, and Cactus ransomware campaigns.
.aspx/.php files created post-patch.- Patch Oracle E-Business Suite by Jul 18 (CISA deadline) — no exceptions
- Implement application-layer monitoring on Oracle Payments HTTP endpoints for anomalous request patterns
- Review all Oracle E-Business Suite instances for internet exposure — these should never be directly accessible
- Enable transaction anomaly detection — flag unusual payment amounts, destinations, or timing
- Cross-reference authentication logs against Iranian IP ranges (AS213790, AS42337)
- Audit all ABB Edgenius, Advant Master, and T-MAC Plus deployments for patch status (CVE-2026-31431)
- Restrict Rockwell 1715-AENTR management interfaces to dedicated OT management VLANs — no IT network access
- Implement unidirectional gateways (data diodes) between IT and OT networks where not already deployed
- Review Purdue Model segmentation — ensure the Level 3.5 DMZ is enforced
- Conduct a tabletop exercise for an ICS wiper scenario based on Handala's demonstrated capabilities
- Block all traffic to/from AS213790 at the network perimeter immediately
- Deploy IcedID detection signatures — the documented precursor to Cactus ransomware
- Ensure offline backups of EHR systems are current and tested (recovery time < 4 hours)
- Review medical device segmentation — IoMT devices should not be reachable from compromised IT systems
- Activate the ransomware IR playbook to "warm standby" — pre-stage communications templates and vendor contacts
- Emergency patching: SonicWall SMA1000, SharePoint (CVE-2026-45659 + CVE-2026-32201), Oracle E-Business Suite
- Audit all SharePoint instances for prior compromise — web shells, unexpected service accounts, anomalous uploads since Jun 2026
- Implement conditional access policies blocking authentication from Iranian ASNs
- Review OAuth application consent grants in Microsoft Entra ID — revoke suspicious third-party permissions
- Enable enhanced audit logging for Exchange Web Services (EWS) API calls — APT34 historically uses this for C2
- Brief recruiting and engineering teams on the fake resume/GitHub TTP — verify all coding-challenge repositories before execution
- Implement application allowlisting on developer workstations — prevent execution of unsigned binaries from downloaded repositories
- Monitor GitHub Enterprise for unusual cloning patterns or new external collaborator additions
- Review CI/CD pipelines for unauthorized GitHub Actions or dependencies — pin all actions to commit SHAs
- Segment developer environments from production networks and sensitive program data
185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]180, 5.160.228[.]186, 2.188.214[.]142, 62.60.130[.]237, 37.148.2[.]228.138 days into this conflict, the pattern is unmistakable: Iranian cyber operations are not slowing — they are maturing. The convergence of state-sponsored access with criminal ransomware infrastructure means organizations face both espionage and extortion from the same initial compromise. Three CVSS 9.0+ vulnerabilities under active exploitation, combined with a confirmed Iranian C2 refresh, create an environment where unpatched systems will be compromised — not might be, will be. The operational silence from MuddyWater and Handala is not reassurance. It is preparation.