TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber Retaliation Clock Is Ticking:

What CISOs Need to Know After Operation Midnight Hammer

CRITICAL. Twenty-five days after U.S. kinetic strikes on Iranian nuclear facilities and public confirmation that U.S. Cyber Command disabled Iranian air defenses during Operation Midnight Hammer, Iran's cyber apparatus has gone conspicuously silent. Pioneer Kitten, Handala, and MuddyWater have converged into a confirmed access-to-destruction pipeline — validated by seven shared malware samples and a first-ever defense-sector ransomware crossover. The public disclosure of USCYBERCOM's role now provides Iran both strategic motivation and propaganda justification for retaliatory operations at scale. The next 14 days represent the highest-risk window of the conflict.

I am a
My sector

DateDevelopmentSignificance
Jul 22Operation Midnight Hammer cyber component publicly disclosed — USCYBERCOM confirms disabling Iranian air defense systemsProvides Iran propaganda justification for retaliatory cyber operations at scale
Jul 2225 days of complete hacktivist silence — longest on record following a kinetic escalationAssessed as pre-staging indicator for coordinated multi-vector attack
Jul 21MuddyWater/Dalbit defense-sector sample identified with Hive ransomware componentsFirst DIB-specific targeting in espionage-as-ransomware crossover pipeline
Jul 21CISA publishes 10 ICS advisories — Siemens RUGGEDCOM and Rockwell Studio 5000 Logix DesignerOT attack surface expands during peak conflict — includes arbitrary file execution in PLC programming environments
Jul 20–21HOLLOWGRAPH implant publicly disclosed; APT34 refreshes malware with expanded targetingM365 Graph API C2 now observed against Malaysian and Australian targets
Jul 16CISA adds CVE-2026-25089 (FortiSandbox pre-auth RCE, CVSS 9.8) to KEV catalogPioneer Kitten historically exploits Fortinet vulnerabilities within 24–72 hours of KEV disclosure
Jul 11–14ASN213790 C2 infrastructure refreshed — three IPs at confidence 77–97Pre-operational indicator: infrastructure actively maintained and ready for activation
Jul 7U.S. retaliatory strikes for Strait of Hormuz cargo ship attackSecond kinetic trigger; retaliation pressure compounds across all Iranian proxy groups
Jun 29Israeli cyber chief publicly confirms Iranian cyberattacks surged in 2026Validates escalating Iranian cyber tempo throughout the conflict
Jun 26U.S. Operation Midnight Hammer — strikes on Fordo, Natanz, Isfahan nuclear facilitiesRetaliation clock starts; USCYBERCOM disables Iranian SAM command-and-control
Jun 3HOLLOWGRAPH implant becomes operational against Israeli targetsAPT34/Lyceum deploys novel M365 Graph API C2 — no prior public reporting
Feb 28Iran-Israel conflict escalation beginsIranian cyber operations tempo increases across all actor groups

PhaseTimeframeCyber Activity
Pre-escalationBefore Feb 28, 2026Baseline Iranian espionage — APT34, MuddyWater, Pioneer Kitten access brokering; HOLLOWGRAPH development underway
Conflict escalationFeb 28 – May 2026Iranian cyber tempo increases; APT34 deploys HOLLOWGRAPH against Israeli targets; Pioneer Kitten infrastructure build-out
Operation Midnight HammerJun 26, 2026U.S. strikes Fordo, Natanz, Isfahan; USCYBERCOM disables Iranian air defenses; retaliation window opens
Retaliation stagingJun 27 – Jul 21, 202625-day hacktivist silence begins; ASN213790 infrastructure refreshed; Pioneer Kitten/Handala/Banished Kitten convergence confirmed via shared malware samples; MuddyWater pivots to defense-sector targeting
Current (Day 25)Jul 22, 2026Midnight Hammer cyber operations disclosed; maximum retaliatory motivation established; 10 ICS advisories expand OT attack surface; defense-sector ransomware targeting confirmed

We are 25 days into the retaliation window following Operation Midnight Hammer — exceeding all modern precedents for Iranian hacktivist response time. Historical patterns: Stuxnet disclosure drove Shamoon within 18 months; Soleimani assassination triggered DDoS and wiper campaigns within 72 hours; U.S. strikes on Houthis produced Cyber Av3ngers ICS campaigns within 2 weeks. None of those silences lasted 25 days.

