TLP:GREEN  ·  Iran / Israel Conflict
Iranian Cyber Retaliation Clock — Day 25:

What CISOs Must Do Before the Storm Breaks

CRITICAL. Twenty-five days after U.S. military strikes on Iranian territory, the expected cyber retaliation has not materialized — and that silence is the loudest signal in the threat landscape. Iranian state-sponsored groups are refreshing infrastructure, CVE-2026-25089 (CVSS 9.8) sits unanswered in Pioneer Kitten's preferred attack surface at Day 5 post-KEV, six new ICS advisories expose Rockwell and Siemens OT systems, and every known hacktivist proxy — Handala, Cyber Av3ngers, DieNet, 313 Team — has gone dark for 24+ days. This is not restraint. This is preparation.

I am a
My sector

DateDevelopmentSignificance
Jul 16CVE-2026-25089 (FortiSandbox pre-auth RCE, CVSS 9.8) added to CISA KEVPioneer Kitten exploits Fortinet vulns within 24–72 hrs of KEV listing — now at Day 5
Jul 16Five Rockwell Automation ICS advisories published simultaneously — CompactLogix, ControlLogix, GuardLogix, ArenaBackbone of U.S. industrial control now carries exploitable DoS vulnerabilities
Jul 16Siemens SICAM 8 substation automation vulnerabilities disclosedElectrical grid protection systems have known attack paths during active conflict
Jul 20HOLLOWGRAPH implant publicly disclosed by Group-IB; Fox Kitten / APT39 records refreshedNovel M365 Graph API calendar C2 — traditional network detection will not catch this traffic
Jul 21APT34 / OilRig malware hash refresh (same-day); ASN213790 C2 infrastructure confirmed active at confidence 97Same-day indicator updates signal active operations, not dormant infrastructure
Jul 21ASN213790 infrastructure diversifying to secondary ISP ASN34918 (Pishgaman Toseeh, Tehran)Deliberate resilience measure — single-ASN blocking now insufficient
Day 25Handala, Cyber Av3ngers, DieNet, and 313 Team maintain 24+ day operational silenceHistorical response window is 48–72 hours. This gap is unprecedented and assessed as pre-operational staging

PhaseTimeframeCyber Activity
Pre-escalationBefore Jun 2026Baseline Iranian espionage (APT34/OilRig, MuddyWater, Pioneer Kitten); HOLLOWGRAPH implant deployed against Israeli targets Jun 3
Conflict triggerJun 26U.S. kinetic strikes on Iran (Strait of Hormuz retaliation); IOCONTROL ICS malware maintained in active development; all known hacktivist proxies go silent within 48 hours
Proxy silence / stagingJun 26 – Jul 15Handala, Cyber Av3ngers, DieNet, 313 Team operationally dark — no public claims; Iranian APT infrastructure continues active development and C2 refresh
Attack surface expansionJul 16–20CISA adds CVE-2026-25089 to KEV (Day 0); 9 ICS advisories (Rockwell CompactLogix, ControlLogix, GuardLogix, Arena; Siemens SICAM 8); HOLLOWGRAPH publicly disclosed Jul 20
Current (Day 25)Jul 21, 2026APT34/OilRig same-day hash refresh; ASN213790 active at confidence 97; infrastructure diversifying to ASN34918; CVSS 9.8 window now at Day 5 unanswered

An unauthenticated OS command injection vulnerability in Fortinet FortiSandbox (versions 4.2 through 5.0.5, including Cloud and PaaS deployments) allows remote code execution without credentials. CISA added it to the Known Exploited Vulnerabilities catalog on July 16. As of July 21, we are at Day 5 post-KEV listing with no patch confirmation from most organizations.

Why it's critical now: Pioneer Kitten (Fox Kitten, UNC757, Parisite) is an IRGC-affiliated group with a documented pattern of weaponizing Fortinet vulnerabilities within 24–72 hours of public disclosure. Their operational history includes CVE-2018-13379, CVE-2019-5591, and CVE-2020-12812 — all Fortinet products, all exploited rapidly after disclosure. Active ASN213790 C2 infrastructure is online today. The window is closing.

T1190T1059.004

Five high-confidence IPs on Iranian-hosted ASNs remain operational with Cactus ransomware, IcedID, LockBit, and command injection tags. Critically, a second Iranian ISP (ASN34918, Pishgaman Toseeh) has now appeared alongside the primary ASN213790 hosting bloc. This infrastructure diversification is a deliberate resilience measure — organizations blocking only ASN213790 have a gap.

