TLP:GREEN  ·  Iran / Israel Conflict
Iran’s Cyber Arsenal Is Reloading:

What CISOs Need to Know Right Now

ELEVATED. Iranian operations are refreshing C2 infrastructure, reviving a 31-day dormant aerospace phishing campaign, and expanding their ICS surface — while hacktivist proxies stay silent. A Fortinet flaw (CVE-2025-25249) hit CISA KEV, weaponized as a firewall-resident RAT, and C2 across three malware families was refreshed today.

I am a
My sector

DateDevelopmentSignificance
Sep 9, 2026FortiOS CVE-2025-25249 added to CISA KEV — CVSS 8.1, weaponized as PivotC2 FortiGate RATPioneer Kitten's preferred access vector
Sep 10, 2026Iranian C2 refreshed — Cobalt Strike, AsyncRAT, Mirai co-hosted on one Shatel /24Shared staging ground for Iranian ops
Sep 10, 2026UNC6446 aerospace phishing reactivated after 31 days, via GitHub fake-resume luresRenewed DIB pre-positioning
Through Sep 3, 2026UNC7033 ClickFix campaign remains active vs. think tanks and policy orgsEvades traditional email/URL security
Sep 3–8, 2026ICS attack surface expanded — 5 new CISA advisories (Schneider, Rockwell, IXON, CareCam, Pyramid)Widens OT surface across energy/mfg
OngoingPro-Iran hacktivists gone silent (Handala, Cyber Toufan, DieNet, 313 Team)Historically a pre-surge indicator

PhaseTimeframeCyber Activity
Conflict onsetFeb 28, 2026Iran-Israel military confrontation begins; cyber operations become a below-threshold escalation lever
Sustained espionage operationsJul 5 – Aug 27, 2026UNC7033 ClickFix campaign active against think tanks and policy influencers
Dormancy window~Aug 10 – Sep 2, 2026UNC6446/Pioneer Kitten aerospace campaign goes quiet (31-day gap); hacktivist groups also silent
ICS/OT surface expansionSep 3–8, 2026Five ICS advisories published; Microsoft patches 974 CVEs; CareCam Pro camera advisory issued
Capability reconstitution (current)Sep 9–10, 2026FortiOS CVE-2025-25249 added to KEV; Agentemis/Cobalt Strike C2 refreshed; UNC6446 reactivated; 25 Iranian actor profiles updated

UNC6446’s phishing reactivation and the FortiOS KEV listing landed the same day: Pioneer Kitten (Fox Kitten, PARISITE) exploits Fortinet flaws for access, falling back to GitHub lures when patching blocks the path. Close both doors at once.

T1190T1566.002T1204.001T1078T1105

217.60.241.x/24 on Shatel DSL co-hosts Cobalt Strike (443), AsyncRAT (8808), and a Mirai variant — one operator, three mission sets. Treat the whole /24 as hostile.

T1071.001T1071.004T1059.001T1583.003

UNC7033 impersonates US think tanks, staging encrypted payloads in browser storage before tricking victims into pasting shell commands ("ClickFix") — bypassing email/URL scanners. Active vs. ceasefire and nuclear-policy targets.

T1566.002T1204.002T1027.013T1059T1102

Five ICS advisories (Sep 3–8) widen the OT surface across substation control (Schneider), PLC tooling (Rockwell ControlFLASH), remote VPN access (IXON), IP cameras (CareCam Pro), and industrial protocol stacks (Pyramid NetStaX). Cyber Av3ngers has previously targeted water/energy ICS.

T1190T0831T0816T1133

Handala, Cyber Toufan, DieNet, and 313 Team have gone quiet for multiple cycles — historically a pre-escalation signal. Discipline, retooling, or pre-positioning — none reassuring. This is a warning, not a reprieve.

ProbabilityPredictionTimeframeBasis
70%Iranian C2 infrastructure on 217.60.241.x/24 will rotate to new IPs on the same or adjacent ASNs48–72 hoursPublic exposure via threat intelligence feeds typically triggers rapid infrastructure rotation
60%UNC6446/Pioneer Kitten will escalate the GitHub lure campaign with new repositories mimicking aerospace job postings7 daysCampaign refresh on Sep 10 signals active operator engagement; historical pattern shows escalation after dormancy
50%Pro-Iran hacktivist groups will resume disruptive operations (DDoS, wipers, defacements) if ceasefire negotiations stall or kinetic operations resume7–14 daysHacktivist silence during active state APT operations is historically a pre-surge indicator
40%CVE-2025-25249 (FortiOS) will be exploited by Iranian actors against unpatched targets7 daysPioneer Kitten has a documented pattern of rapid Fortinet exploitation; KEV listing confirms active weaponization
35%UNC7033 ClickFix technique will be adopted by additional Iranian groups beyond the original operator30 daysNovel TTPs that prove effective in the Iranian ecosystem tend to proliferate across IRGC and MOIS units

PriorityDetectionATT&CK IDData Source
IMMEDIATECobalt Strike BEACON on port 53 (DNS C2)T1071.004DNS logs, NDR
IMMEDIATEOutbound to 217.60.241.0/24 on any portT1071.001Firewall, proxy
IMMEDIATEFortiOS unexpected admin session or config changeT1078FortiGate syslog
7-DAYAsyncRAT on port 8808T1571NDR, EDR
7-DAYBrowser localStorage write → clipboard paste → shell executionT1204.002EDR
7-DAYGitHub resume lure links in email to DIB personnelT1566.002Email gateway
30-DAYEtherNet/IP protocol anomalies (Pyramid Solutions NetStaX)T0831OT network monitoring
IOC Blocking Table:
217.60.241[.]1787.107.191[.]39217.60.241[.]19217.60.241[.]39185.209.42[.]10578.38.19[.]161mabeyn[.]irpardisfilm[.]irliasang-westasia[.]comtirfile[.]irmmc100[.]irdarmanjoo[.]com