Two hypotheses explain this: pre-staging a coordinated operation (60% confidence) — Iranian operators using the quiet period to pre-position access, stage destructive payloads, and coordinate across proxy groups for a simultaneous multi-target attack; or capability degradation from kinetic strikes (40% confidence). Persistent C2 activity on ASN213790 argues strongly against the latter. The silence is not reassurance. It is the signal.

T1071.001T1485

Eight confirmed Iranian threat actor groups are active or have been updated in intelligence platforms within the past 48 hours. IRGC-affiliated actors are executing the access-to-destruction chain; MOIS-affiliated actors are conducting espionage and supply-chain targeting.

ActorAffiliationRoleCurrent Status
Pioneer Kitten (Fox Kitten, UNC757)IRGCAccess broker — edge appliance exploitation, access handoff to destructorsActive — 7 fresh malware samples Jul 22; Fortinet exploitation within 24–72h of KEV
Cyber Av3ngersIRGCICS/OT destructor — targets water, energy PLCsSilent 25 days — anomalous; may indicate exploit development for new ICS advisories
Handala / Banished Kitten (Cotton Sandstorm)IRGCDestructive hacktivist — wiper deployment, data leaksSilent 25 days — convergence with Pioneer Kitten confirmed via shared malware samples
APT34 (OilRig, Helix Kitten)MOISEspionage — government, energy, telecom; HOLLOWGRAPH M365 C2Active — malware refresh Jul 21; expanded targeting to Malaysia and Australia
MuddyWater (UNC3313, Static Kitten)MOISInitial access + espionage — government, DIB, telecomActive — defense-sector samples with Hive ransomware crossover confirmed
APT33 (Elfin)IRGC/MOISDestructive capability — aviation, energy, petrochemicalUpdated Jul 21–22 in threat intelligence platforms
APT35 (Phosphorus)IRGCCredential harvesting — think tanks, government, mediaUpdated Jul 21–22 in threat intelligence platforms
APT42IRGC-IOSurveillance + credential theft — dissidents, policy makersUpdated Jul 21–22
T1190T1071.001T1078

The most dangerous development in this conflict cycle: seven malware samples are co-tagged to Pioneer Kitten, Handala, and Banished Kitten simultaneously — confirming a live operational handoff pipeline between Iran's leading access broker and its most destructive proxy groups.

The pipeline mirrors the model Iran used in the 2022 Albanian government wiper attack, where access was established months before the destructive phase. Pioneer Kitten gains initial access via exploitation of internet-facing Fortinet, Citrix, and Ivanti appliances; access is handed to Handala or Banished Kitten; a destructive payload — wiper, ransomware-as-cover, or data destruction — is deployed. The 25-day silence is consistent with the pre-positioning phase of this model.

T1190T1486T1485T1133

Intelligence this cycle confirms MuddyWater is adopting the Russian playbook of using ransomware to mask espionage and provide plausible deniability for destructive operations. Samples now tagged to both MuddyWater and Dalbit/Silent Chollima with Hive ransomware family indicators explicitly target the defense sector — the first confirmed DIB-specific targeting in this crossover pipeline.

Rather than conducting overt espionage that risks attribution and diplomatic consequences, MOIS-affiliated actors are deploying ransomware that appears criminal while simultaneously exfiltrating sensitive defense data. The targeting of financial services, government, telecom, and utilities alongside defense suggests broad pre-positioning across multiple verticals.