IPASNConfidenceTags
185.93.89[.]43ASN213790 (Tehran)97Cactus, CommandInjection, IcedID
77.90.185[.]118ASN21379091Cactus, IcedID, Scanner
185.93.89[.]75ASN21379077LockBit, T1071, T1571
192.253.248[.]169ASN21379077LockBit, Cactus, multi-industry
5.202.4[.]18ASN34918 (Pishgaman Toseeh)77Cactus, IcedID
T1071T1571T1190

The simultaneous disclosure on July 16 of vulnerabilities in Rockwell CompactLogix/ControlLogix (America's most deployed PLC platform) and Siemens SICAM 8 (substation automation) creates a window of elevated OT risk during an active military conflict with Iran. Cyber Av3ngers (IRGC-affiliated) have previously targeted PLC-class devices and publicly claimed attacks on water and energy infrastructure. These advisories provide a technical roadmap.

Key vulnerabilities: Rockwell 1756-EN2/EN3/ENBT communication modules (DoS without deep OT protocol knowledge), Siemens SICAM 8 substation automation DoS affecting electrical grid protection systems, Rockwell Arena arbitrary code execution (engineering workstation vector), and SALTO ProAccess Space physical access control privilege escalation (cyber-physical convergence).

T1499T0816T0826

Intelligence confirms a coordinated multi-actor threat landscape spanning IRGC and MOIS-affiliated groups operating across the full kill chain simultaneously — from initial access brokering through espionage to potential destructive operations:

ActorAffiliationRoleCurrent Status
Pioneer Kitten (Fox Kitten, UNC757)IRGCFortinet exploitation, initial access brokeringActive — CVE-2026-25089 exploitation window open
Cyber Av3ngersIRGC-affiliatedICS/OT disruption, water/energy targetingSilent — assessed as staging for retaliation
APT34 / OilRigMOISEspionage, telecom targeting, credential harvestingActive — same-day hash refresh Jul 21
Lyceum / OilRig subsetMOISNovel C2 techniques, Israeli/Western targetingActive — HOLLOWGRAPH campaign (low confidence)
Handala / DieNet / 313 TeamIRGC-alignedHacktivist operations, leak and wiper campaignsSilent — 24+ days, unprecedented gap

Disclosed July 20 by Group-IB, HOLLOWGRAPH is a novel command-and-control technique abusing Microsoft 365 Graph API calendar events for bidirectional C2 communications. Operational since June 3 against twelve Israeli organizations, this implant demonstrates Iranian actors' investment in living-off-the-land techniques that blend with legitimate cloud traffic. Low-confidence attribution to Lyceum/OilRig (APT34).

The defensive challenge: this C2 traffic is indistinguishable from legitimate Microsoft 365 activity at the network layer. Traditional perimeter-based detection — firewall logs, proxy inspection, DNS filtering — will not catch it. Defenders need cloud-native audit log analysis and Graph API permission auditing to detect HOLLOWGRAPH activity. Any M365-enabled organization is a potential target.

T1102T1071.001

Same-day refresh of APT34 malware samples on July 21 — SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc — confirms active telecom-sector targeting with defense evasion capabilities including security tool disabling and debugger evasion. Targeting has expanded beyond traditional Middle East victims to include Malaysia and Australia, suggesting either broadened collection requirements or infrastructure pre-positioning in Five Eyes-adjacent networks.

Why same-day matters: indicator updates on the day of publication signal active operational tempo, not maintenance of dormant infrastructure. This group is running live operations today.

T1562.001T1622T1012

Every known Iranian-aligned hacktivist proxy — Handala, Cyber Av3ngers, DieNet, and 313 Team — has been silent for 24+ days following U.S. kinetic strikes on Iranian soil. Historical precedent shows these groups respond within 48–72 hours of perceived provocations. This gap is unprecedented.

Three hypotheses, all demanding the same response: Coordinated preparation (assessed most likely) — groups are staging for a synchronized multi-target operation, matching the quiet-before-storm pattern observed before Iran's 2022 Albanian government wiper attack. Enhanced OPSEC discipline — directed to avoid attribution signals during preparation. Collection gap — visibility into communication channels has degraded. All three hypotheses demand proactive hunting, not passive waiting.

