| Date | Development | Significance |
|---|---|---|
| Jul 16 | CVE-2026-25089 (FortiSandbox, CVSS 9.8) added to CISA KEV — unauthenticated OS command injection affecting FortiSandbox 4.2–5.0.5, Cloud, and PaaS | New exploitation vector; Pioneer Kitten historically exploits every Fortinet KEV within 72 hours |
| Jul 16 | Nine ICS advisories published in a single day — five affecting Rockwell CompactLogix/ControlLogix, plus Siemens SICAM grid protection relays | OT attack surface expansion coinciding with the June 24 IOCONTROL update |
| Jul 17 | Seven Iran-hosted C2 nodes confirmed active, including Agentemis (Cobalt Strike loader) using DNS-over-port-53 and a Remcos RAT on an IRGC-adjacent academic network | Iranian offensive infrastructure is expanding, not contracting |
| Jul 17 | UNC6496 IRGC attribution confirmed — credential phishing using SARAQAKIT/SILENTRAQIB kits against Middle East and US government targets | New IRGC-adjacent group operating in proximity to APT42 |
| Ongoing | Prior-cycle CVEs remain active and unresolved: SonicWall SMA1000 (CVE-2026-15409, CVSS 10.0), Oracle EBS (CVE-2026-46817, CVSS 9.8), SharePoint chain (CVE-2026-45659 + CVE-2026-32201) linked to the DHS HSIN breach | Threat level held at HIGH (unchanged from Jul 16); today's developments add to an unresolved backlog |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Initial escalation | Feb 28, 2026 (Day 0) | Iran-related conflict escalation begins — start of the current operational period |
| Regional widening | May 12, 2026 | Saudi Arabia conducts covert attacks on Iran; regional war widens into multi-front pressure on Iran |
| Pre-strike positioning | Jun 24–25, 2026 | IOCONTROL ICS malware updated (no deployment sightings since); Iranian drone attack on a commercial vessel in the Strait of Hormuz — kinetic trigger |
| Kinetic escalation | Jun 26–29, 2026 | US CENTCOM strikes Iranian missile/drone sites, starting the retaliation clock; Israeli cyber chief confirms Iranian cyberattacks surged in 2026 |
| Active retaliation window | Jul 8–16, 2026 | DHS HSIN breach disclosed (SharePoint chain, confirmed access to US government networks); 10 Iranian actor profiles refreshed in ThreatStream; CISA KEV additions (SonicWall, Oracle EBS, FortiSandbox); 9 ICS advisories; APT34/OilRig reactivated |
| Current (Day 21) | Jul 17, 2026 | Seven active Iran C2 IPs confirmed; UNC6496 IRGC attribution confirmed — the outer edge of the historical retaliation window |
ASN213790 ("Limited Network," Iranian hosting) has emerged as the single most important infrastructure indicator in this conflict. Three IPs on this ASN are tagged to Cactus ransomware — the extortion partner used by Pioneer Kitten to monetize state-sponsored access: 185.93.89[.]75 (financial services), 77.90.185[.]118 (government/healthcare/technology), and 185.93.89[.]43 (healthcare/manufacturing, command injection capability).
Separately, two IPs host Agentemis, a custom Cobalt Strike loader attributed to Pioneer Kitten and MuddyWater: 217.60.241[.]17 (beacon on port 443) and 87.107.191[.]39 (DNS-over-port-53, a known MuddyWater evasion technique). A Remcos RAT node at 62.60.226[.]42 is hosted on an IRGC-adjacent academic network, operating on non-standard port 43155.
Why it matters: this is the convergence of state espionage and criminal extortion — Iranian intelligence gains access, then hands off to ransomware operators for monetization and plausible deniability.