T1195.002T1486T1562.001T1497.003

Ten new CISA ICS advisories published July 21 affect systems directly relevant to critical infrastructure operators during peak conflict: Rockwell Studio 5000 Logix Designer — arbitrary file execution and configuration alteration in PLC programming environments (highest concern given Cyber Av3ngers' demonstrated interest in PLC manipulation); Siemens RUGGEDCOM APE1808 — PAN-OS vulnerabilities in industrial firewall appliances; and Rockwell 1734/1719 POINT I/O — denial-of-service against I/O modules capable of causing physical process disruption.

Cyber Av3ngers has previously demonstrated both the intent and capability to target industrial control systems. Their 25-day silence during a period of maximum kinetic escalation and maximum new vulnerability disclosure is consistent with exploit development rather than operational cessation.

T0816T0826T1190

An IP address on ASN42337 (Respina Networks, Tehran) carries APT28 (GRU Unit 26165) attribution tags — a Russian military intelligence actor appearing on Iranian-hosted infrastructure. While this could represent misattribution or shared scanning infrastructure, the signal aligns with broader intelligence indicating Russian-Iranian operational cooperation in cyberspace.

Implication for defenders: monitor for blended TTPs that combine Russian sophistication (advanced persistence, living-off-the-land techniques) with Iranian targeting preferences (critical infrastructure, defense sector, government). Organizations should develop detection logic that alerts on traffic to Iranian ASNs matching Russian APT behavioral signatures.

T1071.001T1583

ScenarioProbabilityTimeframeBasis
Iranian state media / IRGC issues retaliatory rhetoric responding to Midnight Hammer disclosure70%48–72 hoursStandard propaganda response cycle; disclosure provides narrative ammunition and justification framework
Handala or Cyber Av3ngers breaks silence with a claimed operation (likely pre-staged)45%7–14 days25-day silence consistent with pre-staging; historical pattern of coordinated reveal following quiet pre-positioning
Pioneer Kitten mass-exploitation of CVE-2026-25089 (FortiSandbox) against Western targets35%7–14 daysHistorical exploitation within 24–72h of Fortinet KEV additions; currently within window since Jul 16 disclosure
MuddyWater phishing campaign targeting U.S. government / military using conflict lures30%7–14 daysConflict-themed lures are standard MuddyWater tradecraft; defense-sector targeting already confirmed this cycle
Destructive wiper deployment against Israeli or Gulf state critical infrastructure25%14–30 daysHandala pipeline confirmed active; 2022 Albania precedent shows months of pre-staging before destructive phase
Coordinated multi-target retaliatory campaign (DDoS + wiper + data leak) against U.S. interests20%14–45 daysHighest-consequence scenario; silence duration suggests coordination across multiple groups; 60% pre-staging confidence

RuleData SourceATT&CKPriority
Any connection (inbound or outbound) to 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 — ASN213790, Iranian APT C2Firewall / NetflowT1071.001CRITICAL
SHA-256 match on Pioneer Kitten / Handala / Banished Kitten samples (7 hashes) on any endpointEDRT1190 T1486CRITICAL
Anomalous Microsoft 365 Graph API call volumes or unexpected OneDrive / SharePoint API access (HOLLOWGRAPH C2 pattern)M365 Audit LogsT1071.001 T1567.002HIGH
Exploitation attempts targeting FortiSandbox CVE-2026-25089 — pre-auth RCE, CVSS 9.8WAF / Edge appliance logsT1190HIGH
SHA-256 match on MuddyWater / Dalbit / Hive samples in defense contractor network segments (3 hashes)EDRT1195.002 T1486HIGH
Security tool disabling (EDR agent tampering, AV exclusion additions) followed by anomalous file encryptionEDRT1562.001 T1497.003HIGH
Unexpected PLC programming activity or configuration changes on Rockwell Studio 5000 / Siemens RUGGEDCOMOT network monitoringT0816 T0826HIGH
Connections to ASN34918 (Pishgaman Toseeh) or ASN42337 (Respina Networks) — confirmed Iranian APT-linked hostingFirewall / NetflowT1071.001MEDIUM
IOC Blocking Table:
185.93.89[.]7577.90.185[.]118185.93.89[.]435.202.4[.]182.188.214[.]142

