TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Operations Maintain Steady-State Siege:

VPN Exploitation, Telecom Espionage, and Healthcare Targeting Intensify at Day 165

CRITICAL. Maintained from the prior cycle. 165 days into the U.S.-Iran kinetic conflict, Iranian state-sponsored cyber operations are diversifying rather than fatiguing. CISA has added an actively exploited Cisco ASA/FTD VPN vulnerability to its KEV catalog, TRACER KITTEN's telecom espionage group has resurfaced after months of silence, and Iranian infrastructure on ASN 213790 now converges state espionage with Cactus ransomware — with one IP explicitly tagged for healthcare targeting.

I am a
My sector

DevelopmentDateSignificance
CVE-2026-20349 (Cisco ASA/FTD SSL VPN DoS) added to CISA KEV2026-08-11Active exploitation confirmed. Unauthenticated remote device reload. Iranian actors historically chain VPN disruption with credential-based follow-on access.
TRACER KITTEN (Greenbug/MOIS) profile refreshed2026-08-11First update in months for this telecom-targeting espionage group. Signals renewed Call Data Record (CDR) collection campaign — a precursor to kinetic targeting.
UNC5203/Handala (IRGC) profile updated2026-08-12Primary Iranian destructive/wiper actor remains actively tracked. Targets energy, financial services, government, telecom, and utilities.
Cobalt Strike "Agentemis" C2 confirmed active on Iranian ASN 444362026-08-06–08-12DNS tunneling on port 53 — deliberate evasion of standard HTTPS-focused detection.
ASN 213790 infrastructure (5 IPs) refreshed with healthcare targeting2026-08-10–08-11Cactus ransomware + state-sponsored tooling convergence. Healthcare explicitly added as target vertical.
Johnson Controls C-CURE 9000 RCE advisory published2026-08-11Remote code execution in physical access control systems used in government/military facilities.
ABB Ability Zenon ICS vulnerabilities disclosed2026-08-06SCADA/HMI platform used in energy, water, and manufacturing — bypass, crash, and unauthorized execution flaws.

PhaseTimeframeCyber Activity
Conflict initiationFeb 28, 2026U.S.-Iran kinetic conflict begins (Day 0).
Multi-state water utility campaignJul 26 – Aug 5, 2026CyberAv3ngers (IRGC) launches and confirms the largest Iranian ICS attack on U.S. soil — PLC manipulation across 36+ water facilities in 7 states; UNC5866 (Emennet Pasargad) profile updated with unusual manufacturing/retail sector expansion.
ICS advisories & C2 infrastructure build-outAug 6–10, 2026ABB Ability Zenon SCADA advisory published; Cobalt Strike "Agentemis" C2 confirmed active on Iranian ASN 44436 (DNS tunneling, port 53); Mythic C2 server confirmed on ASN 60631; ASN 213790 infrastructure refreshed with Cactus ransomware and healthcare targeting.
Perimeter exploitation & espionage resurgenceAug 11, 2026CVE-2026-20349 (Cisco ASA/FTD VPN DoS) added to CISA KEV with active exploitation confirmed; TRACER KITTEN (Greenbug/MOIS) telecom espionage profile refreshed after months of silence; Johnson Controls C-CURE 9000 physical access control RCE advisory published.
Current (Day 165)Aug 12, 2026UNC5203/Handala (IRGC) destructive/wiper profile updated, maintaining readiness across energy, financial services, government, technology, telecom, and utilities.

CVE-2026-20349 is an unauthenticated denial-of-service vulnerability (CVSS 8.6) in the Remote Access SSL VPN service of Cisco ASA and Firepower Threat Defense (FTD) appliances. A crafted HTTP request causes a full device reload.

Why this matters beyond DoS: Iranian actors — particularly Pioneer Kitten (Fox Kitten) — have a documented pattern of exploiting perimeter VPN/firewall vulnerabilities, establishing persistent access, and then either conducting espionage or selling that access to ransomware operators. This is not merely a service disruption risk; it is the first step in a kill chain that ends with ransomware deployment or data destruction.

Combined with the earlier CVE-2026-20316 (Cisco FMC static credentials), this represents a sustained campaign against Cisco perimeter infrastructure. Organizations running Cisco ASA or FTD with Remote Access VPN enabled are at immediate risk.

T1190T1499.004

TRACER KITTEN (also known as Greenbug) is a MOIS-linked espionage group that has targeted telecommunications providers in the Middle East and South Asia since 2016. Their objective: exfiltration of Call Data Records (CDRs) — the metadata showing who called whom, when, and from where.

