TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber Arsenal Expands:

Critical Check Point Zero-Day, ICS Vulnerabilities, and Ransomware Convergence Demand Immediate Action

HIGH. Five months into the Iran-Israel conflict, Iranian state-sponsored cyber operations are accelerating in sophistication and scope. CISA has confirmed active exploitation of CVE-2026-16232, a CVSS 9.1 authentication bypass granting full administrative control of Check Point SmartConsole to any unauthenticated attacker. Simultaneously, seven new ICS advisories expose foundational power grid protocols to unauthenticated attack, and Iranian state espionage actors, hacktivist-cover operations, and ransomware-as-revenue groups are confirmed sharing infrastructure on the same Iranian ASNs.

I am a
My sector

DateDevelopmentSignificance
Jul 27CVE-2026-16232 (Check Point SmartConsole, CVSS 9.1) added to CISA KEVAuth bypass grants full admin control; exploitation confirmed against a "very small number of customers" — expected to grow rapidly
Jul 27CVE-2025-68686 (FortiOS symlink persistence) added to CISA KEVDefeats prior patch remediation — organizations may still harbor persistent access from before they patched
Jul 28Cavern Manticore (MOIS) threat profile refreshedHigh operational tempo; modular .NET C2 framework designed to evade analysis
Jul 28Cactus ransomware C2 confirmed active on Iranian ASNs (213790, 215930, 34918)State-criminal infrastructure convergence validated, confidence 77–91
Jul 23Seven CISA ICS advisories published (IEC 61850, IEC 60870-5-104, Rockwell, Johnson Controls, Panduit)Foundational power grid protocols exposed to unauthenticated attack
Jul 25–28APT42's TAMECAT backdoor silent 3+ days; BELLACIAO/SHELLAFEL campaign updated Jul 28Likely tooling rotation rather than operational pause
Jul 27PULSAR KITTEN profile refreshed — confirmed targeting a U.S. transportation company via its German subsidiaryDemonstrates deliberate exploitation of international subsidiaries as weaker entry points

PhaseTimeframeCyber Activity
Escalation begins2026-02-28Iran-Israel conflict escalation begins; marks start of sustained state-on-state cyber operations
Coordination & tooling buildupJul 18 – 23MuddyWater/Dalbit ransomware samples confirmed active (defense, energy, government); APT42 AI-generated phishing with TAMECAT against defense officials (Jul 21); CISA publishes 7 ICS advisories exposing IEC 61850/60870-5-104 (Jul 23)
Active exploitation & retaliation windowJul 25 – 28Qilin RaaS affiliates exploit Fortinet/Palo Alto/Check Point/Citrix VPNs, ~75,000 FortiGate devices compromised (Jul 25–27); Ukrainian strike eliminates Iran's Caspian Sea maritime corridor (Jul 26); APT42 infrastructure refreshed (Jul 26); CVE-2026-16232 (Check Point) and CVE-2025-68686 (FortiOS) added to CISA KEV (Jul 27); PULSAR KITTEN targeting U.S. transportation via German subsidiary confirmed (Jul 27)
Current (Day 150)Jul 28, 2026Cavern Manticore (MOIS) Operation Epic Fury profile refreshed at high tempo; Cactus ransomware C2 confirmed on Iranian ASN 213790 (confidence 91) — state-criminal infrastructure convergence validated

CVE-2026-16232 represents the most urgent patching priority this week. An unauthenticated attacker can obtain a full administrative token for any Check Point SmartConsole management server accessible from the internet without Trusted Client restrictions. The implications are severe: complete firewall policy manipulation, VPN credential extraction, and network-wide visibility for the attacker.

CVE-2025-68686 is equally concerning for a different reason — it defeats the remediation for a previously patched symlink persistence mechanism in FortiOS. Organizations that patched earlier Fortinet vulnerabilities may still harbor persistent access if attackers exploited the original flaw before patching. Affects FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, and all 7.2/7.0/6.4 branches.