Five IPs across ASN213790 (confidence 77–97), ASN34918, and ASN42337 — confirmed Iranian APT C2 infrastructure. Pioneer Kitten / Handala (7 hashes, confidence High): 028d3de0f0709a18c9928526519e761a08f6766d1eca386e908588f995f44e7f, 0a5cf97e699c8bfacee7f89ebfaa851ff03dd004a58ffde9c609fcc2cd27f250, 7540bed5efd55f75271bb4b5a5afb28f343ebe64a816f74f0edba8527dc5e181, and 4 additional hashes. MuddyWater / Dalbit / Hive (3 hashes): 0a472e47c338062af13c2e18561b4e5f7371c71732136c7c117eca7370678d77, 9db865ccc51ab10e6db39682e7cad87386e43bcf41dadb2559ce1030f691d8c6, fcc85234347de8a69b510c40acb1ad7a0bd63893870f6f190597d88b3c828f50. Full IOC set via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190, T1078, T1133
Pioneer Kitten dormant access via VPN / edge appliances
Are there historical connections to ASN213790 or ASN34918 in our 90-day netflow? Review Fortinet, Citrix, and Ivanti authentication logs for unexpected service accounts, unauthorized admin sessions, or configuration changes not tied to change management records.
HUNT 02 · T1071.001, T1567.002
HOLLOWGRAPH C2 via Microsoft 365 Graph API
Are there anomalous Graph API call volumes or unexpected service principals accessing OneDrive and SharePoint in our M365 environment? Hunt for spikes in API traffic from non-standard application IDs or outside normal business hours.
HUNT 03 · T1195.002, T1204.002
MuddyWater supply-chain compromise of defense software
Is there unsigned binary execution or unexpected software update behavior in defense contractor network segments? Hunt for PowerStats malware family indicators, unexpected process trees from PTC Windchill or engineering data systems, and lateral movement from software update mechanisms.
HUNT 04 · T0816, T0826
Cyber Av3ngers ICS reconnaissance against new advisory targets
Is there unusual access to Rockwell Studio 5000 Logix Designer programming environments or Siemens RUGGEDCOM APE1808 management interfaces? Monitor for unexpected PLC programming sessions, configuration reads outside maintenance windows, or Modbus/EtherNet/IP traffic anomalies from IT-side hosts.
HUNT 05 · T1486, T1562.001, T1497.003
Hive ransomware-as-cover operation in defense-sector networks
Is there evidence of security tool disabling followed by anomalous encryption activity in segments touching defense contractors or sensitive government data? Hunt for Hive ransomware behavioral signatures and time-based sandbox evasion techniques in EDR telemetry.