CDR data is signals intelligence. In a kinetic conflict, it enables target development — identifying military personnel movements, mapping command structures, and locating high-value individuals. The August 11 profile refresh, while not accompanied by new IOCs, follows a pattern where vendor intelligence updates precede public campaign disclosures by 5–10 days.

Known tooling: DNSDAT, ISMDoor, RGDoor, Mimikatz, Bitvise SSH Client, Plink. Their ISMDoor implant shares code lineage with OilRig's ISMAgent, indicating MOIS tool-sharing across actor groups.

T1505.003T1572

ASN 213790 ("Limited Network," Tehran) continues to host infrastructure serving dual purposes: state-sponsored espionage and ransomware operations. Five high-confidence IPs on this ASN are simultaneously tagged with Cactus ransomware indicators and advanced persistent threat tooling. One IP (77.90.185[.]248) now explicitly targets healthcare organizations.

This convergence is not coincidental. It reflects the documented Pioneer Kitten operational model: exploit perimeter devices → establish access → either conduct espionage or hand off access to ransomware affiliates for monetization and deniability. The Cactus ransomware family has been linked to this handoff pattern since earlier in the conflict.

T1566.001T1486

Two new ICS advisories expand the attack surface for Iranian destructive operations:

  • Johnson Controls C-CURE 9000: Remote code execution in physical access control systems. These systems control badge readers, door locks, and security cameras in government and military facilities. Compromise enables physical intrusion or lockout scenarios.
  • ABB Ability Zenon: Multiple vulnerabilities in a SCADA/HMI platform used across energy, water, and manufacturing. Exploitation enables security bypass, system crashes, and unauthorized control manipulation.

Given CyberAv3ngers' demonstrated capability against water utility PLCs (36+ facilities compromised in July), these vulnerabilities represent immediate expansion opportunities for Iranian ICS operators.

T0831T1190

UNC5203, operating under the "Handala" hacktivist persona, is the IRGC's primary destructive cyber actor. Responsible for deploying BiBiWiper, ZeroShred, and GoneXML against Israeli targets, this group maintains active capability against energy, financial services, government, technology, telecommunications, and utilities.

The August 12 profile update without new IOCs indicates maintained operational readiness — the actor is being tracked but has not launched a new destructive campaign this cycle. This is consistent with a "pre-positioned and waiting" posture.

T1485

ScenarioProbabilityTimeframeBasis
TRACER KITTEN IOCs published revealing active telecom campaign70%7 daysProfile refresh pattern historically precedes disclosure by 5–10 days
CVE-2026-20349 exploitation attributed to Iranian actor (likely Pioneer Kitten)60%14 daysMatches historical Pioneer Kitten perimeter exploitation pattern; same vendor/product class
Healthcare sector ransomware incident linked to ASN 213790 infrastructure50%21 daysExplicit healthcare targeting tag on 77.90.185[.]248; Cactus ransomware convergence
SPECTRAL KITTEN/Agrius activates dormant ICS persistence in Israeli utility40%30 daysMid-June intrusion confirmed; silence since Day 137 suggests achieved persistence
UNC5203/Handala launches new destructive operation against allied infrastructure35%30 daysMaintained readiness; activation likely tied to kinetic escalation trigger
Pioneer Kitten sells Cisco VPN access to ransomware affiliate55%21 daysDocumented operational model; active exploitation of CVE-2026-20349 creates access inventory

1. Cobalt Strike DNS Tunneling (T1071.004 — Application Layer Protocol: DNS):

Iranian operators are using Cobalt Strike BEACON with DNS tunneling on port 53 to evade HTTPS-focused C2 detection. The "Agentemis" framework specifically targets organizations with mature HTTPS inspection. Hunt hypothesis: Anomalous DNS query volume to external resolvers, particularly queries with high-entropy subdomain labels (base64-encoded data exfiltration) Detection: Monitor for DNS queries to non-corporate resolvers from internal hosts; alert on DNS TXT record responses exceeding 512 bytes; flag any internal host communicating on port 53 to IPs outside approved DNS infrastructure Block: 217.60.241[.]17 (ASN 51396, port 443) and 87.107.191[.]39 (ASN 44436, port 53)

