| Date | Development | Significance |
|---|---|---|
| Jul 16 | CVE-2026-25089 (FortiSandbox pre-auth RCE, CVSS 9.8) added to CISA KEV | Pioneer Kitten exploits Fortinet vulns within 24–72 hrs of KEV listing — now at Day 5 |
| Jul 16 | Five Rockwell Automation ICS advisories published simultaneously — CompactLogix, ControlLogix, GuardLogix, Arena | Backbone of U.S. industrial control now carries exploitable DoS vulnerabilities |
| Jul 16 | Siemens SICAM 8 substation automation vulnerabilities disclosed | Electrical grid protection systems have known attack paths during active conflict |
| Jul 20 | HOLLOWGRAPH implant publicly disclosed by Group-IB; Fox Kitten / APT39 records refreshed | Novel M365 Graph API calendar C2 — traditional network detection will not catch this traffic |
| Jul 21 | APT34 / OilRig malware hash refresh (same-day); ASN213790 C2 infrastructure confirmed active at confidence 97 | Same-day indicator updates signal active operations, not dormant infrastructure |
| Jul 21 | ASN213790 infrastructure diversifying to secondary ISP ASN34918 (Pishgaman Toseeh, Tehran) | Deliberate resilience measure — single-ASN blocking now insufficient |
| Day 25 | Handala, Cyber Av3ngers, DieNet, and 313 Team maintain 24+ day operational silence | Historical response window is 48–72 hours. This gap is unprecedented and assessed as pre-operational staging |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before Jun 2026 | Baseline Iranian espionage (APT34/OilRig, MuddyWater, Pioneer Kitten); HOLLOWGRAPH implant deployed against Israeli targets Jun 3 |
| Conflict trigger | Jun 26 | U.S. kinetic strikes on Iran (Strait of Hormuz retaliation); IOCONTROL ICS malware maintained in active development; all known hacktivist proxies go silent within 48 hours |
| Proxy silence / staging | Jun 26 – Jul 15 | Handala, Cyber Av3ngers, DieNet, 313 Team operationally dark — no public claims; Iranian APT infrastructure continues active development and C2 refresh |
| Attack surface expansion | Jul 16–20 | CISA adds CVE-2026-25089 to KEV (Day 0); 9 ICS advisories (Rockwell CompactLogix, ControlLogix, GuardLogix, Arena; Siemens SICAM 8); HOLLOWGRAPH publicly disclosed Jul 20 |
| Current (Day 25) | Jul 21, 2026 | APT34/OilRig same-day hash refresh; ASN213790 active at confidence 97; infrastructure diversifying to ASN34918; CVSS 9.8 window now at Day 5 unanswered |
An unauthenticated OS command injection vulnerability in Fortinet FortiSandbox (versions 4.2 through 5.0.5, including Cloud and PaaS deployments) allows remote code execution without credentials. CISA added it to the Known Exploited Vulnerabilities catalog on July 16. As of July 21, we are at Day 5 post-KEV listing with no patch confirmation from most organizations.
Why it's critical now: Pioneer Kitten (Fox Kitten, UNC757, Parisite) is an IRGC-affiliated group with a documented pattern of weaponizing Fortinet vulnerabilities within 24–72 hours of public disclosure. Their operational history includes CVE-2018-13379, CVE-2019-5591, and CVE-2020-12812 — all Fortinet products, all exploited rapidly after disclosure. Active ASN213790 C2 infrastructure is online today. The window is closing.
Five high-confidence IPs on Iranian-hosted ASNs remain operational with Cactus ransomware, IcedID, LockBit, and command injection tags. Critically, a second Iranian ISP (ASN34918, Pishgaman Toseeh) has now appeared alongside the primary ASN213790 hosting bloc. This infrastructure diversification is a deliberate resilience measure — organizations blocking only ASN213790 have a gap.
| IP | ASN | Confidence | Tags |
|---|---|---|---|
185.93.89[.]43 | ASN213790 (Tehran) | 97 | Cactus, CommandInjection, IcedID |
77.90.185[.]118 | ASN213790 | 91 | Cactus, IcedID, Scanner |
185.93.89[.]75 | ASN213790 | 77 | LockBit, T1071, T1571 |
192.253.248[.]169 | ASN213790 | 77 | LockBit, Cactus, multi-industry |
5.202.4[.]18 | ASN34918 (Pishgaman Toseeh) | 77 | Cactus, IcedID |
The simultaneous disclosure on July 16 of vulnerabilities in Rockwell CompactLogix/ControlLogix (America's most deployed PLC platform) and Siemens SICAM 8 (substation automation) creates a window of elevated OT risk during an active military conflict with Iran. Cyber Av3ngers (IRGC-affiliated) have previously targeted PLC-class devices and publicly claimed attacks on water and energy infrastructure. These advisories provide a technical roadmap.