Financial Services
Banking Infrastructure, SWIFT, Fintech
Primary threats
MuddyWater/Dalbit ransomware crossover explicitly targeting financial services; Hive ransomware as cover for espionage and data theft; IcedID loader on ASN34918 infrastructure as initial access vector into banking systems
Actions
  • Audit SWIFT and core banking system access controls for anomalous service accounts or off-hours authentication
  • Verify offline backup integrity for transaction databases — assume ransomware deployment is possible within the 14-day window
  • Monitor for IcedID loader activity (tagged on ASN34918 infrastructure) as a potential initial access vector
  • Review third-party vendor connections to defense contractors for crossover targeting risk
  • Enable enhanced logging on all internet-facing financial applications and API gateways
Energy
OT, Grid, ICS, Substations
Primary threats
Cyber Av3ngers' demonstrated ICS capability combined with 10 new Siemens/Rockwell advisories; Rockwell Studio 5000 arbitrary file execution directly threatens PLC programming environments; 25-day Cyber Av3ngers silence may indicate exploit development for newly disclosed vulnerabilities
Actions
  • Immediately verify IT/OT air-gap integrity — assume adversary will attempt lateral movement from IT-side compromise to OT networks
  • Patch or isolate Rockwell Studio 5000 Logix Designer per ICSA-26-202-10; verify no internet exposure of PLC programming environments
  • Audit Siemens RUGGEDCOM APE1808 firmware versions against ICSA-26-202-02; restrict remote management access
  • Deploy additional monitoring on Rockwell 1734/1719 POINT I/O modules for denial-of-service indicators
  • Prepare manual override procedures for critical processes in case of PLC manipulation or configuration alteration
Healthcare
Patient Portals, EHR Systems, Medical Devices
Primary threats
ASN213790 infrastructure (confidence 97) explicitly tagged with healthcare sector targeting; Pioneer Kitten access-broker model means dormant access may exist on edge devices; ransomware deployment via the confirmed operational pipeline represents acute risk to patient data and care continuity
Actions
  • Conduct emergency audit of all Fortinet, Citrix, and Ivanti appliances for indicators of Pioneer Kitten exploitation
  • Block ASN213790 and ASN34918 at network perimeter immediately; expand to full ASN-level monitoring
  • Verify medical device network segmentation — ensure IoT and medical devices cannot reach identified C2 infrastructure
  • Review VPN authentication logs for the past 90 days for connections originating from Iranian ASNs
  • Ensure patient data backup systems are isolated, verified, and tested for restoration within acceptable RTO
Government
Civilian & Defense Agencies, DIB
Primary threats
MuddyWater defense-sector supply-chain compromise (T1195.002) targeting government and DIB networks; Midnight Hammer disclosure creates maximum retaliatory motivation against U.S. government systems; HOLLOWGRAPH C2 expanding targeting to Western government-affiliated organizations
Actions
  • Activate heightened monitoring on all .gov and .mil email systems for Iran conflict-themed phishing lures
  • Audit Microsoft Teams device-code authentication flows — a known MuddyWater initial access technique
  • Review PTC Windchill and other PLM/engineering data systems for unauthorized access (DIB supply chain risk)
  • Verify ITSM and ServiceNow platforms are patched against recent CVEs exploited by MOIS actors
  • Coordinate with CISA for latest Shields Up guidance specific to Iranian retaliation scenarios
Aviation / Logistics
DIB Contractors, Maritime Logistics
Primary threats
APT33 (Elfin) historically targets aviation and was updated in threat intelligence platforms Jul 21–22; Strait of Hormuz cargo ship attack and subsequent U.S. retaliation creates specific motivation for maritime logistics targeting; Pioneer Kitten access brokering into DIB contractor networks
Actions
  • Review all Cisco ASA/FTD configurations for unauthorized changes — APT33 historically targets network infrastructure in aviation
  • Audit flight operations and logistics management systems for anomalous access patterns or privilege escalation
  • Monitor for APT33-associated malware families (Shamoon variants, StoneDrill) in endpoint telemetry
  • Verify cargo tracking and port management systems are segmented from corporate networks and cannot reach identified C2 infrastructure
  • Coordinate with TSA and maritime security authorities on current threat posture and Shields Up implementation
No sector cards match the selected filters.

