TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Operations Intensify:

Three Critical Vulnerabilities Face Active Exploitation

HIGH. We are now 138 days into an active US-Iranian conflict, and the cyber dimension is accelerating. In the past 48 hours CISA confirmed active exploitation of three critical vulnerabilities — including a perfect CVSS 10.0 in SonicWall SMA1000 — while Iranian command-and-control infrastructure refreshed with ransomware tooling that signals a convergence of state-sponsored espionage and criminal extortion. IRGC and MOIS-affiliated groups are pre-positioned, infrastructure is live, and for unpatched organizations the exploitation window is measured in hours, not weeks.

I am a
My sector

DateDevelopmentSignificance
Jul 9Fake resume / GitHub campaign targeting DIB aerospace contractors updatedTrojanized coding challenges pre-position access across the defense industrial base
Jul 10–12Iranian C2 on ASN 213790 ("Limited Network," Tehran) refreshed with Cactus ransomware + IcedID loader tagsState infrastructure now actively hosting criminal ransomware operations (confidence 91–97)
Jul 12MuddyWater / TEMP.Zagros infrastructure refreshed, then went operationally silentPattern historically consistent with retooling before a new campaign
Jul 14CVE-2026-15409 (SonicWall SMA1000, CVSS 10.0) added to CISA KEVUnauthenticated SSRF confirmed actively exploited — internal network pivot without credentials
Jul 14CISA SharePoint hardening alert — CVE-2026-45659 + CVE-2026-32201 chain confirmed exploitedSame pattern as the DHS HSIN breach disclosed Jul 8
Jul 14New ABB (Edgenius, Advant Master, T-MAC Plus) + Rockwell 1715-AENTR ICS advisoriesOT attack surface expands for Iranian proxy groups with demonstrated ICS capability
Jul 14–15US CENTCOM strikes Iranian coastal infrastructure; Iran retaliates across six Gulf statesKinetic escalation historically parallels cyber acceleration
Jul 15CVE-2026-46817 (Oracle E-Business Suite, CVSS 9.8) added to KEV with 3-day deadlineUnauthenticated RCE against Oracle Payments; remediation due Jul 18
Jul 15APT34 / OilRig reactivates toolingMOIS-affiliated espionage group operational again, coinciding with kinetic escalation
OngoingHandala / Banished Kitten silent four months since the Stryker wiper attackExtended quiet assessed as destructive pre-positioning, not retirement

PhaseTimeframeCyber Activity
Pre-escalationBefore Feb 28Baseline Iranian espionage (APT34, MuddyWater, Pioneer Kitten)
Initial escalationFeb 28 – Mar 2026US-Iran kinetic conflict begins (Day 0); Handala/Banished Kitten deploys Stryker wiper — 200,000 endpoints destroyed
Sustained operationsMay – Jul 9 2026MuddyWater credential harvesting; DHS HSIN network breach disclosed (Jul 8); fake resume/GitHub campaign targets aerospace (Jul 9)
Active retaliation windowJul 10 – 15ASN 213790 C2 refresh (Cactus + IcedID); SonicWall, SharePoint, and Oracle KEV additions; US CENTCOM strikes and Iranian retaliation across six Gulf states; APT34 reactivation
Current (Day 138)Jul 16, 2026Three confirmed active exploits; Iranian infrastructure live; MuddyWater and Handala silent in assessed retooling

Four formally attributed Iranian groups are operating in a coordinated posture, with reactivations and silences aligning directly to the July 14–15 kinetic escalation:

ActorAffiliationRoleStatus
Pioneer Kitten (Fox Kitten, UNC757)IRGCVPN/edge appliance exploitation; access handoff to ransomware operatorsTarget set directly affected by SonicWall CVE; possible persistence already achieved
Handala / Banished Kitten (Cyber Av3ngers)IRGCDestructive wiper operationsSilent four months — assessed as destructive pre-positioning
APT34 / OilRigMOISEspionage against government, energy, financial sectorsReactivated tooling Jul 15
MuddyWater / TEMP.ZagrosMOISDinDoor backdoor, Microsoft Teams-based phishingSilent since Jul 12 after infrastructure refresh — assessed retooling

The reactivations track the conflict tempo; the silences from Handala and MuddyWater are assessed not as cessation but as preparation for the next operational phase.

T1190T1566.002

The most concerning development this cycle is the convergence of Iranian state infrastructure with criminal ransomware operations. Four IPs on AS213790 — a Tehran-based hosting provider — carry simultaneous tags for Cactus ransomware, IcedID (a common ransomware precursor loader), and APT-level classification at confidence scores above 90.