Why it matters: Pioneer Kitten (Fox Kitten, RUBIDIUM) has a documented pattern of weaponizing firewall and VPN authentication bypasses within two weeks of KEV listing. Its known exploit arsenal already includes CVE-2022-47966, CVE-2021-44228, CVE-2022-26134, CVE-2021-34473, and CVE-2018-13379.

T1190T1078.004T1098T1547.009

Intelligence confirms an operational convergence between Iranian state espionage actors, hacktivist-cover operations, and ransomware-as-revenue groups sharing infrastructure: Pioneer Kitten (IRGC-affiliated espionage), Handala / Banished Kitten (hacktivist-cover operations), and Cactus ransomware (criminal revenue generation).

These actors share IOCs, infrastructure on Iranian ASNs (213790, 34918, 215930), and targeting profiles. The same IPs tagged to Cactus ransomware C2 are co-located on networks hosting LockBit-affiliated infrastructure — a deliberate operational model where state actors use ransomware personas for deniability and revenue while maintaining espionage access. Active C2 on ASN 213790 (Limited Network) is tagged with both IcedID loader delivery and Cactus operations, targeting healthcare, government, education, and technology.

T1566.001T1204.002T1071T1571

The libIEC61850 vulnerability (ICSA-26-204-06) deserves particular attention. IEC 61850 is the international standard for substation automation communication — it underpins power grid operations globally. The vulnerability allows an unauthenticated network-adjacent attacker to crash IEC 61850 services, creating denial-of-service conditions at substations.

Similarly, lib60870 (ICSA-26-204-07) affects IEC 60870-5-104, the standard for SCADA telecontrol. Both are open-source libraries used across multiple vendor implementations — meaning the blast radius extends far beyond any single product.

Threat actor context: Cyber Av3ngers (IRGC-affiliated) has demonstrated both intent and capability to target water and energy infrastructure. These protocol-level vulnerabilities require no authentication and only network adjacency — a low bar for an actor that has already demonstrated ICS access.

T1499T0816T0826

Cavern Manticore — linked to Iran's Ministry of Intelligence and Security (MOIS) — is conducting destructive operations against Israeli government and IT sectors under the campaign name "Operation Epic Fury." The group employs a modular .NET C2 framework with multiple compilation formats as an anti-analysis layer, combined with wiper capabilities.

This actor operates alongside MuddyWater (also MOIS-affiliated) in an apparent division of labor: MuddyWater handles initial access and espionage, while Cavern Manticore executes destructive payloads when political objectives demand visible impact.

T1059.001T1027T1071.001T1485

A refreshed profile for PULSAR KITTEN reveals targeting of a German branch of a U.S. transportation company — demonstrating the Iranian playbook of attacking Western organizations through their international subsidiaries where security controls may be weaker. The actor deploys SilkySand and SurveyAgent malware, focuses on aerospace, defense, and satellite organizations, and maintains infrastructure overlap with operations against Iraqi telecom entities.

T1190T1219T1110

ScenarioProbabilityTimeframeIndicators to Watch
CVE-2026-16232 exploitation expands beyond initial victims as PoC circulates70%7 daysPublic PoC release, exploitation volume increase in vendor telemetry, additional victim disclosures
Coordinated retaliatory cyber operations by Handala/Cyber Toufan/DieNet following kinetic escalation70%7–14 daysTelegram channel reactivation, new leak sites, DDoS infrastructure provisioning
Pioneer Kitten weaponizes CVE-2025-68686 for persistent access to previously-patched FortiGate devices55%14–21 daysFortinet-heavy exploit portfolio; symlink persistence bypass enables re-entry
APT42 surfaces with BELLACIAO or SHELLAFEL indicators (tooling rotation from TAMECAT)50%7–14 daysCampaign infrastructure updated Jul 28 but TAMECAT silent 3+ days — active tool-swap pattern
Iranian election influence operations surge targeting Israeli elections45%14–21 daysHistorical IO campaigns activate 2–3 weeks before elections; current silence may indicate OPSEC pause before surge
Cyber Av3ngers probes libIEC61850 implementations in Israeli/Gulf power infrastructure35%14 daysVulnerability requires only network adjacency, targets exact protocol stack in regional power infrastructure

Highest Priority · Check Point Management Exploitation:

Alert on SmartConsole admin logins from non-whitelisted source IPs. Monitor for bulk policy export or rule modification events. Correlate with Trusted Client configuration — any management server without this restriction is vulnerable (CVE-2026-16232).