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1071.004
Hunt 1 — Cobalt Strike DNS C2 (T1071.004)
Search for DNS queries to 87.107.191[.]39 on port 53, or anomalous DNS TXT record volumes to any IP in the 87.107.191.0/24 range. Cobalt Strike's DNS beacon uses TXT records for data exfiltration. Look for DNS queries with unusually long subdomain labels (>30 characters) — a hallmark of DNS-tunneled C2.
HUNT 02 · T1571
Hunt 2 — AsyncRAT on Non-Standard Ports (T1571)
Search for outbound connections to port 8808 across all endpoints. AsyncRAT commonly uses non-standard ports to evade default firewall rules. Correlate with any .NET process spawning unexpected network connections.
HUNT 03 · T1190
Hunt 3 — FortiOS Post-Exploitation (T1190, T1059)
If your organization runs FortiOS 6.4–7.6.3, search FortiGate logs for: unexpected admin sessions, new local accounts, configuration changes to VPN settings, or outbound connections from the management interface to unknown IPs. The PivotC2 RAT turns the appliance itself into a C2 node — look for the firewall talking to infrastructure it shouldn't.
HUNT 04 · T1027.013
Hunt 4 — ClickFix Browser Storage Staging (T1027.013, T1204.002)
Monitor for browser processes writing large encoded blobs to localStorage or sessionStorage followed by clipboard paste events containing encoded PowerShell, bash, or osascript commands. This is UNC7033's signature delivery mechanism. EDR telemetry showing cmd.exe or powershell.exe spawned from a browser process with clipboard-sourced arguments is a high-fidelity detection.
HUNT 05 · T1566.002
Hunt 5 — GitHub-Hosted Lure Detection (T1566.002, T1204.001)
Search email logs and web proxy logs for links to GitHub repositories containing resume-themed content (keywords: "resume," "CV," "portfolio," "job application") sent to aerospace, defense, or engineering personnel. UNC6446 uses GitHub's legitimate reputation to bypass URL filtering.
HUNT 06
Hunt 6 — Shatel DSL /24 Range Sweep
Search all network telemetry for any connection to the 217.60.241.0/24 range. Given multi-family malware co-hosting, any connection to this subnet — even to IPs not yet individually flagged — should be investigated.

Financial Services
Perimeter, Access Brokering
Primary threat
FortiOS exposure; Agentemis/AsyncRAT brokering (not sector-specific)
Actions
  • Patch FortiOS; block C2 IPs; brief exec on impersonation risk
Energy
Substation Control, OT Access
Primary threat
5 ICS advisories hit substation/PLC/VPN control; Cyber Av3ngers precedent
Actions
  • Patch Schneider/IXON; segment ControlFLASH; watch EtherNet/IP
Healthcare
Edge Devices, Physical Security
Primary threat
FortiOS exposure; CareCam Pro full-takeover camera flaw
Actions
  • VLAN-isolate cameras; block AsyncRAT node `217.60.241[.]19`
Government
Defense, Diplomacy, Policy
Primary threats
UNC6446 (aerospace lures), UNC7033 (ClickFix), APT42/IRGC-IO (nuclear policy)
Actions
  • Deploy Hunts 1-6 (emphasize 4/5); patch FortiOS in 24h
Aviation / Logistics
DIB Recruiting Workflows
Primary threat
UNC6446 fake-resume GitHub lures exploit hiring workflows
Actions
  • Brief HR on resume-lure TTP; patch FortiOS; block Agentemis C2
No sector cards match the selected filters.

Patch FortiOS 7.6.4+ for CVE-2025-25249 (KEV, PivotC2 confirmed).
Incident Responder
Block C2 IPs/domains: 217.60.241[.]17/19/39, 87.107.191[.]39, 185.209.42[.]105, 78.38.19[.]161, mabeyn[.]ir, tirfile[.]ir, darmanjoo[.]com.
SOC Analyst
Verify FortiGate integrity — admins, VPN config, mgmt egress.
Incident Responder
Brief execs & pre-authorize emergency patch windows.
CISO / Exec
No immediate actions for the selected roles.
Deploy signatures: CS DNS-C2 (53), AsyncRAT (8808); detect ClickFix storage-write → clipboard exec.
SOC Analyst
Brief recruiting on GitHub resume lures.
CISO / Exec
Patch OT & isolate cameras: Schneider, IXON VPN, VLAN-isolate CareCam Pro.
ICS / OT
No 7-day actions for the selected roles.
Evaluate blocking the Shatel /24 wholesale; schedule Rockwell patching.
ICS / OTCISO / Exec
Red-team & rehearse: Forti/GitHub/OT paths, plus an IR playbook for a hacktivist surge.
Incident ResponderCISO / Exec
Diversify intel sources.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Six months into the Iran-Israel conflict, the cyber dimension is reloading, not winding down. Iranian actors are refreshing infrastructure, reviving UNC6446, and landing a Fortinet flaw on KEV that fits Pioneer Kitten’s playbook — ensuring that if one access vector is blocked, another stays open. The silence from Handala, Cyber Toufan, DieNet, and 313 Team — groups that have hit 100+ US water systems with wipers — is not peace. It is preparation.

1
Have you patched FortiOS today?
2
Have you blocked the Shatel DSL C2 infrastructure?
3
Is your IR playbook ready for a hacktivist surge?
No items found.