This mirrors the documented Pioneer Kitten model: Iranian state actors compromise networks through VPN/edge exploitation, establish persistence, then hand off access to ransomware affiliates for monetization. The new element is Cactus replacing previously tracked INC and BlackCat partnerships. The targeting profile — healthcare, technology, government, and manufacturing — aligns precisely with Iranian strategic interests during the conflict.

T1071T1105

Three actively exploited vulnerabilities create a compounding risk across the exact attack surface Iranian APTs have historically favored:

CVEProductCVSSAttack VectorImpact
CVE-2026-15409SonicWall SMA100010.0Unauthenticated SSRFInternal network pivot
CVE-2026-46817Oracle E-Business Suite9.8Unauthenticated RCEPayment workflow takeover
CVE-2026-45659Microsoft SharePoint8.8Deserialization RCEWeb shell deployment
CVE-2026-32201Microsoft SharePoint6.5Input validation spoofingCredential theft chain

The DHS HSIN breach (disclosed Jul 8) used SharePoint exploitation patterns; Pioneer Kitten's entire model centers on edge appliance compromise; and Oracle E-Business Suite serves DIB contractors for financial operations.

T1190T1505.003

New advisories for ABB Ability Edgenius (CVE-2026-31431, CVSS 7.8), ABB Advant Master, ABB T-MAC Plus, and Rockwell 1715-AENTR EtherNet/IP adapters expand the operational technology attack surface. The Rockwell vulnerability is particularly concerning — it allows an attacker to read/delete files, stop tasks, modify memory, and change I/O on industrial control systems.

Iranian proxy groups (Cyber Av3ngers) have previously demonstrated both willingness and capability to target ICS/OT systems. These advisories represent new potential entry points.

T0816T0839

A CISA advisory (AA26-194A) on Russian FSB Center 16 exploitation of poorly configured routers adds another dimension. IPs on Iranian AS213790 carry APT28 (Russian) tags alongside Iranian APT indicators.

While the Russia-Iran cyber relationship remains circumstantial, shared infrastructure between Russian and Iranian operations creates attribution challenges and expands the threat surface for defenders.

ScenarioProbabilityTimeframeIndicators to Watch
Pioneer Kitten exploits CVE-2026-15409 against allied networks75%7 daysEdge-appliance web shells; CVSS 10.0 confirmed exploited; 72-hour window
MuddyWater / TEMP.Zagros launches a new campaign65%7 daysInfrastructure refresh + operational silence; historical weekly tempo
Cactus ransomware incident with an Iranian infrastructure nexus40%7 daysHigh-confidence IOCs active on Iranian ASN; healthcare/technology targeting
Handala / Cyber Av3ngers destructive (wiper) operation30–40%7 daysFour-month silence consistent with pre-positioning; kinetic escalation provides motive
Oracle E-Business Suite exploitation against DIB financial systems35%7 daysKEV-confirmed; DIB contractors use Oracle Payments; no actor attribution yet
ICS/OT targeted attack against energy infrastructure25%7 daysNew ABB/Rockwell vulns expand surface; Cyber Av3ngers has demonstrated ICS capability

Note: hacktivist activity probability is currently unassessable due to a 6-day intelligence collection gap affecting Telegram channel monitoring — the primary communication medium for pro-Iran hacktivist groups.

RuleData SourceATT&CKPriority
SonicWall SMA1000 SSRF — internal network requests originating from the appliance management interfaceFirewall/Web logsT1190CRITICAL
Outbound to confirmed Iranian C2 (AS213790) — any communication to this ASNFirewall/NetflowT1071CRITICAL
New .aspx web shells in non-standard SharePoint directories created after Jun 2026File integrity/Web logsT1505.003CRITICAL
Oracle E-Business Suite HTTP requests to the Payments module from unexpected source IPsWAF/Web logsT1190HIGH
IcedID loader activity — documented precursor to Cactus ransomware deploymentEDRT1105HIGH
Rockwell 1715-AENTR unauthorized file operations, task modifications, or memory changesICS monitoringT0839MEDIUM
IOC Blocking Table:
185.93.89[.]43185.93.89[.]7577.90.185[.]118192.253.248[.]1805.160.228[.]1862.188.214[.]14262.60.130[.]23737.148.2[.]228

First four IPs are Iranian C2 on AS213790 ("Limited Network," Tehran); 5.160.228[.]186 and 2.188.214[.]142 on AS42337 (Rampant Kitten/TeleSpy); remaining IPs on AS215930 and AS205647. Verified SHA-256 hashes for Iranian APT tooling tracked this cycle have been withheld pending source verification — query Anomali ThreatStream and partner feeds for the latest confirmed indicators tagged to AS213790, MuddyWater/TEMP.Zagros, Pioneer Kitten, and Cactus ransomware campaigns.