High Priority · FortiOS Symlink Persistence:

Post-patch integrity verification of FortiOS filesystem. Compare running configuration against known-good baseline. Monitor for FortiGate devices communicating with IPs on ASN 213790 or 215930 (CVE-2025-68686).

High Priority · Cactus/IcedID Delivery Chain:

Monitor for outbound connections to 77.90.185[.]118, 62.60.130[.]237, 5.202.4[.]18, 185.93.89[.]75. Alert on IcedID-characteristic HTTPS patterns on non-443 ports.

Elevated Priority · ICS Protocol Anomalies:

Deploy ICS-aware network monitoring on OT segments. Alert on any non-whitelisted source communicating with IEC 61850/60870-5-104 services (port 102/TCP). Baseline normal MMS traffic patterns and alert on deviations.

Elevated Priority · .NET C2 Framework (Cavern Manticore):

Monitor for csc.exe or msbuild.exe invocations outside development environments. Alert on .NET assemblies loaded from temp directories. Behavioral detection for wiper precursors (volume shadow copy deletion, boot record access).

Monitoring Priority · LegacyHive Registry Technique:

Monitor Windows Event ID 1 (process creation) for profile loading utilities accessing non-standard registry paths. Alert on registry hive file access outside normal logon sequences.

Monitoring Priority · AutoIT Process Injection (VIPKeylogger):

Alert on charmap.exe establishing network connections (should never happen legitimately). Monitor for AutoIT script execution preceded by PowerShell. Block cphost17[.]qhoster[.]net at DNS.

ThreatATT&CK
Check Point Management ExploitationT1190 T1078.004 T1098
FortiOS Symlink PersistenceT1190 T1547.009 T1562.001
Cactus/IcedID Delivery ChainT1566.001 T1204.002 T1071 T1571
ICS Protocol AnomaliesT1499 T0816 T0826
.NET C2 Framework (Cavern Manticore)T1059.001 T1027 T1071.001 T1485
LegacyHive Registry TechniqueT1546 T1003
AutoIT Process Injection (VIPKeylogger)T1055 T1059.005 T1059.001
IOC Blocking Table:
77.90.185[.]11862.60.130[.]237185.93.89[.]755.202.4[.]182.188.214[.]142cphost17[.]qhoster[.]net

IPv4s above: Cactus ransomware C2 / IcedID (ASN 213790, 215930, 34918), confidence 77–91. Domain: VIPKeylogger C2 (AutoIT injection campaign). SHA-256 (selected): 028d3de0f0709a18c9928526519e761a08f6766d1eca386e908588f995f44e7f, 0a5cf97e699c8bfacee7f89ebfaa851ff03dd004a58ffde9c609fcc2cd27f250 (Pioneer Kitten/Handala convergence), bcf0ee6ec34d835b2521330f57466e357b95970129e5c0742c6da7c40bda56fb (MuddyWater/MOIS). 14 total SHA-256 hashes available via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01 · T1190
Check Point Management token abuse
Attackers are obtaining admin tokens from internet-exposed Check Point SmartConsole servers. Look for anomalous admin session creation from external IPs, policy changes outside change windows, new VPN user provisioning without tickets.
HUNT 02 · T1547.009
FortiGate re-compromise via symlink bypass
Attackers who previously compromised FortiGate devices may retain access via symlink persistence even after patching. Look for unexpected symbolic links in FortiOS filesystem, configuration drift post-patch, outbound connections from management interfaces to unknown destinations.
HUNT 03 · T1071
IcedID → Cactus delivery chain
IcedID loaders are delivering Cactus ransomware payloads via phishing. Look for IcedID beacon patterns (HTTPS POST to non-standard ports), process injection into legitimate Windows processes, lateral movement following initial infection.
HUNT 04 · T1499
ICS protocol probing
Adversaries may probe IEC 61850 MMS services for crash conditions. Look for malformed MMS packets, unexpected connection attempts to port 102/TCP, service restarts on substation automation systems.
HUNT 05 · T1071.001
Cavern Manticore .NET C2
Cavern Manticore uses modular .NET payloads with multiple compilation formats to evade static analysis. Look for unusual .NET assembly loading patterns, PowerShell downloading and executing .NET binaries.

