TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber Retaliation Clock Hits Day 21:

What CISOs Must Do Now

HIGH. Twenty-one days after US CENTCOM struck Iranian missile and drone sites on June 26, 2026, Iran's cyber apparatus is in confirmed pre-positioning mode. Active command-and-control infrastructure is being refreshed on Iranian state-affiliated networks, a critical Fortinet vulnerability is under active exploitation, and the largest batch of ICS advisories in 2026 just dropped — all while Iran's most destructive hacktivist proxies maintain an ominous operational silence. The historical retaliation window is closing. If you haven't already shifted to a wartime cyber posture, today is the day.

I am a
My sector

DateDevelopmentSignificance
Jul 16CVE-2026-25089 (FortiSandbox, CVSS 9.8) added to CISA KEV — unauthenticated OS command injection affecting FortiSandbox 4.2–5.0.5, Cloud, and PaaSNew exploitation vector; Pioneer Kitten historically exploits every Fortinet KEV within 72 hours
Jul 16Nine ICS advisories published in a single day — five affecting Rockwell CompactLogix/ControlLogix, plus Siemens SICAM grid protection relaysOT attack surface expansion coinciding with the June 24 IOCONTROL update
Jul 17Seven Iran-hosted C2 nodes confirmed active, including Agentemis (Cobalt Strike loader) using DNS-over-port-53 and a Remcos RAT on an IRGC-adjacent academic networkIranian offensive infrastructure is expanding, not contracting
Jul 17UNC6496 IRGC attribution confirmed — credential phishing using SARAQAKIT/SILENTRAQIB kits against Middle East and US government targetsNew IRGC-adjacent group operating in proximity to APT42
OngoingPrior-cycle CVEs remain active and unresolved: SonicWall SMA1000 (CVE-2026-15409, CVSS 10.0), Oracle EBS (CVE-2026-46817, CVSS 9.8), SharePoint chain (CVE-2026-45659 + CVE-2026-32201) linked to the DHS HSIN breachThreat level held at HIGH (unchanged from Jul 16); today's developments add to an unresolved backlog

PhaseTimeframeCyber Activity
Initial escalationFeb 28, 2026 (Day 0)Iran-related conflict escalation begins — start of the current operational period
Regional wideningMay 12, 2026Saudi Arabia conducts covert attacks on Iran; regional war widens into multi-front pressure on Iran
Pre-strike positioningJun 24–25, 2026IOCONTROL ICS malware updated (no deployment sightings since); Iranian drone attack on a commercial vessel in the Strait of Hormuz — kinetic trigger
Kinetic escalationJun 26–29, 2026US CENTCOM strikes Iranian missile/drone sites, starting the retaliation clock; Israeli cyber chief confirms Iranian cyberattacks surged in 2026
Active retaliation windowJul 8–16, 2026DHS HSIN breach disclosed (SharePoint chain, confirmed access to US government networks); 10 Iranian actor profiles refreshed in ThreatStream; CISA KEV additions (SonicWall, Oracle EBS, FortiSandbox); 9 ICS advisories; APT34/OilRig reactivated
Current (Day 21)Jul 17, 2026Seven active Iran C2 IPs confirmed; UNC6496 IRGC attribution confirmed — the outer edge of the historical retaliation window

ASN213790 ("Limited Network," Iranian hosting) has emerged as the single most important infrastructure indicator in this conflict. Three IPs on this ASN are tagged to Cactus ransomware — the extortion partner used by Pioneer Kitten to monetize state-sponsored access: 185.93.89[.]75 (financial services), 77.90.185[.]118 (government/healthcare/technology), and 185.93.89[.]43 (healthcare/manufacturing, command injection capability).

Separately, two IPs host Agentemis, a custom Cobalt Strike loader attributed to Pioneer Kitten and MuddyWater: 217.60.241[.]17 (beacon on port 443) and 87.107.191[.]39 (DNS-over-port-53, a known MuddyWater evasion technique). A Remcos RAT node at 62.60.226[.]42 is hosted on an IRGC-adjacent academic network, operating on non-standard port 43155.

Why it matters: this is the convergence of state espionage and criminal extortion — Iranian intelligence gains access, then hands off to ransomware operators for monetization and plausible deniability.