2. Cisco ASA/FTD VPN Exploitation (T1190 — Exploit Public-Facing Application):

Hunt hypothesis: Unexpected ASA/FTD device reloads or crash dumps in the last 72 hours may indicate exploitation attempts Detection: Monitor for repeated device reloads without administrative action; alert on malformed HTTP requests to the SSL VPN portal; review ASA syslogs for %ASA-6-302014 connection teardowns from unusual source IPs Immediate action: Verify patch status for CVE-2026-20349 across all ASA/FTD devices with Remote Access VPN enabled

3. Mythic C2 Framework (T1219 — Remote Access Software; T1071.001 — Web Protocols):

Hunt hypothesis: Mythic agents use HTTP/HTTPS with customizable profiles that mimic legitimate traffic. Look for beaconing patterns with consistent intervals and jitter to non-categorized domains Detection: Deploy Mythic-specific YARA rules alongside existing Cobalt Strike detection; monitor for unusual PowerShell or Python processes establishing persistent HTTPS connections; flag traffic to Iranian ASN 60631

4. Cactus Ransomware Precursors (T1486 — Data Encrypted for Impact; T1059.001 — PowerShell):

Hunt hypothesis: Cactus operators use legitimate remote management tools (NetsupportManager) for persistence before encryption. Look for NetsupportManager installations not deployed by IT Detection: Alert on NetsupportManager RAT (win.netsupportmanager) installations outside approved software inventory; monitor for Sality virus indicators (legacy but present in Cactus toolchain); flag connections to ASN 213790 IP ranges Block: 192.253.248[.]65, 77.90.185[.]248, 77.90.185[.]28

5. TRACER KITTEN Telecom Targeting (T1505.003 — Web Shell; T1572 — Protocol Tunneling):

Hunt hypothesis: TRACER KITTEN deploys web shells on IIS servers and uses SSH tunneling for persistent access to telecom billing/CDR systems Detection: Monitor IIS servers for new ASPX files in web-accessible directories; alert on Bitvise SSH Client or Plink execution from non-admin contexts; flag outbound SSH connections to MENA IP ranges from servers that don't normally SSH externally Signatures to pre-stage: DNSDAT, ISMDoor, RGDoor YARA rules

6. ICS/OT Monitoring (T0831 — Manipulation of Control; T1489 — Service Stop):

Hunt hypothesis: Iranian actors pre-position on IT networks before pivoting to OT. Look for reconnaissance of ICS protocols (Modbus, BACnet, OPC-UA) from IT-segment hosts Detection: Monitor for network scanning targeting ICS ports (502/TCP Modbus, 47808/UDP BACnet, 4840/TCP OPC-UA) from non-engineering workstations; alert on any access to Johnson Controls C-CURE 9000 management interfaces from non-approved sources; flag ABB Zenon engineering workstation connections from outside the OT network

ThreatATT&CK
1. Cobalt Strike DNS Tunneling (T1071.004 — Application Layer Protocol: DNS)T1071.004
2. Cisco ASA/FTD VPN Exploitation (T1190 — Exploit Public-Facing Application)T1190
3. Mythic C2 Framework (T1219 — Remote Access Software; T1071.001 — Web Protocols)T1219 T1071.001
4. Cactus Ransomware Precursors (T1486 — Data Encrypted for Impact; T1059.001 — PowerShell)T1486 T1059.001
5. TRACER KITTEN Telecom Targeting (T1505.003 — Web Shell; T1572 — Protocol Tunneling)T1505.003 T1572
6. ICS/OT Monitoring (T0831 — Manipulation of Control; T1489 — Service Stop)T0831 T1489
IOC Blocking Table:
217.60.241[.]1787.107.191[.]39192.253.248[.]6577.90.185[.]24877.90.185[.]28176.123.87[.]162.188.214[.]14291.231.222[.]184172.94.9[.]74

