| Date | Development | Significance |
|---|---|---|
| Jul 22 | Operation Midnight Hammer cyber component publicly disclosed — USCYBERCOM confirms disabling Iranian air defense systems | Provides Iran propaganda justification for retaliatory cyber operations at scale |
| Jul 22 | 25 days of complete hacktivist silence — longest on record following a kinetic escalation | Assessed as pre-staging indicator for coordinated multi-vector attack |
| Jul 21 | MuddyWater/Dalbit defense-sector sample identified with Hive ransomware components | First DIB-specific targeting in espionage-as-ransomware crossover pipeline |
| Jul 21 | CISA publishes 10 ICS advisories — Siemens RUGGEDCOM and Rockwell Studio 5000 Logix Designer | OT attack surface expands during peak conflict — includes arbitrary file execution in PLC programming environments |
| Jul 20–21 | HOLLOWGRAPH implant publicly disclosed; APT34 refreshes malware with expanded targeting | M365 Graph API C2 now observed against Malaysian and Australian targets |
| Jul 16 | CISA adds CVE-2026-25089 (FortiSandbox pre-auth RCE, CVSS 9.8) to KEV catalog | Pioneer Kitten historically exploits Fortinet vulnerabilities within 24–72 hours of KEV disclosure |
| Jul 11–14 | ASN213790 C2 infrastructure refreshed — three IPs at confidence 77–97 | Pre-operational indicator: infrastructure actively maintained and ready for activation |
| Jul 7 | U.S. retaliatory strikes for Strait of Hormuz cargo ship attack | Second kinetic trigger; retaliation pressure compounds across all Iranian proxy groups |
| Jun 29 | Israeli cyber chief publicly confirms Iranian cyberattacks surged in 2026 | Validates escalating Iranian cyber tempo throughout the conflict |
| Jun 26 | U.S. Operation Midnight Hammer — strikes on Fordo, Natanz, Isfahan nuclear facilities | Retaliation clock starts; USCYBERCOM disables Iranian SAM command-and-control |
| Jun 3 | HOLLOWGRAPH implant becomes operational against Israeli targets | APT34/Lyceum deploys novel M365 Graph API C2 — no prior public reporting |
| Feb 28 | Iran-Israel conflict escalation begins | Iranian cyber operations tempo increases across all actor groups |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Pre-escalation | Before Feb 28, 2026 | Baseline Iranian espionage — APT34, MuddyWater, Pioneer Kitten access brokering; HOLLOWGRAPH development underway |
| Conflict escalation | Feb 28 – May 2026 | Iranian cyber tempo increases; APT34 deploys HOLLOWGRAPH against Israeli targets; Pioneer Kitten infrastructure build-out |
| Operation Midnight Hammer | Jun 26, 2026 | U.S. strikes Fordo, Natanz, Isfahan; USCYBERCOM disables Iranian air defenses; retaliation window opens |
| Retaliation staging | Jun 27 – Jul 21, 2026 | 25-day hacktivist silence begins; ASN213790 infrastructure refreshed; Pioneer Kitten/Handala/Banished Kitten convergence confirmed via shared malware samples; MuddyWater pivots to defense-sector targeting |
| Current (Day 25) | Jul 22, 2026 | Midnight Hammer cyber operations disclosed; maximum retaliatory motivation established; 10 ICS advisories expand OT attack surface; defense-sector ransomware targeting confirmed |
We are 25 days into the retaliation window following Operation Midnight Hammer — exceeding all modern precedents for Iranian hacktivist response time. Historical patterns: Stuxnet disclosure drove Shamoon within 18 months; Soleimani assassination triggered DDoS and wiper campaigns within 72 hours; U.S. strikes on Houthis produced Cyber Av3ngers ICS campaigns within 2 weeks. None of those silences lasted 25 days.