ScenarioProbabilityTimeframeIndicators to Watch
Coordinated hacktivist retaliation wave (wiper + DDoS + data leak) by Handala / Cyber Av3ngers / DieNet / 313 Team45%Next 7 daysNew Telegram channels, return of hacktivist personas, infrastructure overlap with known IOCs, pre-wiper reconnaissance spikes
Pioneer Kitten exploitation of CVE-2026-25089 against Western critical infrastructure targets35%Next 7 daysFortiSandbox management interface connections from Iranian ASNs; new C2 callbacks from patched or unpatched systems
APT34 / OilRig telecom espionage expansion to Malaysia, Australia, and Five Eyes-adjacent networks30%14–30 daysNew APT34 malware hash submissions; telecom sector anomalous authentication events; additional geographies in targeting data
ICS/OT disruption attempt against energy or water sector using Rockwell / Siemens vulnerabilities25%7–30 daysICS-CERT incident reports; Cyber Av3ngers public claims; OT scanning activity on EtherNet/IP networks
HOLLOWGRAPH technique reuse against non-Israeli targets (U.S. government, defense contractors)20%30+ daysM365 audit log anomalies; Graph API calendar permissions changes; CISA advisories on novel M365 TTPs

RuleData SourceATT&CKPriority
Outbound to Iranian C2 IPs 185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]169, 5.202.4[.]18 on any portFirewall / NetflowT1071CRITICAL
APT34 malware hashes present on any endpoint — SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc or fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392EDRT1562.001CRITICAL
FortiSandbox service account spawning shell process (/bin/sh, /bin/bash) or anomalous outbound connection from management interfaceEDR / SysmonT1190 T1059.004CRITICAL
Microsoft Graph API calendar create/modify event by service principal not in approved application listM365 Audit LogsT1102HIGH
EDR or AV service termination, process kill, or exclusion list modification by non-administrative accountEDR / Windows Event LogT1562.001HIGH
EtherNet/IP (TCP/44818) or Siemens SICAM protocol traffic originating from IT VLAN to OT controller segmentsOT Monitoring / IDST0846 T1499HIGH
System language enumeration API calls (IsValidLocaleName, GetUserDefaultLangID) before primary payload execution — indicative of Iranian-origin malware OPSECEDR / SysmonT1614.001MEDIUM
IOC Blocking Table:
185.93.89[.]4377.90.185[.]118185.93.89[.]75192.253.248[.]1695.202.4[.]18

Network: all five IPs on ASN213790 (Tehran) / ASN34918 (Pishgaman Toseeh) — Cactus ransomware C2, IcedID, LockBit, command injection. Confidence: 77–97. File: APT34/OilRig telecom-targeting malware SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc (confidence 85) and associated sample fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392 (confidence 70). Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
FortiSandbox exploitation (CVE-2026-25089)
Are any FortiSandbox instances accessible from the internet without patch 5.0.6+? Monitor management interfaces for unexpected outbound connections, new scheduled tasks, or shell process creation from the FortiSandbox service account. We are at Day 5 post-KEV — this is the active exploitation window for Pioneer Kitten.
HUNT 02 · T1071
Iranian C2 communication (ASN213790 / ASN34918)
Are any internal hosts communicating with ASN213790 (185.93.89.0/24, 77.90.185.0/24) or ASN34918 (5.202.0.0/16)? Check firewall logs, netflow, and DNS resolution attempts. Alert on any connection to the five listed IOC IPs at severity CRITICAL — historical connections also require investigation.
HUNT 03 · T1102
HOLLOWGRAPH Microsoft 365 Graph API abuse
Have any service principals created or modified calendar events via the Graph API outside of known scheduling applications in the past 60 days? Review M365 audit logs for OAuth token patterns from unusual service principals. Calendar events with encoded or obfuscated content in body/subject fields are high-priority indicators.
HUNT 04 · T1562.001
APT34 defense evasion and persistence
Any EDR or AV service termination, exclusion list modification, or debugger-presence check (IsDebuggerPresent, CheckRemoteDebuggerPresent API calls) in the past 30 days? Search for both listed APT34 SHA-256 hashes across endpoint telemetry. Registry queries to HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion from unusual processes are also indicative.
HUNT 05 · T0846
ICS/OT reconnaissance from IT segment
Is any EtherNet/IP traffic (TCP/44818) originating from IT VLANs reaching OT controller management ports? Verify network segmentation is enforced in practice, not just in documentation. Any new connections to Rockwell 1756-EN2/EN3/ENBT interfaces or Siemens SICAM management panels from unauthorized sources require immediate investigation.