Block the above at perimeter firewalls, proxies, and DNS. File hashes (SHA-256, Cactus/NetsupportManager associated unless noted): f4f105544e9c26e228fe63c5f3dfdad2edc0d098f0a8faeb419d03652d61df39, 025b2a2b91e45f4cfbb32cff89f33f51144429fc0fec1a8275ed9cb95462cd63, d4bc7b0e02380c6733c7241e444221d6be60478f12a0774570a216c12fa2d8b7, and 6bb3c19f1ed89ba8150785d5804b641b80d04d60fa5ed3f589d98621ffe4b23b (Remcos RAT associated). Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1071.004
Cobalt Strike DNS tunneling ("Agentemis")
Anomalous DNS query volume to external resolvers, particularly queries with high-entropy subdomain labels (base64-encoded data exfiltration).
HUNT 02 · T1190
Cisco ASA/FTD exploitation attempts
Unexpected ASA/FTD device reloads or crash dumps in the last 72 hours may indicate CVE-2026-20349 exploitation attempts.
HUNT 03 · T1219
Mythic C2 beaconing
Mythic agents use HTTP/HTTPS with customizable profiles that mimic legitimate traffic. Look for beaconing patterns with consistent intervals and jitter to non-categorized domains.
HUNT 04 · T1486
Cactus ransomware precursors
Cactus operators use legitimate remote management tools (NetsupportManager) for persistence before encryption. Look for NetsupportManager installations not deployed by IT.
HUNT 05 · T1505.003
TRACER KITTEN telecom persistence
TRACER KITTEN deploys web shells on IIS servers and uses SSH tunneling for persistent access to telecom billing/CDR systems.
HUNT 06 · T0831
IT-to-OT pre-positioning reconnaissance
Iranian actors pre-position on IT networks before pivoting to OT. Look for reconnaissance of ICS protocols (Modbus, BACnet, OPC-UA) from IT-segment hosts.

Financial Services
Banking, SWIFT Systems
Primary threat
Cactus ransomware via Iranian access broker handoff; UNC5203/Handala destructive operations against Israeli-linked financial institutions.
Actions
  • Audit all Cisco ASA/FTD VPN appliances for CVE-2026-20349 patch status — financial services VPN concentrators are high-value targets for access brokers
  • Monitor for NetsupportManager RAT installations on endpoints — Cactus precursor activity
  • Review SWIFT and core banking system access logs for anomalous authentication from VPN-connected sessions
  • Ensure offline backups of transaction databases are tested and current (Handala wiper defense)
  • Block ASN 213790 IP ranges at network perimeter and in SWIFT transaction monitoring
Energy
SCADA/HMI, Grid PLCs
Primary threat
ICS/OT pre-positioning for destructive operations; ABB Zenon SCADA exploitation; CyberAv3ngers PLC manipulation pattern.
Actions
  • Immediately audit ABB Ability Zenon deployments for network exposure and patch status
  • Verify IT/OT network segmentation — no direct path from corporate VPN to SCADA/HMI systems
  • Deploy additional monitoring at IT/OT boundary for ICS protocol reconnaissance (Modbus, DNP3, OPC-UA scanning)
  • Review CyberAv3ngers TTPs from the July water utility attacks and validate detection coverage for PLC-level manipulation
  • Conduct tabletop exercise for scenario: "Perimeter VPN compromised → lateral movement to OT → safety system manipulation"
Healthcare
Patient Portals, EHR Systems
Primary threat
Cactus ransomware with explicit healthcare targeting from ASN 213790 infrastructure (77.90.185[.]248).
Actions
  • Block 77.90.185[.]248 immediately — this IP is explicitly tagged for healthcare targeting with very-high severity
  • Audit all internet-facing systems (patient portals, telehealth platforms, VPN appliances) for unpatched vulnerabilities
  • Verify ransomware resilience: offline backups of EHR systems, tested recovery procedures, clinical system isolation capability
  • Monitor for NetsupportManager and Sality indicators — present in Cactus toolchain samples
  • Ensure clinical systems can operate in degraded mode (paper-based fallback) if ransomware encrypts IT infrastructure
Government
Physical Access Control, Federal Networks
Primary threat
Johnson Controls C-CURE 9000 RCE (physical access control compromise); Pioneer Kitten VPN exploitation for persistent access; UNC5203/Handala destructive operations.
Actions
  • Audit Johnson Controls C-CURE 9000 and Victor video management system deployments for network exposure — RCE enables physical security bypass
  • Verify Cisco ASA/FTD patch status across all government network perimeters — CVE-2026-20349 is actively exploited
  • Review physical access control system logs for anomalous badge events or configuration changes
  • Assess exposure to the Pioneer Kitten access-broker model: if your VPN is compromised, assume access will be sold to ransomware operators within 14–21 days
  • Monitor for UNC5866 (Emennet Pasargad) — an IRGC contractor conducting information operations using fabricated personas
Aviation / Logistics
Satellite Comms, DIB Contractors
Primary threat
TRACER KITTEN telecom/satellite espionage (CDR collection for target development); PULSAR KITTEN aerospace targeting; supply chain compromise via DIB contractors.
Actions
  • Monitor for DNSDAT and ISMDoor signatures on network infrastructure — TRACER KITTEN's primary implants for telecom environments
  • Audit satellite communication systems and ground station connectivity for unauthorized access
  • Review supply chain access from DIB contractors — PTC Windchill and similar PLM systems may harbor dormant Iranian persistence (31+ days of silence on this vector)
  • Monitor for SSH tunneling (Bitvise, Plink) from servers that don't normally establish outbound SSH connections
  • Assess CDR/metadata exposure: if your organization's communications metadata is collected, what operational security implications follow?
No sector cards match the selected filters.