T1572T1219

Iranian operations are converging around a coordinated set of IRGC- and MOIS-linked actors, several of them refreshed or reactivated in the past week:

ActorAffiliationStatus (Jul 17)Primary Capability
Pioneer Kitten / Fox KittenIRGCActive — C2 refresh confirmed; 72h window for CVE-2026-25089Network exploitation → ransomware handoff (Cactus/INC)
Handala / Banished Kitten / Cyber Av3ngersIRGCSilent 8+ days — assessed as pre-positioningDestructive wipers, ICS attacks (IOCONTROL), DDoS
APT34 / OilRigMOISReactivated Jul 15Espionage, credential harvesting, supply chain
MuddyWater / TEMP.ZagrosMOISSilent since Jul 12 — assessed as retoolingFirst-responder for retaliation; PowerShell / DLL sideloading
UNC6496IRGC (adjacent to APT42)Profile confirmed Jul 17; active phishingSARAQAKIT / SILENTRAQIB phishing kits
T1059.001T1574.002T1078

The July 16 advisory batch is not routine disclosure — it is a roadmap for adversaries already holding ICS-targeting capability. Five Rockwell products are affected (CompactLogix, ControlLogix, GuardLogix, FactoryTalk DataMosaix, Arena) plus Siemens SICAM 8 grid protection relays. Rockwell's CompactLogix/ControlLogix family is deployed in over 60% of US water treatment facilities.

IOCONTROL — the Iranian ICS malware updated June 24 — was designed for exactly this class of device. Cyber Av3ngers previously targeted Unitronics PLCs, the entry-level of this ecosystem; CompactLogix/ControlLogix is the next tier of sophistication.

Why it matters: the absence of any IOCONTROL deployment sightings in the three weeks since its update is not reassuring — it suggests the capability is being held in reserve for a politically authorized moment.

CVEProductCVSSStatusIranian Actor Linkage
CVE-2026-25089FortiSandbox 4.2–5.0.59.8KEV (Jul 16) — activePioneer Kitten (Fortinet exploitation pattern)
CVE-2026-15409SonicWall SMA100010.0KEV (Jul 14) — activePioneer Kitten (confirmed)
CVE-2026-46817Oracle E-Business Suite9.8KEV (Jul 15) — 3-day deadlineAPT34 / OilRig (Oracle targeting history)
CVE-2026-45659 + CVE-2026-32201Microsoft SharePointChainCISA alert (Jul 14) — DHS breachIranian state actor (via HSIN breach)
T1190

ScenarioProbabilityTimeframeBasis
Pioneer Kitten exploitation of CVE-2026-25089 (FortiSandbox)70%Within 72 hoursHistorical pattern: exploitation within 72h of every Fortinet KEV
Iranian cyber retaliation operation (DDoS or wiper) publicly claimed or attributed60%Within 7 daysDay 21 with no claims is historically unprecedented; pressure is building
Handala / Cyber Av3ngers destructive operation (wiper or ICS attack)50%Within 10 days8+ days of silence during kinetic conflict = OPSEC discipline before a major op
IOCONTROL deployment against US water/energy ICS infrastructure40%Within 14 daysCapability updated, target surface expanded, political authorization pending
MuddyWater campaign targeting US government networks30%Within 7 daysActor silent since Jul 12 (retooling); historically first-responder for retaliation

The critical insight: the absence of Iranian cyber retaliation claims at Day 21 post-strike is the loudest signal. Iran has never gone this long without a cyber response during active kinetic conflict — either operations are already underway against targets invisible to open-source collection, or a major coordinated operation is being held for political timing.

DetectionATT&CKLogic
Cobalt Strike DNS beacon on port 53T1572Periodic DNS TXT queries at 60s intervals to 87.107.191[.]39; anomalous DNS payload sizes
Remcos RAT on non-standard portT1219Encrypted TCP on port 43155 with periodic keepalive matching the Remcos beacon profile
FortiSandbox exploitation attemptT1190Unauthenticated HTTP requests to the FortiSandbox management interface with OS command injection patterns
MuddyWater PowerShell executionT1059.001Encoded PowerShell (-enc) with outbound connections to Iranian ASNs (213790, 44436, 51396, 58224)
DLL sideloading in temp directoriesT1574.002New DLLs written to %TEMP% / %APPDATA% then executed by legitimate signed binaries
Credential harvesting via phishing kitT1566.002Inbound emails linking to spoofed authentication portals; SARAQAKIT/SILENTRAQIB patterns
IOC Blocking Table:
185.93.89[.]7577.90.185[.]118185.93.89[.]43217.60.241[.]1787.107.191[.]3962.60.226[.]4293.118.146[.]156

Block all seven at perimeter controls (firewall, proxy, DNS sinkhole) and add to SIEM correlation. Cactus ransomware C2 (ASN213790): 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (HTTPS). Agentemis/Cobalt Strike: 217.60.241[.]17 (443), 87.107.191[.]39 (53/DNS). Remcos RAT (IRGC-adjacent): 62.60.226[.]42 (43155). Hajime botnet C2 (ASN58224): 93.118.146[.]156. Additional IOCs for the campaigns discussed in this report are available through Anomali ThreatStream and partner feeds.

