| Date | Development | Significance |
|---|---|---|
| Sep 9, 2026 | FortiOS CVE-2025-25249 added to CISA KEV — CVSS 8.1, weaponized as PivotC2 FortiGate RAT | Pioneer Kitten's preferred access vector |
| Sep 10, 2026 | Iranian C2 refreshed — Cobalt Strike, AsyncRAT, Mirai co-hosted on one Shatel /24 | Shared staging ground for Iranian ops |
| Sep 10, 2026 | UNC6446 aerospace phishing reactivated after 31 days, via GitHub fake-resume lures | Renewed DIB pre-positioning |
| Through Sep 3, 2026 | UNC7033 ClickFix campaign remains active vs. think tanks and policy orgs | Evades traditional email/URL security |
| Sep 3–8, 2026 | ICS attack surface expanded — 5 new CISA advisories (Schneider, Rockwell, IXON, CareCam, Pyramid) | Widens OT surface across energy/mfg |
| Ongoing | Pro-Iran hacktivists gone silent (Handala, Cyber Toufan, DieNet, 313 Team) | Historically a pre-surge indicator |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict onset | Feb 28, 2026 | Iran-Israel military confrontation begins; cyber operations become a below-threshold escalation lever |
| Sustained espionage operations | Jul 5 – Aug 27, 2026 | UNC7033 ClickFix campaign active against think tanks and policy influencers |
| Dormancy window | ~Aug 10 – Sep 2, 2026 | UNC6446/Pioneer Kitten aerospace campaign goes quiet (31-day gap); hacktivist groups also silent |
| ICS/OT surface expansion | Sep 3–8, 2026 | Five ICS advisories published; Microsoft patches 974 CVEs; CareCam Pro camera advisory issued |
| Capability reconstitution (current) | Sep 9–10, 2026 | FortiOS CVE-2025-25249 added to KEV; Agentemis/Cobalt Strike C2 refreshed; UNC6446 reactivated; 25 Iranian actor profiles updated |
UNC6446’s phishing reactivation and the FortiOS KEV listing landed the same day: Pioneer Kitten (Fox Kitten, PARISITE) exploits Fortinet flaws for access, falling back to GitHub lures when patching blocks the path. Close both doors at once.
217.60.241.x/24 on Shatel DSL co-hosts Cobalt Strike (443), AsyncRAT (8808), and a Mirai variant — one operator, three mission sets. Treat the whole /24 as hostile.
UNC7033 impersonates US think tanks, staging encrypted payloads in browser storage before tricking victims into pasting shell commands ("ClickFix") — bypassing email/URL scanners. Active vs. ceasefire and nuclear-policy targets.
Five ICS advisories (Sep 3–8) widen the OT surface across substation control (Schneider), PLC tooling (Rockwell ControlFLASH), remote VPN access (IXON), IP cameras (CareCam Pro), and industrial protocol stacks (Pyramid NetStaX). Cyber Av3ngers has previously targeted water/energy ICS.
Handala, Cyber Toufan, DieNet, and 313 Team have gone quiet for multiple cycles — historically a pre-escalation signal. Discipline, retooling, or pre-positioning — none reassuring. This is a warning, not a reprieve.
| Probability | Prediction | Timeframe | Basis |
|---|---|---|---|
| 70% | Iranian C2 infrastructure on 217.60.241.x/24 will rotate to new IPs on the same or adjacent ASNs | 48–72 hours | Public exposure via threat intelligence feeds typically triggers rapid infrastructure rotation |
| 60% | UNC6446/Pioneer Kitten will escalate the GitHub lure campaign with new repositories mimicking aerospace job postings | 7 days | Campaign refresh on Sep 10 signals active operator engagement; historical pattern shows escalation after dormancy |
| 50% | Pro-Iran hacktivist groups will resume disruptive operations (DDoS, wipers, defacements) if ceasefire negotiations stall or kinetic operations resume | 7–14 days | Hacktivist silence during active state APT operations is historically a pre-surge indicator |
| 40% | CVE-2025-25249 (FortiOS) will be exploited by Iranian actors against unpatched targets | 7 days | Pioneer Kitten has a documented pattern of rapid Fortinet exploitation; KEV listing confirms active weaponization |
| 35% | UNC7033 ClickFix technique will be adopted by additional Iranian groups beyond the original operator | 30 days | Novel TTPs that prove effective in the Iranian ecosystem tend to proliferate across IRGC and MOIS units |
| Priority | Detection | ATT&CK ID | Data Source |
|---|---|---|---|
| IMMEDIATE | Cobalt Strike BEACON on port 53 (DNS C2) | T1071.004 | DNS logs, NDR |
| IMMEDIATE | Outbound to 217.60.241.0/24 on any port | T1071.001 | Firewall, proxy |
| IMMEDIATE | FortiOS unexpected admin session or config change | T1078 | FortiGate syslog |
| 7-DAY | AsyncRAT on port 8808 | T1571 | NDR, EDR |
| 7-DAY | Browser localStorage write → clipboard paste → shell execution | T1204.002 | EDR |
| 7-DAY | GitHub resume lure links in email to DIB personnel | T1566.002 | Email gateway |
| 30-DAY | EtherNet/IP protocol anomalies (Pyramid Solutions NetStaX) | T0831 | OT network monitoring |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
87.107.191[.]39 on port 53, or anomalous DNS TXT record volumes to any IP in the 87.107.191.0/24 range. Cobalt Strike's DNS beacon uses TXT records for data exfiltration. Look for DNS queries with unusually long subdomain labels (>30 characters) — a hallmark of DNS-tunneled C2.cmd.exe or powershell.exe spawned from a browser process with clipboard-sourced arguments is a high-fidelity detection.217.60.241.0/24 range. Given multi-family malware co-hosting, any connection to this subnet — even to IPs not yet individually flagged — should be investigated.- Patch FortiOS; block C2 IPs; brief exec on impersonation risk
- Patch Schneider/IXON; segment ControlFLASH; watch EtherNet/IP
- VLAN-isolate cameras; block AsyncRAT node `217.60.241[.]19`
- Deploy Hunts 1-6 (emphasize 4/5); patch FortiOS in 24h
- Brief HR on resume-lure TTP; patch FortiOS; block Agentemis C2
217.60.241[.]17/19/39, 87.107.191[.]39, 185.209.42[.]105, 78.38.19[.]161, mabeyn[.]ir, tirfile[.]ir, darmanjoo[.]com.Six months into the Iran-Israel conflict, the cyber dimension is reloading, not winding down. Iranian actors are refreshing infrastructure, reviving UNC6446, and landing a Fortinet flaw on KEV that fits Pioneer Kitten’s playbook — ensuring that if one access vector is blocked, another stays open. The silence from Handala, Cyber Toufan, DieNet, and 313 Team — groups that have hit 100+ US water systems with wipers — is not peace. It is preparation.