Patch all Cisco ASA/FTD appliances for CVE-2026-20349. If patching is not immediately possible, implement CISA-recommended mitigations for the Remote Access SSL VPN service. Active exploitation is confirmed.
Incident Responder
Block the following IPs at all perimeter firewalls, proxy servers, and DNS sinkholes: 217.60.241[.]17, 87.107.191[.]39, 192.253.248[.]65, 77.90.185[.]248, 77.90.185[.]28 — confirmed Iranian APT C2 and ransomware infrastructure.
SOC Analyst
Deploy DNS tunneling detection for Cobalt Strike beaconing on port 53 to Iranian ASN ranges (44436, 51396, 213790). Alert on high-entropy DNS queries and oversized TXT responses.
SOC Analyst
Review the last 72 hours of Cisco ASA/FTD syslogs for unexpected device reloads, crash dumps, or malformed HTTP requests to VPN portals — potential indicators of CVE-2026-20349 exploitation attempts.
SOC Analyst
No immediate actions for the selected roles.
Deploy YARA signatures for DNSDAT, ISMDoor, and RGDoor on DNS monitoring and IDS/IPS infrastructure — pre-position detection for anticipated TRACER KITTEN campaign disclosure.
Threat Hunter
Audit Johnson Controls C-CURE 9000, Victor, and ABB Ability Zenon deployments for network exposure. Isolate management interfaces from the general corporate network. Apply vendor patches where available.
ICS / OT
Create a correlation rule for Cobalt Strike + Mythic C2 detection — Iranian operators are diversifying frameworks. Ensure detection covers both HTTPS beaconing (Cobalt Strike) and customizable HTTP profiles (Mythic).
SOC Analyst
Audit NetsupportManager installations across all endpoints. Any instance not deployed by IT is a potential Cactus ransomware precursor. Remove unauthorized installations immediately.
Incident Responder
No 7-day actions for the selected roles.
Commission a proactive threat hunt for SPECTRAL KITTEN/Agrius persistence indicators in utility and ICS networks. The confirmed mid-June Israeli utility intrusion followed by 60+ days of silence is the highest-risk absence signal in the current threat landscape.
CISO / ExecThreat Hunter
Reassess Defense Industrial Base monitoring — 31+ days of silence on PIR-007 (DIB pre-positioning) may indicate successful persistent access that has evaded detection. Conduct a focused hunt on PTC Windchill instances, GitHub access tokens, and dormant service accounts.
CISO / ExecIncident Responder
Conduct a tabletop exercise for a combined scenario: VPN perimeter compromise (CVE-2026-20349) → lateral movement → ransomware deployment (Cactus) with simultaneous ICS/OT disruption. Test executive decision-making for ransom payment, regulatory notification, and operational continuity.
CISO / Exec
Evaluate telecom metadata exposure — if TRACER KITTEN is conducting CDR collection against your communications providers, assess what operational intelligence an adversary could derive from your organization's call/messaging metadata. Consider encrypted communications alternatives for sensitive operations.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

165 days into this conflict, the pattern is unmistakable: Iranian cyber operations are not winding down — they are professionalizing. The convergence of state espionage tooling and ransomware infrastructure on the same ASNs, the diversification from Cobalt Strike to Mythic C2, the expansion from water utilities to healthcare, and the resurrection of telecom espionage capabilities all point to an adversary that is learning, adapting, and preparing for the next phase. The most dangerous signal in today's intelligence is not what we found — it's what went silent. SPECTRAL KITTEN's confirmed ICS intrusion has produced no follow-on indicators for weeks. The Defense Industrial Base pre-positioning vector has been quiet for over a month. In offensive cyber operations, silence after confirmed access does not mean the threat has passed. It means the adversary has achieved what they need and is waiting.

1
Patch Cisco ASA/FTD for CVE-2026-20349. Active exploitation is confirmed. Every hour unpatched is an hour of exposure.
2
Block the five confirmed Iranian C2 IPs listed above. This is a 5-minute firewall change that eliminates confirmed threat infrastructure.
3
Authorize the SPECTRAL KITTEN persistence hunt. The silence is the signal. Find them before they activate.
No items found.