ASN watchlist: monitor all outbound traffic to ASN213790 (Cactus / Pioneer Kitten), ASN44436 and ASN51396 (Agentemis / Cobalt Strike), and ASN58224 (Hajime botnet) — any connection warrants immediate investigation.

Hunting Hypotheses:
HUNT 01 · T1059.001
MuddyWater has pre-positioned access via PowerShell / DLL sideloading
Hunt for encoded PowerShell execution, DLLs in %TEMP% loaded by legitimate processes, and outbound connections to Iranian ASN ranges. MuddyWater's silence since July 12 during active kinetic conflict is anomalous — they are historically the first-responder for Iranian cyber retaliation.
HUNT 02 · T1190
Pioneer Kitten has already exploited FortiSandbox instances
Hunt for unexpected OS-level commands on FortiSandbox appliances, new scheduled tasks or cron jobs, and outbound connections to ASN213790 IPs. Check FortiSandbox logs for authentication anomalies in the past 72 hours.
HUNT 03 · T1572
Agentemis / Cobalt Strike beacons are active using DNS tunneling
Hunt for DNS query-volume anomalies to external resolvers, DNS TXT responses with encoded payloads, and regular-interval beaconing on port 53 traffic that is not legitimate DNS resolution.
HUNT 04 · ICS/OT
IOCONTROL or precursor tooling is present on OT network segments
Hunt for unexpected connections from PLC/HMI subnets to internet-facing hosts, firmware modification attempts on Rockwell CompactLogix/ControlLogix, and anomalous Modbus/EtherNet-IP traffic patterns.

Financial Services
Banking, Payments, Oracle EBS
Primary threats
Cactus ransomware via Pioneer Kitten access handoff. IP 185.93.89[.]75 (ASN213790) is specifically tagged as targeting financial services.
Actions
  • Audit all Fortinet appliances (FortiSandbox, FortiClient EMS, FortiGate) for CVE-2026-25089 and prior Fortinet KEVs
  • Review SWIFT/payment system segmentation — ensure no path from internet-facing Fortinet appliances to payment infrastructure
  • Increase monitoring on Oracle E-Business Suite instances (CVE-2026-46817)
  • Pre-stage the ransomware IR playbook; confirm backup integrity for critical financial systems
Energy
Water & Energy OT, Grid Relays
Primary threats
IOCONTROL deployment against Rockwell/Siemens PLCs.
Secondary threat
Cyber Av3ngers destructive operations against ICS/OT.
Actions
  • Immediately audit all Rockwell CompactLogix/ControlLogix and Siemens SICAM 8 deployments for internet exposure and segmentation compliance
  • Apply firmware updates per ICSA-26-197-02 (communication modules) and ICSA-26-197-06 (CompactLogix/ControlLogix DoS)
  • Verify OT monitoring can detect anomalous Modbus/EtherNet-IP traffic and unauthorized firmware writes
  • Test manual override procedures for grid protection systems (Siemens SICAM); coordinate with E-ISAC on IOCONTROL indicators
Healthcare
EHR, PACS, Medical Devices
Primary threats
Cactus ransomware targeting healthcare — IPs 77.90.185[.]118 and 185.93.89[.]43 are specifically tagged healthcare.
Actions
  • Prioritize patching of all internet-facing appliances (SonicWall SMA1000, FortiSandbox, Cisco ASA)
  • Ensure medical device network segments cannot reach the C2 IPs listed above
  • Verify ransomware resilience: test restoration of EHR, PACS imaging, and pharmacy systems from backup
  • Brief clinical leadership on Iranian-nexus ransomware as asymmetric retaliation; coordinate with H-ISAC
Government
SharePoint, Privileged Access
Primary threats
SharePoint exploitation chains, confirmed via the DHS HSIN breach.
Secondary threat
MuddyWater/APT34 espionage; UNC6496 credential phishing (APT42-adjacent).
Actions
  • Verify all SharePoint instances are patched against CVE-2026-45659 and CVE-2026-32201; apply CISA hardening from the July 14 alert
  • Deploy enhanced monitoring for SARAQAKIT/SILENTRAQIB credential phishing (UNC6496/APT42)
  • Conduct a privileged account audit — Iranian actors consistently target valid credentials (T1078) for persistence
  • Implement phishing-resistant MFA (FIDO2) for all privileged accounts; SMS/email OTP is insufficient against APT42-class actors
Aviation / Logistics
Maritime, Ports, Logistics OT
Primary threats
Disruption of Strait of Hormuz corridor operations; DDoS against logistics systems.
Secondary threat
Hajime botnet DDoS marshaling capability (93.118.146[.]156).
Actions
  • Increase monitoring of OT systems controlling cargo handling, flight management, and port operations
  • Audit IoT device inventory — Hajime botnet targets IoT devices for DDoS marshaling
  • Review DDoS mitigation capacity and test failover for customer-facing booking/tracking systems
  • Ensure satellite communication and GPS systems have integrity monitoring (Iranian GPS spoofing is documented in the Strait of Hormuz)
No sector cards match the selected filters.