Hunting Hypotheses:
HUNT 01 · T1505.003
Pioneer Kitten web shells on edge appliances
Has Pioneer Kitten already compromised edge appliances and deployed web shells before patches were available? Search VPN/edge appliances and SharePoint for new .aspx/.php files created post-patch.
HUNT 02 · T1566.002
MuddyWater Teams/OAuth reconnaissance
Is MuddyWater conducting reconnaissance via Microsoft Teams and OAuth? Check Azure AD sign-in and Teams audit logs for unusual OAuth consent grants and messages from external tenants.
HUNT 03 · T1567
Cactus data staging before encryption
Are Cactus operators staging data exfiltration before encryption? Review NetFlow, DLP alerts, and proxy logs for large outbound transfers to cloud storage or non-standard ports.
HUNT 04 · T1078
Valid credentials from SharePoint exploitation
Are Iranian actors using valid credentials obtained via SharePoint exploitation? Check authentication logs and impossible-travel alerts for logins from Iranian IP ranges or VPN exit nodes after SharePoint compromise.
HUNT 05 · T1053.005
Handala dormant implants
Is Handala pre-positioning via dormant implants? Search scheduled-task creation and startup-folder monitoring for tasks with future execution dates and encoded PowerShell payloads.

Financial Services
Payment & Transaction Systems
Primary threats
CVE-2026-46817 (Oracle E-Business Suite, CVSS 9.8) directly targets Oracle Payments — enabling unauthenticated takeover of payment workflows: wire fraud, transaction manipulation, and financial data theft without prior access.
Actions
  • Patch Oracle E-Business Suite by Jul 18 (CISA deadline) — no exceptions
  • Implement application-layer monitoring on Oracle Payments HTTP endpoints for anomalous request patterns
  • Review all Oracle E-Business Suite instances for internet exposure — these should never be directly accessible
  • Enable transaction anomaly detection — flag unusual payment amounts, destinations, or timing
  • Cross-reference authentication logs against Iranian IP ranges (AS213790, AS42337)
Energy
Grid, ICS/OT
Primary threats
ABB and Rockwell ICS vulnerabilities expand the OT attack surface as Cyber Av3ngers demonstrate intent and capability against energy infrastructure. CVE-2026-31431 affects ABB Ability Edgenius (CVSS 7.8); Rockwell 1715-AENTR allows unauthorized file operations and memory modification.
Actions
  • Audit all ABB Edgenius, Advant Master, and T-MAC Plus deployments for patch status (CVE-2026-31431)
  • Restrict Rockwell 1715-AENTR management interfaces to dedicated OT management VLANs — no IT network access
  • Implement unidirectional gateways (data diodes) between IT and OT networks where not already deployed
  • Review Purdue Model segmentation — ensure the Level 3.5 DMZ is enforced
  • Conduct a tabletop exercise for an ICS wiper scenario based on Handala's demonstrated capabilities
Healthcare
EHR & IoMT Systems
Primary threats
Iranian-hosted infrastructure (AS213790) explicitly targets healthcare with Cactus ransomware and IcedID loaders at confidence 91–97. The Pioneer Kitten → ransomware handoff means state-sponsored initial access may precede criminal encryption.
Actions
  • Block all traffic to/from AS213790 at the network perimeter immediately
  • Deploy IcedID detection signatures — the documented precursor to Cactus ransomware
  • Ensure offline backups of EHR systems are current and tested (recovery time < 4 hours)
  • Review medical device segmentation — IoMT devices should not be reachable from compromised IT systems
  • Activate the ransomware IR playbook to "warm standby" — pre-stage communications templates and vendor contacts
Government
SharePoint, Edge, .gov Apps
Primary threats
Multi-vector targeting: SharePoint exploitation (confirmed in the DHS HSIN breach), edge appliance compromise (SonicWall CVSS 10.0), and MuddyWater credential harvesting via Teams/OAuth phishing. Government networks face the full spectrum of Iranian espionage.
Actions
  • Emergency patching: SonicWall SMA1000, SharePoint (CVE-2026-45659 + CVE-2026-32201), Oracle E-Business Suite
  • Audit all SharePoint instances for prior compromise — web shells, unexpected service accounts, anomalous uploads since Jun 2026
  • Implement conditional access policies blocking authentication from Iranian ASNs
  • Review OAuth application consent grants in Microsoft Entra ID — revoke suspicious third-party permissions
  • Enable enhanced audit logging for Exchange Web Services (EWS) API calls — APT34 historically uses this for C2
Aviation / Logistics
DIB Contractors, Aerospace
Primary threats
An active fake resume/GitHub campaign (last updated Jul 9) targets the aerospace sector via supply chain compromise, using trojanized coding challenges and GitHub repositories to deliver malware to engineers and developers at DIB contractors.
Actions
  • Brief recruiting and engineering teams on the fake resume/GitHub TTP — verify all coding-challenge repositories before execution
  • Implement application allowlisting on developer workstations — prevent execution of unsigned binaries from downloaded repositories
  • Monitor GitHub Enterprise for unusual cloning patterns or new external collaborator additions
  • Review CI/CD pipelines for unauthorized GitHub Actions or dependencies — pin all actions to commit SHAs
  • Segment developer environments from production networks and sensitive program data
No sector cards match the selected filters.