Iranian operations are converging around a coordinated set of IRGC- and MOIS-linked actors, several of them refreshed or reactivated in the past week:
| Actor | Affiliation | Status (Jul 17) | Primary Capability |
|---|---|---|---|
| Pioneer Kitten / Fox Kitten | IRGC | Active — C2 refresh confirmed; 72h window for CVE-2026-25089 | Network exploitation → ransomware handoff (Cactus/INC) |
| Handala / Banished Kitten / Cyber Av3ngers | IRGC | Silent 8+ days — assessed as pre-positioning | Destructive wipers, ICS attacks (IOCONTROL), DDoS |
| APT34 / OilRig | MOIS | Reactivated Jul 15 | Espionage, credential harvesting, supply chain |
| MuddyWater / TEMP.Zagros | MOIS | Silent since Jul 12 — assessed as retooling | First-responder for retaliation; PowerShell / DLL sideloading |
| UNC6496 | IRGC (adjacent to APT42) | Profile confirmed Jul 17; active phishing | SARAQAKIT / SILENTRAQIB phishing kits |
The July 16 advisory batch is not routine disclosure — it is a roadmap for adversaries already holding ICS-targeting capability. Five Rockwell products are affected (CompactLogix, ControlLogix, GuardLogix, FactoryTalk DataMosaix, Arena) plus Siemens SICAM 8 grid protection relays. Rockwell's CompactLogix/ControlLogix family is deployed in over 60% of US water treatment facilities.
IOCONTROL — the Iranian ICS malware updated June 24 — was designed for exactly this class of device. Cyber Av3ngers previously targeted Unitronics PLCs, the entry-level of this ecosystem; CompactLogix/ControlLogix is the next tier of sophistication.
Why it matters: the absence of any IOCONTROL deployment sightings in the three weeks since its update is not reassuring — it suggests the capability is being held in reserve for a politically authorized moment.
| CVE | Product | CVSS | Status | Iranian Actor Linkage |
|---|---|---|---|---|
| CVE-2026-25089 | FortiSandbox 4.2–5.0.5 | 9.8 | KEV (Jul 16) — active | Pioneer Kitten (Fortinet exploitation pattern) |
| CVE-2026-15409 | SonicWall SMA1000 | 10.0 | KEV (Jul 14) — active | Pioneer Kitten (confirmed) |
| CVE-2026-46817 | Oracle E-Business Suite | 9.8 | KEV (Jul 15) — 3-day deadline | APT34 / OilRig (Oracle targeting history) |
| CVE-2026-45659 + CVE-2026-32201 | Microsoft SharePoint | Chain | CISA alert (Jul 14) — DHS breach | Iranian state actor (via HSIN breach) |
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Pioneer Kitten exploitation of CVE-2026-25089 (FortiSandbox) | 70% | Within 72 hours | Historical pattern: exploitation within 72h of every Fortinet KEV |
| Iranian cyber retaliation operation (DDoS or wiper) publicly claimed or attributed | 60% | Within 7 days | Day 21 with no claims is historically unprecedented; pressure is building |
| Handala / Cyber Av3ngers destructive operation (wiper or ICS attack) | 50% | Within 10 days | 8+ days of silence during kinetic conflict = OPSEC discipline before a major op |
| IOCONTROL deployment against US water/energy ICS infrastructure | 40% | Within 14 days | Capability updated, target surface expanded, political authorization pending |
| MuddyWater campaign targeting US government networks | 30% | Within 7 days | Actor silent since Jul 12 (retooling); historically first-responder for retaliation |
The critical insight: the absence of Iranian cyber retaliation claims at Day 21 post-strike is the loudest signal. Iran has never gone this long without a cyber response during active kinetic conflict — either operations are already underway against targets invisible to open-source collection, or a major coordinated operation is being held for political timing.
| Detection | ATT&CK | Logic |
|---|---|---|
| Cobalt Strike DNS beacon on port 53 | T1572 | Periodic DNS TXT queries at 60s intervals to 87.107.191[.]39; anomalous DNS payload sizes |
| Remcos RAT on non-standard port | T1219 | Encrypted TCP on port 43155 with periodic keepalive matching the Remcos beacon profile |
| FortiSandbox exploitation attempt | T1190 | Unauthenticated HTTP requests to the FortiSandbox management interface with OS command injection patterns |
| MuddyWater PowerShell execution | T1059.001 | Encoded PowerShell (-enc) with outbound connections to Iranian ASNs (213790, 44436, 51396, 58224) |
| DLL sideloading in temp directories | T1574.002 | New DLLs written to %TEMP% / %APPDATA% then executed by legitimate signed binaries |
| Credential harvesting via phishing kit | T1566.002 | Inbound emails linking to spoofed authentication portals; SARAQAKIT/SILENTRAQIB patterns |
Block all seven at perimeter controls (firewall, proxy, DNS sinkhole) and add to SIEM correlation. Cactus ransomware C2 (ASN213790): 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 (HTTPS). Agentemis/Cobalt Strike: 217.60.241[.]17 (443), 87.107.191[.]39 (53/DNS). Remcos RAT (IRGC-adjacent): 62.60.226[.]42 (43155). Hajime botnet C2 (ASN58224): 93.118.146[.]156. Additional IOCs for the campaigns discussed in this report are available through Anomali ThreatStream and partner feeds.