Key vulnerabilities: Rockwell 1756-EN2/EN3/ENBT communication modules (DoS without deep OT protocol knowledge), Siemens SICAM 8 substation automation DoS affecting electrical grid protection systems, Rockwell Arena arbitrary code execution (engineering workstation vector), and SALTO ProAccess Space physical access control privilege escalation (cyber-physical convergence).
Intelligence confirms a coordinated multi-actor threat landscape spanning IRGC and MOIS-affiliated groups operating across the full kill chain simultaneously — from initial access brokering through espionage to potential destructive operations:
| Actor | Affiliation | Role | Current Status |
|---|---|---|---|
| Pioneer Kitten (Fox Kitten, UNC757) | IRGC | Fortinet exploitation, initial access brokering | Active — CVE-2026-25089 exploitation window open |
| Cyber Av3ngers | IRGC-affiliated | ICS/OT disruption, water/energy targeting | Silent — assessed as staging for retaliation |
| APT34 / OilRig | MOIS | Espionage, telecom targeting, credential harvesting | Active — same-day hash refresh Jul 21 |
| Lyceum / OilRig subset | MOIS | Novel C2 techniques, Israeli/Western targeting | Active — HOLLOWGRAPH campaign (low confidence) |
| Handala / DieNet / 313 Team | IRGC-aligned | Hacktivist operations, leak and wiper campaigns | Silent — 24+ days, unprecedented gap |
Disclosed July 20 by Group-IB, HOLLOWGRAPH is a novel command-and-control technique abusing Microsoft 365 Graph API calendar events for bidirectional C2 communications. Operational since June 3 against twelve Israeli organizations, this implant demonstrates Iranian actors' investment in living-off-the-land techniques that blend with legitimate cloud traffic. Low-confidence attribution to Lyceum/OilRig (APT34).
The defensive challenge: this C2 traffic is indistinguishable from legitimate Microsoft 365 activity at the network layer. Traditional perimeter-based detection — firewall logs, proxy inspection, DNS filtering — will not catch it. Defenders need cloud-native audit log analysis and Graph API permission auditing to detect HOLLOWGRAPH activity. Any M365-enabled organization is a potential target.
Same-day refresh of APT34 malware samples on July 21 — SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc — confirms active telecom-sector targeting with defense evasion capabilities including security tool disabling and debugger evasion. Targeting has expanded beyond traditional Middle East victims to include Malaysia and Australia, suggesting either broadened collection requirements or infrastructure pre-positioning in Five Eyes-adjacent networks.
Why same-day matters: indicator updates on the day of publication signal active operational tempo, not maintenance of dormant infrastructure. This group is running live operations today.
Every known Iranian-aligned hacktivist proxy — Handala, Cyber Av3ngers, DieNet, and 313 Team — has been silent for 24+ days following U.S. kinetic strikes on Iranian soil. Historical precedent shows these groups respond within 48–72 hours of perceived provocations. This gap is unprecedented.
Three hypotheses, all demanding the same response: Coordinated preparation (assessed most likely) — groups are staging for a synchronized multi-target operation, matching the quiet-before-storm pattern observed before Iran's 2022 Albanian government wiper attack. Enhanced OPSEC discipline — directed to avoid attribution signals during preparation. Collection gap — visibility into communication channels has degraded. All three hypotheses demand proactive hunting, not passive waiting.