Two hypotheses explain this: pre-staging a coordinated operation (60% confidence) — Iranian operators using the quiet period to pre-position access, stage destructive payloads, and coordinate across proxy groups for a simultaneous multi-target attack; or capability degradation from kinetic strikes (40% confidence). Persistent C2 activity on ASN213790 argues strongly against the latter. The silence is not reassurance. It is the signal.
Eight confirmed Iranian threat actor groups are active or have been updated in intelligence platforms within the past 48 hours. IRGC-affiliated actors are executing the access-to-destruction chain; MOIS-affiliated actors are conducting espionage and supply-chain targeting.
| Actor | Affiliation | Role | Current Status |
|---|---|---|---|
| Pioneer Kitten (Fox Kitten, UNC757) | IRGC | Access broker — edge appliance exploitation, access handoff to destructors | Active — 7 fresh malware samples Jul 22; Fortinet exploitation within 24–72h of KEV |
| Cyber Av3ngers | IRGC | ICS/OT destructor — targets water, energy PLCs | Silent 25 days — anomalous; may indicate exploit development for new ICS advisories |
| Handala / Banished Kitten (Cotton Sandstorm) | IRGC | Destructive hacktivist — wiper deployment, data leaks | Silent 25 days — convergence with Pioneer Kitten confirmed via shared malware samples |
| APT34 (OilRig, Helix Kitten) | MOIS | Espionage — government, energy, telecom; HOLLOWGRAPH M365 C2 | Active — malware refresh Jul 21; expanded targeting to Malaysia and Australia |
| MuddyWater (UNC3313, Static Kitten) | MOIS | Initial access + espionage — government, DIB, telecom | Active — defense-sector samples with Hive ransomware crossover confirmed |
| APT33 (Elfin) | IRGC/MOIS | Destructive capability — aviation, energy, petrochemical | Updated Jul 21–22 in threat intelligence platforms |
| APT35 (Phosphorus) | IRGC | Credential harvesting — think tanks, government, media | Updated Jul 21–22 in threat intelligence platforms |
| APT42 | IRGC-IO | Surveillance + credential theft — dissidents, policy makers | Updated Jul 21–22 |
The most dangerous development in this conflict cycle: seven malware samples are co-tagged to Pioneer Kitten, Handala, and Banished Kitten simultaneously — confirming a live operational handoff pipeline between Iran's leading access broker and its most destructive proxy groups.
The pipeline mirrors the model Iran used in the 2022 Albanian government wiper attack, where access was established months before the destructive phase. Pioneer Kitten gains initial access via exploitation of internet-facing Fortinet, Citrix, and Ivanti appliances; access is handed to Handala or Banished Kitten; a destructive payload — wiper, ransomware-as-cover, or data destruction — is deployed. The 25-day silence is consistent with the pre-positioning phase of this model.
Intelligence this cycle confirms MuddyWater is adopting the Russian playbook of using ransomware to mask espionage and provide plausible deniability for destructive operations. Samples now tagged to both MuddyWater and Dalbit/Silent Chollima with Hive ransomware family indicators explicitly target the defense sector — the first confirmed DIB-specific targeting in this crossover pipeline.
Rather than conducting overt espionage that risks attribution and diplomatic consequences, MOIS-affiliated actors are deploying ransomware that appears criminal while simultaneously exfiltrating sensitive defense data. The targeting of financial services, government, telecom, and utilities alongside defense suggests broad pre-positioning across multiple verticals.
Ten new CISA ICS advisories published July 21 affect systems directly relevant to critical infrastructure operators during peak conflict: Rockwell Studio 5000 Logix Designer — arbitrary file execution and configuration alteration in PLC programming environments (highest concern given Cyber Av3ngers' demonstrated interest in PLC manipulation); Siemens RUGGEDCOM APE1808 — PAN-OS vulnerabilities in industrial firewall appliances; and Rockwell 1734/1719 POINT I/O — denial-of-service against I/O modules capable of causing physical process disruption.