Block all five Iranian APT IPs at perimeter firewall and add to SIEM correlation rules: 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43, 5.202.4[.]18, 2.188.214[.]142. Expand to ASN-level blocking for ASN213790 and ASN34918.
SOC Analyst
Deploy all 10 SHA-256 hashes (Pioneer Kitten / Handala and MuddyWater / Dalbit samples) to EDR blocklists across all endpoints immediately.
SOC Analyst
Activate heightened monitoring posture — reduce alert thresholds for Iranian-attributed TTPs; staff 24/7 SOC coverage for a minimum of 14 days.
SOC Analyst
Initiate 90-day historical log review for any connections to ASN213790, ASN34918, or ASN42337. Pioneer Kitten pre-positions access months before activation — historical review is non-optional.
SOC Analyst
Activate incident response retainer — ensure IR partner is briefed on Iranian retaliation scenario and can mobilize within 2 hours. Confirm scope of retainer covers destructive attack scenarios.
Incident Responder
Brief C-suite on elevated threat posture — communicate potential for destructive attack within 14 days; confirm crisis communication plan is current and key contacts are reachable outside business hours.
CISO / Exec
No immediate actions for the selected roles.
Patch Rockwell Studio 5000 Logix Designer per ICSA-26-202-10 — verify no internet exposure of PLC programming environments; isolate unpatched systems from corporate networks immediately.
ICS / OT
Verify Siemens RUGGEDCOM APE1808 PAN-OS firmware is current per ICSA-26-202-02; restrict remote management to known maintenance IP ranges only.
ICS / OT
Emergency patch audit for all Fortinet appliances against CVE-2026-25089 (FortiSandbox pre-auth RCE, CVSS 9.8). Pioneer Kitten exploits Fortinet KEV additions within 24–72 hours — the window opened July 16.
Incident Responder
Conduct threat hunt for MuddyWater / Dalbit indicators in defense contractor and sensitive government network segments. Hunt Hypothesis 03 above provides the detailed detection logic.
Threat Hunter
Implement detection for M365 Graph API abuse (HOLLOWGRAPH C2 pattern) — monitor anomalous OneDrive / SharePoint API call volumes and unexpected service principal activity in M365 audit logs.
SOC Analyst
Audit all VPN / edge appliance configurations (Fortinet, Citrix, Ivanti) for unauthorized accounts, configuration changes not tied to change records, or passive sniffer implants.
IAM Analyst
Brief defense industrial base partners and critical vendors on MuddyWater / Dalbit defense-targeting samples and the Pioneer Kitten → Handala access-to-destruction pipeline.
CISO / Exec
No 7-day actions for the selected roles.
Commission comprehensive threat hunt for dormant Pioneer Kitten access across all edge infrastructure — focus on Fortinet, Citrix, and Ivanti devices with historical connections to Iranian ASNs. Use Hunt Hypothesis 01 as the starting framework.
Threat Hunter
Develop detection analytics for Russian-Iranian infrastructure convergence — alert on traffic to Iranian ASNs matching Russian APT behavioral signatures (APT28/GRU tooling patterns on ASN42337).
SOC Analyst
Conduct network segmentation review — verify OT/ICS networks are properly isolated from IT networks with monitored jump hosts; test lateral movement paths from internet-facing systems to SCADA environments.
ICS / OT
Evaluate addition of cloud security threat feeds (Wiz, Orca, Permiso) to address collection gaps on AI/cloud/OAuth weaponization techniques emerging from Iranian and allied actor groups.
CISO / Exec
Conduct tabletop exercise simulating a coordinated Iranian retaliatory campaign — simultaneous DDoS, wiper deployment, and data leak — against your organization. Test crisis communication, IR escalation, and business continuity procedures.
Incident ResponderCISO / Exec
Develop ASN-level blocking policy for Iranian hosting providers used by confirmed APT infrastructure — ASN213790, ASN34918, ASN42337. Coordinate with network teams on operational impact before deployment.
SOC Analyst
No 30-day actions for the selected roles.
Bottom Line

We are in uncharted territory. Nearly five months into the Iran conflict and 25 days after the most significant U.S. kinetic strikes on Iran since 1988, the Iranian cyber apparatus has maintained complete operational silence. Every historical precedent tells us this silence precedes action — not inaction. The confirmed convergence of Pioneer Kitten (access), Handala (destruction), and MuddyWater (espionage-as-ransomware) into coordinated operational pipelines means that when the retaliation comes, it will likely be simultaneous, multi-vector, and designed to maximize both operational impact and propaganda value. Your defensive posture today determines whether you are a target or a hard target.

1
Have you reviewed 90 days of netflow for ASN213790 connections? Iranian C2 infrastructure is actively maintained at confidence 97. Historical review is not optional — Pioneer Kitten pre-positions access months before activation.
2
Are all Fortinet appliances patched against CVE-2026-25089? Pioneer Kitten exploits Fortinet KEV additions within 24–72 hours of disclosure. The window opened July 16. It is closing now.
3
Do you have a wiper response plan? Handala's 25-day silence during peak escalation matches pre-deployment patterns from 2022. The group that ran the Albanian government wiper attack is quiet. That should concern you far more than if they were loud.
No items found.