Financial Services
Banking Infrastructure, Payment Systems
Primary threats
Cactus ransomware via Iranian C2 infrastructure (ASN213790/ASN34918); IcedID initial access loader tagged on active infrastructure; potential destructive wiper masquerading as ransomware during retaliation window
Actions
  • Validate offline backup integrity for core banking systems — Iranian actors have historically deployed wipers disguised as ransomware (ZeroCleare, Shamoon)
  • Review SWIFT/payment system segmentation from general corporate networks
  • Monitor for IcedID initial access — typically arrives via malicious Office documents or hijacked email threads; tagged on active Iranian infrastructure
  • Block all five C2 IPs at perimeter deny lists; add ASN213790 and ASN34918 to threat intelligence watchlists
Energy
Grid, Substations, ICS/OT
Primary threats
ICS/OT disruption via Rockwell CompactLogix/ControlLogix DoS vulnerabilities and Siemens SICAM 8 substation exploitation; Cyber Av3ngers demonstrated intent and capability against energy sector OT; IOCONTROL ICS-targeting malware in active development
Actions
  • Inventory all Rockwell 1756-EN2/EN3/ENBT communication modules; verify firmware versions against ICSA-26-197-06 and ICSA-26-197-02
  • Patch Siemens SICAM 8 substation systems per ICSA-26-197-05; deploy monitoring for anomalous SICAM protocol traffic
  • Ensure safety instrumented systems (SIS) are physically isolated — not just logically segmented
  • Pre-position OT incident response playbooks; confirm manual override procedures are documented and tested
Healthcare
Clinical Systems, EHR, Medical Devices
Primary threats
Ransomware deployment via Cactus/LockBit infrastructure with potential for patient safety impact; Iranian actors have targeted hospitals during geopolitical tension peaks; CVE-2026-25089 may expose FortiSandbox-protected healthcare networks
Actions
  • Verify medical device network segmentation — particularly embedded Windows devices that cannot be patched
  • Ensure clinical systems (EHR, PACS, lab systems) have tested offline operation procedures
  • Monitor for IcedID loader activity — the initial access vector tagged on active Iranian infrastructure
  • Review FortiSandbox deployments; CVE-2026-25089 is a direct path to network compromise from sandboxing appliances
Government
.gov Systems, Cleared Personnel
Primary threats
Espionage via APT34/OilRig (telecom interception, credential harvesting); HOLLOWGRAPH M365 C2 technique specifically designed to evade government SOC detection; Rampant Kitten domestic surveillance tools may pivot to external government targets
Actions
  • Audit Microsoft 365 Graph API permissions — revoke unnecessary calendar API access for service principals
  • Hunt for HOLLOWGRAPH indicators: calendar events with encoded/obfuscated content created by non-human accounts
  • Review FortiSandbox deployments in .gov environments — CVE-2026-25089 is a direct path to network compromise
  • Deploy APT34 hash detections across all endpoint platforms; increase monitoring on cleared personnel accounts for anomalous access patterns
  • Coordinate with CISA for sector-specific threat briefings on Iranian retaliation scenarios
Aviation / Logistics
Aerospace, DIB Contractors, Cargo
Primary threats
APT33 (Elfin) historically targets aerospace with Shamoon-lineage destructive malware; Pioneer Kitten uses DIB contractor networks as pivot points; SALTO ProAccess Space physical access control privilege escalation in airport/port environments (ICSA-26-197-07)
Actions
  • Review supply chain connections to Defense Industrial Base contractors — Pioneer Kitten uses contractor networks as pivot points into prime contractors
  • Monitor for APT33-associated TTPs: spearphishing with job-themed lures targeting aviation engineers
  • Verify OT systems in airport/port environments (baggage handling, cargo management, navigation aids) are properly segmented
  • Assess exposure to SALTO ProAccess Space vulnerability (ICSA-26-197-07) — privilege escalation in widely deployed physical access control systems
No sector cards match the selected filters.