| Scenario | Probability | Timeframe | Indicators to Watch |
|---|---|---|---|
| Coordinated hacktivist retaliation wave (wiper + DDoS + data leak) by Handala / Cyber Av3ngers / DieNet / 313 Team | 45% | Next 7 days | New Telegram channels, return of hacktivist personas, infrastructure overlap with known IOCs, pre-wiper reconnaissance spikes |
| Pioneer Kitten exploitation of CVE-2026-25089 against Western critical infrastructure targets | 35% | Next 7 days | FortiSandbox management interface connections from Iranian ASNs; new C2 callbacks from patched or unpatched systems |
| APT34 / OilRig telecom espionage expansion to Malaysia, Australia, and Five Eyes-adjacent networks | 30% | 14–30 days | New APT34 malware hash submissions; telecom sector anomalous authentication events; additional geographies in targeting data |
| ICS/OT disruption attempt against energy or water sector using Rockwell / Siemens vulnerabilities | 25% | 7–30 days | ICS-CERT incident reports; Cyber Av3ngers public claims; OT scanning activity on EtherNet/IP networks |
| HOLLOWGRAPH technique reuse against non-Israeli targets (U.S. government, defense contractors) | 20% | 30+ days | M365 audit log anomalies; Graph API calendar permissions changes; CISA advisories on novel M365 TTPs |
| Rule | Data Source | ATT&CK | Priority |
|---|---|---|---|
Outbound to Iranian C2 IPs 185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]169, 5.202.4[.]18 on any port | Firewall / Netflow | T1071 | CRITICAL |
APT34 malware hashes present on any endpoint — SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc or fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392 | EDR | T1562.001 | CRITICAL |
FortiSandbox service account spawning shell process (/bin/sh, /bin/bash) or anomalous outbound connection from management interface | EDR / Sysmon | T1190 T1059.004 | CRITICAL |
| Microsoft Graph API calendar create/modify event by service principal not in approved application list | M365 Audit Logs | T1102 | HIGH |
| EDR or AV service termination, process kill, or exclusion list modification by non-administrative account | EDR / Windows Event Log | T1562.001 | HIGH |
| EtherNet/IP (TCP/44818) or Siemens SICAM protocol traffic originating from IT VLAN to OT controller segments | OT Monitoring / IDS | T0846 T1499 | HIGH |
| System language enumeration API calls (IsValidLocaleName, GetUserDefaultLangID) before primary payload execution — indicative of Iranian-origin malware OPSEC | EDR / Sysmon | T1614.001 | MEDIUM |
Network: all five IPs on ASN213790 (Tehran) / ASN34918 (Pishgaman Toseeh) — Cactus ransomware C2, IcedID, LockBit, command injection. Confidence: 77–97. File: APT34/OilRig telecom-targeting malware SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc (confidence 85) and associated sample fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392 (confidence 70). Additional IOCs available via Anomali ThreatStream and partner feeds.
- Validate offline backup integrity for core banking systems — Iranian actors have historically deployed wipers disguised as ransomware (ZeroCleare, Shamoon)
- Review SWIFT/payment system segmentation from general corporate networks
- Monitor for IcedID initial access — typically arrives via malicious Office documents or hijacked email threads; tagged on active Iranian infrastructure
- Block all five C2 IPs at perimeter deny lists; add ASN213790 and ASN34918 to threat intelligence watchlists
- Inventory all Rockwell 1756-EN2/EN3/ENBT communication modules; verify firmware versions against ICSA-26-197-06 and ICSA-26-197-02
- Patch Siemens SICAM 8 substation systems per ICSA-26-197-05; deploy monitoring for anomalous SICAM protocol traffic
- Ensure safety instrumented systems (SIS) are physically isolated — not just logically segmented
- Pre-position OT incident response playbooks; confirm manual override procedures are documented and tested
- Verify medical device network segmentation — particularly embedded Windows devices that cannot be patched
- Ensure clinical systems (EHR, PACS, lab systems) have tested offline operation procedures
- Monitor for IcedID loader activity — the initial access vector tagged on active Iranian infrastructure
- Review FortiSandbox deployments; CVE-2026-25089 is a direct path to network compromise from sandboxing appliances
- Audit Microsoft 365 Graph API permissions — revoke unnecessary calendar API access for service principals
- Hunt for HOLLOWGRAPH indicators: calendar events with encoded/obfuscated content created by non-human accounts
- Review FortiSandbox deployments in .gov environments — CVE-2026-25089 is a direct path to network compromise
- Deploy APT34 hash detections across all endpoint platforms; increase monitoring on cleared personnel accounts for anomalous access patterns
- Coordinate with CISA for sector-specific threat briefings on Iranian retaliation scenarios
- Review supply chain connections to Defense Industrial Base contractors — Pioneer Kitten uses contractor networks as pivot points into prime contractors
- Monitor for APT33-associated TTPs: spearphishing with job-themed lures targeting aviation engineers
- Verify OT systems in airport/port environments (baggage handling, cargo management, navigation aids) are properly segmented
- Assess exposure to SALTO ProAccess Space vulnerability (ICSA-26-197-07) — privilege escalation in widely deployed physical access control systems
185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]169, and 5.202.4[.]18 to perimeter deny lists and SIEM watchlists. Alert on any historical connections at severity CRITICAL.50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc and fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392 to EDR block lists immediately. Same-day refresh on July 21 confirms active operations.Nearly five months into the U.S.-Iran military confrontation and 25 days past the most significant kinetic trigger — direct U.S. strikes on Iranian territory — we are in the most dangerous phase of the retaliation cycle. The infrastructure is active. The vulnerabilities are disclosed. The proxies are silent. Iranian cyber doctrine treats cyber operations as asymmetric force multipliers — cheaper than missiles, deniable through proxies, capable of strategic impact against civilian infrastructure. The 2022 Albanian government wiper, the 2023 Israeli water system attacks, and the ongoing HOLLOWGRAPH campaign all demonstrate that Iran executes on this doctrine. The only variable is timing.