Patch SonicWall SMA1000 for CVE-2026-15409 (CVSS 10.0). If patching is impossible within 24 hours, disconnect the appliance — there is no safe "monitor and wait" posture for a CVSS 10.0 under active exploitation.
Incident Responder
Patch Oracle E-Business Suite for CVE-2026-46817 (CVSS 9.8). CISA deadline is Jul 18. Prioritize any internet-facing Oracle Payments instances.
Incident Responder
Apply SharePoint cumulative updates addressing CVE-2026-45659 (CVSS 8.8) and CVE-2026-32201 (CVSS 6.5) — active exploitation chain confirmed.
Incident Responder
Deploy perimeter blocks for confirmed Iranian C2: 185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]180, 5.160.228[.]186, 2.188.214[.]142, 62.60.130[.]237, 37.148.2[.]228.
SOC Analyst
Hunt for web shells on all SonicWall and SharePoint instances — Pioneer Kitten may have exploited these before patches were available.
Threat Hunter
Pre-authorize emergency patching for future CISA KEV additions affecting your edge appliance fleet — the 3-day Oracle deadline shows normal change management is incompatible with current threat tempo.
CISO / Exec
No immediate actions for the selected roles.
Deploy detection rules for the Cactus initial-access chain: IcedID loader → lateral movement → Cactus deployment. Correlate ransomware precursor activity against Iranian ASN communications.
SOC Analyst
Restrict Rockwell 1715-AENTR management to an OT management VLAN only, and apply firmware updates. Verify IT/OT segmentation isolates ABB and Rockwell systems from corporate networks.
ICS / OT
Review all OAuth application consent grants in Microsoft Entra ID. Revoke any applications granted consent after May 2026 that are not on an approved list.
IAM Analyst
Implement ASN-level alerting for any traffic to/from AS213790 that bypasses perimeter blocks (e.g., VPN split tunneling or cloud egress).
SOC Analyst
Activate crisis communications templates for ransomware and wiper scenarios, and establish direct contact with CISA regional representatives and sector ISACs — information-sharing speed determines defensive advantage during active conflict.
CISO / ExecIncident Responder
No 7-day actions for the selected roles.
Deploy redundant threat intelligence collection — add Telegram monitoring for Handala, Cyber Toufan, and DieNet, plus geopolitical RSS feeds to compensate for OSINT collection gaps.
Threat Hunter
Commission an external red team assessment simulating Pioneer Kitten's edge-appliance-to-ransomware-handoff attack chain against your environment.
CISO / Exec
Conduct a destructive-wiper tabletop modeling Handala's Stryker attack (200,000 endpoints destroyed). Test backup restoration, communication plans, and business continuity.
Incident Responder
Confirm cyber insurance coverage explicitly addresses nation-state attacks — many policies exclude "acts of war," and the US-Iran conflict creates coverage ambiguity.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

138 days into this conflict, the pattern is unmistakable: Iranian cyber operations are not slowing — they are maturing. The convergence of state-sponsored access with criminal ransomware infrastructure means organizations face both espionage and extortion from the same initial compromise. Three CVSS 9.0+ vulnerabilities under active exploitation, combined with a confirmed Iranian C2 refresh, create an environment where unpatched systems will be compromised — not might be, will be. The operational silence from MuddyWater and Handala is not reassurance. It is preparation.

1
Have you patched SonicWall SMA1000, Oracle E-Business Suite, and SharePoint? A CVSS 10.0 under active exploitation has no safe "monitor and wait" posture.
2
Have you blocked AS213790 and the confirmed Iranian C2 IPs? State infrastructure is now hosting Cactus ransomware operations.
3
Do you have a wiper response plan? Handala has been silent for four months. That silence should concern you more than noise would.
No items found.