Block the 7 Iran-hosted C2 IPs at all perimeter controls: 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43, 217.60.241[.]17, 87.107.191[.]39, 62.60.226[.]42, 93.118.146[.]156.
SOC Analyst
Patch FortiSandbox to 5.0.6+ (CVE-2026-25089, CVSS 9.8). If patching is impossible within 24h, restrict the management interface to trusted IPs only.
Incident Responder
Deploy a Snort/Suricata rule for the Cobalt Strike DNS beacon on port 53 — monitor for 60-second-interval DNS TXT beaconing to 87.107.191[.]39.
SOC Analyst
Verify SonicWall SMA1000 is patched against CVE-2026-15409 (CVSS 10.0, KEV since Jul 14).
Incident Responder
Authorize a proactive threat hunt for Iranian APT TTPs — the retaliation window is at maximum tension.
CISO / ExecThreat Hunter
No immediate actions for the selected roles.
Audit Rockwell CompactLogix/ControlLogix and Siemens SICAM 8 for segmentation and internet exposure. Apply firmware updates per ICSA-26-197-02 and ICSA-26-197-06.
ICS / OT
Create a Remcos RAT detection rule for non-standard ports (specifically port 43155) — encrypted TCP with periodic keepalive.
SOC Analyst
Hunt enterprise-wide for MuddyWater TTPs: encoded PowerShell (T1059.001), DLL sideloading in %TEMP% (T1574.002), and outbound connections to Iranian ASNs.
Threat Hunter
Patch Oracle E-Business Suite against CVE-2026-46817 (CVSS 9.8; the 3-day CISA deadline has already passed).
Incident Responder
Implement phishing-resistant MFA (FIDO2/WebAuthn) for all privileged and externally-facing accounts — UNC6496/APT42 credential phishing is active.
IAM Analyst
Update IR playbooks for the Iranian wiper scenario (Handala/Cyber Av3ngers pattern); pre-stage forensic imaging tools and out-of-band communications.
Incident Responder
No 7-day actions for the selected roles.
Commission an assessment of exposure to IOCONTROL-class ICS malware targeting Rockwell/Siemens PLCs in water and energy OT networks.
CISO / Exec
Review and harden all Fortinet, SonicWall, and Cisco perimeter appliances — the primary initial-access vectors for Iranian APTs. Consider zero-trust network access for remote access.
CISO / Exec
Establish or verify an ISAC information-sharing relationship (E-ISAC, H-ISAC, FS-ISAC, A-ISAC) for Iranian threat-indicator sharing.
CISO / Exec
Run a tabletop exercise simulating a coordinated Iranian cyber-kinetic scenario: simultaneous ransomware (Cactus) + ICS disruption (IOCONTROL) + DDoS (Hajime/Cyber Av3ngers).
Incident ResponderCISO / Exec
Implement continuous monitoring of Iranian ASN ranges (213790, 44436, 51396, 58224) with automated alerting on any outbound connection.
SOC Analyst
No 30-day actions for the selected roles.
The Bottom Line

We are 139 days into an active US-Iran conflict and 21 days past the most significant kinetic escalation since it began. Every historical precedent tells us Iranian cyber retaliation follows kinetic strikes within 7–21 days — and we are at the outer edge of that window. Infrastructure is freshly refreshed, four critical CVEs are under active exploitation, IOCONTROL is a weapon loaded but not yet fired, and the destructive proxies have gone deliberately quiet. The question is not whether Iranian cyber retaliation will come. It is whether your organization will detect it in the first hours — or discover it in the aftermath. Patch. Block. Hunt. Now.

1
Are your Fortinet and SonicWall appliances patched? Four critical CVEs are under active exploitation, with Pioneer Kitten's 72-hour clock ticking on FortiSandbox.
2
Have you blocked the seven Iran-hosted C2 nodes? Freshly refreshed infrastructure on Iranian state-affiliated networks is ready now.
3
Do you have an ICS/wiper response plan? IOCONTROL is loaded but unfired, and 8+ days of Handala/Cyber Av3ngers silence is discipline, not inactivity.
No items found.