ASN watchlist: monitor all outbound traffic to ASN213790 (Cactus / Pioneer Kitten), ASN44436 and ASN51396 (Agentemis / Cobalt Strike), and ASN58224 (Hajime botnet) — any connection warrants immediate investigation.
%TEMP% loaded by legitimate processes, and outbound connections to Iranian ASN ranges. MuddyWater's silence since July 12 during active kinetic conflict is anomalous — they are historically the first-responder for Iranian cyber retaliation.185.93.89[.]75 (ASN213790) is specifically tagged as targeting financial services.- Audit all Fortinet appliances (FortiSandbox, FortiClient EMS, FortiGate) for CVE-2026-25089 and prior Fortinet KEVs
- Review SWIFT/payment system segmentation — ensure no path from internet-facing Fortinet appliances to payment infrastructure
- Increase monitoring on Oracle E-Business Suite instances (CVE-2026-46817)
- Pre-stage the ransomware IR playbook; confirm backup integrity for critical financial systems
- Immediately audit all Rockwell CompactLogix/ControlLogix and Siemens SICAM 8 deployments for internet exposure and segmentation compliance
- Apply firmware updates per ICSA-26-197-02 (communication modules) and ICSA-26-197-06 (CompactLogix/ControlLogix DoS)
- Verify OT monitoring can detect anomalous Modbus/EtherNet-IP traffic and unauthorized firmware writes
- Test manual override procedures for grid protection systems (Siemens SICAM); coordinate with E-ISAC on IOCONTROL indicators
77.90.185[.]118 and 185.93.89[.]43 are specifically tagged healthcare.- Prioritize patching of all internet-facing appliances (SonicWall SMA1000, FortiSandbox, Cisco ASA)
- Ensure medical device network segments cannot reach the C2 IPs listed above
- Verify ransomware resilience: test restoration of EHR, PACS imaging, and pharmacy systems from backup
- Brief clinical leadership on Iranian-nexus ransomware as asymmetric retaliation; coordinate with H-ISAC
- Verify all SharePoint instances are patched against CVE-2026-45659 and CVE-2026-32201; apply CISA hardening from the July 14 alert
- Deploy enhanced monitoring for SARAQAKIT/SILENTRAQIB credential phishing (UNC6496/APT42)
- Conduct a privileged account audit — Iranian actors consistently target valid credentials (T1078) for persistence
- Implement phishing-resistant MFA (FIDO2) for all privileged accounts; SMS/email OTP is insufficient against APT42-class actors
93.118.146[.]156).- Increase monitoring of OT systems controlling cargo handling, flight management, and port operations
- Audit IoT device inventory — Hajime botnet targets IoT devices for DDoS marshaling
- Review DDoS mitigation capacity and test failover for customer-facing booking/tracking systems
- Ensure satellite communication and GPS systems have integrity monitoring (Iranian GPS spoofing is documented in the Strait of Hormuz)
185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43, 217.60.241[.]17, 87.107.191[.]39, 62.60.226[.]42, 93.118.146[.]156.87.107.191[.]39.%TEMP% (T1574.002), and outbound connections to Iranian ASNs.We are 139 days into an active US-Iran conflict and 21 days past the most significant kinetic escalation since it began. Every historical precedent tells us Iranian cyber retaliation follows kinetic strikes within 7–21 days — and we are at the outer edge of that window. Infrastructure is freshly refreshed, four critical CVEs are under active exploitation, IOCONTROL is a weapon loaded but not yet fired, and the destructive proxies have gone deliberately quiet. The question is not whether Iranian cyber retaliation will come. It is whether your organization will detect it in the first hours — or discover it in the aftermath. Patch. Block. Hunt. Now.