Financial Services
Banking Trojans, Loader Convergence
Primary threats
IcedID loaders converging with Cactus ransomware on Iranian infrastructure; VIPKeylogger campaign using fake bank emails (Banc Sabadell lures observed) targeting financial credentials
Actions
  • Deploy behavioral detection for IcedID HTTPS beacon patterns (POST requests with encoded payloads to non-standard ports)
  • Review email gateway rules for RAR attachments containing VBS files; implement detonation sandboxing for compressed archive attachments from external senders
  • Watch for process injection into charmap.exe — a novel evasion technique for financial malware in this campaign
Energy
Substation Automation, SCADA Telecontrol
Primary threats
libIEC61850 and lib60870 vulnerabilities — existential risk for substation automation; Cyber Av3ngers (IRGC) has demonstrated intent and capability against water/energy ICS
Actions
  • Conduct emergency inventory of all systems using IEC 61850 MMS or IEC 60870-5-104 protocols; verify network segmentation between corporate IT and OT networks
  • Deploy ICS-aware intrusion detection on OT segments monitoring for malformed MMS packets; engage vendors to confirm patch availability
  • Implement strict access control lists limiting which systems can communicate on port 102/TCP
Healthcare
Cactus C2, ASN-Tagged Targeting
Primary threats
Cactus ransomware C2 infrastructure on Iranian ASNs explicitly tagged as targeting healthcare; IcedID delivery chain providing initial access for ransomware deployment
Actions
  • Block all communication with IPs on ASN 213790 (Limited Network) and ASN 34918 (Pishgaman Toseeh) — both confirmed hosting Cactus C2 targeting healthcare
  • Verify backup integrity and test restoration procedures for critical clinical systems
  • Hunt for SHA-256 hashes associated with Pioneer Kitten/Cactus convergence across endpoint telemetry; review logs for connections to 77.90.185[.]118 and 5.202.4[.]18
Government
Destructive Wipers, AI Phishing
Primary threats
Cavern Manticore's Operation Epic Fury targets government IT with destructive wipers; APT42 targets defense officials with AI-generated phishing; PULSAR KITTEN targets aerospace/defense via international subsidiaries
Actions
  • Implement enhanced monitoring for .NET assembly loading from non-standard paths (Cavern Manticore indicator)
  • Review all personnel who received external communications in the past 30 days for APT42-style social engineering; verify no Check Point management servers are internet-accessible without Trusted Client restrictions
  • Conduct a tabletop exercise for a wiper scenario; ensure offline backup copies exist for critical government systems
Aviation / Logistics
International Subsidiaries, Supply Chain
Primary threats
PULSAR KITTEN's confirmed targeting of a U.S. transportation company via its German subsidiary — deploying SilkySand and SurveyAgent malware, exploiting known vulnerabilities in internet-facing applications
Actions
  • Audit security controls at international subsidiaries and branch offices — Iranian actors deliberately target weaker links; review for CVE-2022-47966, CVE-2021-44228, CVE-2022-26134, CVE-2021-34473
  • Implement network segmentation between subsidiary environments and core transportation/logistics systems
  • Deploy detection for AnyDesk (T1219) usage outside approved remote access channels — PULSAR KITTEN uses legitimate remote access tools for persistence
No sector cards match the selected filters.