Patch FortiSandbox to version 5.0.6+ — CVE-2026-25089 (CVSS 9.8) is confirmed exploited in the wild; we are at Day 5 post-KEV. If patching requires a maintenance window, restrict all external access to FortiSandbox management interfaces immediately. Pioneer Kitten's exploitation window is now.
Incident Responder
Block Iranian C2 infrastructure — Add 185.93.89[.]43, 185.93.89[.]75, 77.90.185[.]118, 192.253.248[.]169, and 5.202.4[.]18 to perimeter deny lists and SIEM watchlists. Alert on any historical connections at severity CRITICAL.
SOC Analyst
Deploy APT34 hash detections — Add SHA-256 50ebfa1dd5b147e40244607d5d5be25709edf2cc66247a78beb920c77ac514cc and fe1b011fe089969d960d2dce2a61020725a02e15dbc812ee6b6ecc6a98875392 to EDR block lists immediately. Same-day refresh on July 21 confirms active operations.
SOC Analyst
Initiate proactive hunt for hacktivist staging — Monitor Telegram channels, paste sites, and dark web forums for Handala, Cyber Av3ngers, DieNet, and 313 Team activity. 24-day silence after a kinetic trigger is a warning, not an all-clear.
Threat HunterSOC Analyst
No immediate actions for the selected roles.
Audit Rockwell CompactLogix / ControlLogix firmware against ICSA-26-197-06 and ICSA-26-197-02. Verify 1756-EN2/EN3/ENBT communication modules are network-segmented from IT environments. Confirm no EtherNet/IP traffic crosses IT/OT boundary from unauthorized sources.
ICS / OT
Audit Microsoft 365 Graph API calendar permissions — Restrict calendar API access to known applications via Conditional Access policies. Deploy detection for anomalous calendar event creation patterns (HOLLOWGRAPH C2 technique, active since June 3 against Israeli targets).
IAM AnalystSOC Analyst
Add ASN213790 and ASN34918 as monitored autonomous systems — Iranian APT infrastructure is deliberately diversifying hosting providers. Single-ASN blocking is no longer sufficient. Alert on any new connections to either ASN from internal hosts.
SOC Analyst
Update incident response playbooks for Iranian wiper scenarios — Ensure playbooks cover ZeroCleare, HOLLOWGRAPH, and IOCONTROL. Pre-position forensic images and recovery media. Verify offline backup integrity under the assumption that Active Directory and backup infrastructure may be simultaneously compromised.
Incident Responder
Brief executive leadership on retaliation probability and potential business impact — the most dangerous phase of the retaliation cycle is active now. Ensure crisis communication plans cover a destructive cyber event. Confirm the board understands the threat level is CRITICAL, not elevated.
CISO / Exec
No 7-day actions for the selected roles.
Patch Siemens SICAM 8 substation automation systems per ICSA-26-197-05. Deploy network monitoring for anomalous SICAM protocol traffic. Confirm safety instrumented systems are physically isolated, not just logically segmented.
ICS / OT
Commission red team exercise simulating Iranian retaliation scenario — include FortiSandbox exploitation (CVE-2026-25089), lateral movement to OT environment, and wiper deployment. Validate detection coverage against the specific TTPs documented in this brief before the retaliation window closes.
CISO / ExecIncident Responder
Evaluate threat intelligence feed coverage — current collection has structural gaps in hacktivist and operational intelligence. Consider adding Telegram monitoring, paid Iranian proxy group tracking, and additional OSINT feeds to close the visibility gap that makes the current 24-day silence unverifiable.
CISO / Exec
Validate backup and recovery capabilities under destructive attack assumptions — test restoration of critical systems from offline backups with the assumption that Active Directory, DNS, and backup infrastructure are simultaneously compromised. Time this test before the retaliation window closes.
Incident Responder
No 30-day actions for the selected roles.
The Bottom Line

Nearly five months into the U.S.-Iran military confrontation and 25 days past the most significant kinetic trigger — direct U.S. strikes on Iranian territory — we are in the most dangerous phase of the retaliation cycle. The infrastructure is active. The vulnerabilities are disclosed. The proxies are silent. Iranian cyber doctrine treats cyber operations as asymmetric force multipliers — cheaper than missiles, deniable through proxies, capable of strategic impact against civilian infrastructure. The 2022 Albanian government wiper, the 2023 Israeli water system attacks, and the ongoing HOLLOWGRAPH campaign all demonstrate that Iran executes on this doctrine. The only variable is timing.

1
Is your FortiSandbox patched to 5.0.6+? CVE-2026-25089 is CVSS 9.8, unauthenticated, and Pioneer Kitten has a documented 24–72 hour exploitation pattern after KEV listing. You are at Day 5.
2
Are the five Iranian C2 IPs blocked at your perimeter? Same-day infrastructure activity at confidence 97 signals operational readiness — not dormant threat, not noise.
3
Does your IR team have a wiper-scenario playbook ready today? The silence from Handala, Cyber Av3ngers, DieNet, and 313 Team should concern you more than if they were loud.
No items found.