Cyber Av3ngers has previously demonstrated both the intent and capability to target industrial control systems. Their 25-day silence during a period of maximum kinetic escalation and maximum new vulnerability disclosure is consistent with exploit development rather than operational cessation.
An IP address on ASN42337 (Respina Networks, Tehran) carries APT28 (GRU Unit 26165) attribution tags — a Russian military intelligence actor appearing on Iranian-hosted infrastructure. While this could represent misattribution or shared scanning infrastructure, the signal aligns with broader intelligence indicating Russian-Iranian operational cooperation in cyberspace.
Implication for defenders: monitor for blended TTPs that combine Russian sophistication (advanced persistence, living-off-the-land techniques) with Iranian targeting preferences (critical infrastructure, defense sector, government). Organizations should develop detection logic that alerts on traffic to Iranian ASNs matching Russian APT behavioral signatures.
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Iranian state media / IRGC issues retaliatory rhetoric responding to Midnight Hammer disclosure | 70% | 48–72 hours | Standard propaganda response cycle; disclosure provides narrative ammunition and justification framework |
| Handala or Cyber Av3ngers breaks silence with a claimed operation (likely pre-staged) | 45% | 7–14 days | 25-day silence consistent with pre-staging; historical pattern of coordinated reveal following quiet pre-positioning |
| Pioneer Kitten mass-exploitation of CVE-2026-25089 (FortiSandbox) against Western targets | 35% | 7–14 days | Historical exploitation within 24–72h of Fortinet KEV additions; currently within window since Jul 16 disclosure |
| MuddyWater phishing campaign targeting U.S. government / military using conflict lures | 30% | 7–14 days | Conflict-themed lures are standard MuddyWater tradecraft; defense-sector targeting already confirmed this cycle |
| Destructive wiper deployment against Israeli or Gulf state critical infrastructure | 25% | 14–30 days | Handala pipeline confirmed active; 2022 Albania precedent shows months of pre-staging before destructive phase |
| Coordinated multi-target retaliatory campaign (DDoS + wiper + data leak) against U.S. interests | 20% | 14–45 days | Highest-consequence scenario; silence duration suggests coordination across multiple groups; 60% pre-staging confidence |
| Rule | Data Source | ATT&CK | Priority |
|---|---|---|---|
Any connection (inbound or outbound) to 185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43 — ASN213790, Iranian APT C2 | Firewall / Netflow | T1071.001 | CRITICAL |
| SHA-256 match on Pioneer Kitten / Handala / Banished Kitten samples (7 hashes) on any endpoint | EDR | T1190 T1486 | CRITICAL |
| Anomalous Microsoft 365 Graph API call volumes or unexpected OneDrive / SharePoint API access (HOLLOWGRAPH C2 pattern) | M365 Audit Logs | T1071.001 T1567.002 | HIGH |
| Exploitation attempts targeting FortiSandbox CVE-2026-25089 — pre-auth RCE, CVSS 9.8 | WAF / Edge appliance logs | T1190 | HIGH |
| SHA-256 match on MuddyWater / Dalbit / Hive samples in defense contractor network segments (3 hashes) | EDR | T1195.002 T1486 | HIGH |
| Security tool disabling (EDR agent tampering, AV exclusion additions) followed by anomalous file encryption | EDR | T1562.001 T1497.003 | HIGH |
| Unexpected PLC programming activity or configuration changes on Rockwell Studio 5000 / Siemens RUGGEDCOM | OT network monitoring | T0816 T0826 | HIGH |
| Connections to ASN34918 (Pishgaman Toseeh) or ASN42337 (Respina Networks) — confirmed Iranian APT-linked hosting | Firewall / Netflow | T1071.001 | MEDIUM |
Five IPs across ASN213790 (confidence 77–97), ASN34918, and ASN42337 — confirmed Iranian APT C2 infrastructure. Pioneer Kitten / Handala (7 hashes, confidence High): 028d3de0f0709a18c9928526519e761a08f6766d1eca386e908588f995f44e7f, 0a5cf97e699c8bfacee7f89ebfaa851ff03dd004a58ffde9c609fcc2cd27f250, 7540bed5efd55f75271bb4b5a5afb28f343ebe64a816f74f0edba8527dc5e181, and 4 additional hashes. MuddyWater / Dalbit / Hive (3 hashes): 0a472e47c338062af13c2e18561b4e5f7371c71732136c7c117eca7370678d77, 9db865ccc51ab10e6db39682e7cad87386e43bcf41dadb2559ce1030f691d8c6, fcc85234347de8a69b510c40acb1ad7a0bd63893870f6f190597d88b3c828f50. Full IOC set via Anomali ThreatStream and partner feeds.