Verify ALL Check Point Management Servers are NOT internet-accessible without Trusted Client restrictions. CVE-2026-16232 (CVSS 9.1) grants full admin via auth bypass — confirmed exploited in the wild.
IAM Analyst
Apply FortiOS patches for CVE-2025-68686 across all 7.x branches. Post-patch: verify filesystem integrity for residual symlinks from prior compromise.
IAM Analyst
Block IPs 77.90.185[.]118, 62.60.130[.]237, 185.93.89[.]75, 5.202.4[.]18 at perimeter firewalls and DNS sinkholes. Confirmed Cactus ransomware C2, confidence 77–91.
SOC Analyst
Block domain cphost17[.]qhoster[.]net at DNS — active VIPKeylogger C2.
SOC Analyst
Deploy hash-based detection for Pioneer Kitten/MuddyWater SHA-256 indicators across all endpoint detection platforms.
SOC Analyst
Confirm incident response retainer is active and responder availability is confirmed. Threat environment supports 70% probability of expanded exploitation within 7 days.
CISO / ExecIncident Responder
No immediate actions for the selected roles.
Deploy IEC 61850 MMS protocol anomaly detection on all OT network segments. Baseline normal traffic and alert on malformed packets or connections from non-whitelisted sources to port 102/TCP.
ICS / OT
Hunt across endpoint telemetry for all SHA-256 hashes in the IOC table. Prioritize Pioneer Kitten and MuddyWater indicators.
Threat Hunter
Audit Johnson Controls C-CURE 9000 and Victor application servers for network exposure. ICSA-26-204-01 enables RCE — physical security system compromise has cascading impact.
IAM Analyst
Implement behavioral detection for .NET assemblies loaded from %TEMP% directories outside development environments (Cavern Manticore indicator).
SOC Analyst
Audit all Rockwell ThinManager deployments for ICSA-26-204-05 — authenticated arbitrary file write to restricted directories.
IAM Analyst
Review email gateway rules: block or detonate RAR attachments containing VBS files from external senders (VIPKeylogger delivery chain).
SOC Analyst
No 7-day actions for the selected roles.
Commission comprehensive assessment of IEC 61850 and IEC 60870-5-104 protocol stack exposure across all substation and SCADA automation. Unknown blast radius — analogous to Log4Shell for OT.
CISO / ExecICS / OT
Conduct a tabletop exercise for a destructive wiper scenario based on Cavern Manticore TTPs. Validate offline backup availability and restoration timelines for critical systems.
CISO / Exec
Audit security controls at all international subsidiaries and branch offices. PULSAR KITTEN specifically targets Western organizations through weaker international links. Verify patching for CVE-2022-47966, CVE-2021-44228, CVE-2022-26134, CVE-2021-34473.
CISO / Exec
Implement network segmentation review ensuring Check Point management planes, FortiGate management interfaces, and ICS/OT protocol services are not reachable from untrusted networks.
IAM Analyst
Evaluate intelligence collection diversity — single-source dependency on any OSINT provider creates unacceptable blind spots. Ensure at least two independent collection channels for each priority intelligence requirement.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The Iran-Israel conflict is now 150 days old with no indication of de-escalation. Iranian cyber operations are not slowing — they are diversifying. The convergence of state espionage actors with ransomware operations, the targeting of foundational ICS protocols, and the active exploitation of critical network security infrastructure (Check Point, Fortinet) create a threat environment where defensive complacency carries measurable risk. The 70% probability of expanded CVE-2026-16232 exploitation within seven days is not a forecast — it is a countdown.

1
Is your Check Point Management Server internet-accessible without Trusted Client restrictions? A 70% probability of expanded exploitation within 7 days is a countdown, not a forecast.
2
Have you re-verified FortiGate integrity post-patch? CVE-2025-68686 means prior remediation may not have been complete.
3
Does your insurance address nation-state "acts of war" exclusions? The Pioneer Kitten/Handala/Cactus convergence deliberately blurs the line between crime and state action.
No items found.