- Audit SWIFT and core banking system access controls for anomalous service accounts or off-hours authentication
- Verify offline backup integrity for transaction databases — assume ransomware deployment is possible within the 14-day window
- Monitor for IcedID loader activity (tagged on ASN34918 infrastructure) as a potential initial access vector
- Review third-party vendor connections to defense contractors for crossover targeting risk
- Enable enhanced logging on all internet-facing financial applications and API gateways
- Immediately verify IT/OT air-gap integrity — assume adversary will attempt lateral movement from IT-side compromise to OT networks
- Patch or isolate Rockwell Studio 5000 Logix Designer per ICSA-26-202-10; verify no internet exposure of PLC programming environments
- Audit Siemens RUGGEDCOM APE1808 firmware versions against ICSA-26-202-02; restrict remote management access
- Deploy additional monitoring on Rockwell 1734/1719 POINT I/O modules for denial-of-service indicators
- Prepare manual override procedures for critical processes in case of PLC manipulation or configuration alteration
- Conduct emergency audit of all Fortinet, Citrix, and Ivanti appliances for indicators of Pioneer Kitten exploitation
- Block ASN213790 and ASN34918 at network perimeter immediately; expand to full ASN-level monitoring
- Verify medical device network segmentation — ensure IoT and medical devices cannot reach identified C2 infrastructure
- Review VPN authentication logs for the past 90 days for connections originating from Iranian ASNs
- Ensure patient data backup systems are isolated, verified, and tested for restoration within acceptable RTO
- Activate heightened monitoring on all .gov and .mil email systems for Iran conflict-themed phishing lures
- Audit Microsoft Teams device-code authentication flows — a known MuddyWater initial access technique
- Review PTC Windchill and other PLM/engineering data systems for unauthorized access (DIB supply chain risk)
- Verify ITSM and ServiceNow platforms are patched against recent CVEs exploited by MOIS actors
- Coordinate with CISA for latest Shields Up guidance specific to Iranian retaliation scenarios
- Review all Cisco ASA/FTD configurations for unauthorized changes — APT33 historically targets network infrastructure in aviation
- Audit flight operations and logistics management systems for anomalous access patterns or privilege escalation
- Monitor for APT33-associated malware families (Shamoon variants, StoneDrill) in endpoint telemetry
- Verify cargo tracking and port management systems are segmented from corporate networks and cannot reach identified C2 infrastructure
- Coordinate with TSA and maritime security authorities on current threat posture and Shields Up implementation
185.93.89[.]75, 77.90.185[.]118, 185.93.89[.]43, 5.202.4[.]18, 2.188.214[.]142. Expand to ASN-level blocking for ASN213790 and ASN34918.We are in uncharted territory. Nearly five months into the Iran conflict and 25 days after the most significant U.S. kinetic strikes on Iran since 1988, the Iranian cyber apparatus has maintained complete operational silence. Every historical precedent tells us this silence precedes action — not inaction. The confirmed convergence of Pioneer Kitten (access), Handala (destruction), and MuddyWater (espionage-as-ransomware) into coordinated operational pipelines means that when the retaliation comes, it will likely be simultaneous, multi-vector, and designed to maximize both operational impact and propaganda value. Your defensive posture today determines whether you are a target or a hard target.