TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Crosses the Rubicon:

First Confirmed Multi-Day Attack on Western Critical Infrastructure

HIGH. Six months into an escalating conflict between Iran and Western coalition partners, Tehran has delivered on its most aggressive cyber threat to date. An Iranian-attributed operation forced a British power plant offline for four consecutive days — the first confirmed multi-day disruption of critical infrastructure in a Five Eyes nation by an Iranian state-nexus actor. Iran has publicly declared intent, executed a destructive operation within 11 days of that declaration, and has not claimed credit — suggesting a deliberate strategy of deniability that raises the ceiling for future escalation.

I am a
My sector

DevelopmentSignificance
UK Power Plant Shutdown Confirmed (19–23 August). Four independent media outlets confirmed that Iranian-linked hackers forced a British power plant offline for four days. Staff "battled to bring systems back online." This is the most significant Iranian cyber operation against Western infrastructure since Shamoon (2012).The most significant Iranian cyber operation against Western infrastructure in over a decade
IRGC Threat-to-Action Cycle Quantified. IRGC Brigadier General Hossein Mohebbi publicly threatened US power grids on 12 August. The UK attack occurred 11 days later. This establishes a measurable predictive indicator — public IRGC threats now carry an operational timeline.Public IRGC threats now carry a measurable, actionable timeline
UNC7033 — New Iranian Espionage Actor Disclosed (27 August). Google Threat Intelligence published a new Iranian espionage cluster using ClickFix social engineering and browser storage pre-staging to target US think tanks and media organizations. Multi-platform capability (Windows and macOS).Novel technique chain bypasses traditional email security via user-initiated execution
Cactus/MuddyWater Infrastructure Active. High-confidence (97%) command-and-control IPs on ASN 213790 ("Limited Network," Tehran) are actively scanning healthcare, manufacturing, and technology targets — consistent with the MuddyWater-to-Cactus ransomware handoff pipeline.State espionage and criminal ransomware converge in a single intrusion
Six ICS Advisories in 24 Hours (27 August). CISA published advisories for Rockwell Automation OTTO Fleet Manager, Mitsubishi CNC, All-Line Fuel-Boss, and others — expanding the remotely exploitable OT attack surface that Iranian actors have historically weaponized within days of disclosure.Rapidly expanding OT attack surface matching Iran's historical exploitation speed
CyberAv3ngers Supply Chain Breach — FBI Investigation (26 August). The FBI opened an investigation into a breach of a Kansas water utility supplier, representing an evolution of the CyberAv3ngers campaign from direct ICS targeting to supply-chain infiltration of water and energy infrastructure.Evolution from direct exploitation to sustainable supply-chain access

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran-Western conflict escalation begins — Day 0 of current crisis.
MOIS espionage/ransomware crossoverJul–Aug 2026MuddyWater deploys updated DinDoor backdoor (Deno runtime) across 15 countries — MOIS espionage plus ransomware crossover confirmed.
Declaratory threat & UK attackAug 12–23, 2026IRGC BG Mohebbi publicly threatens US power grid cyber retaliation (Aug 12) — the first declaratory statement of destructive cyber intent; UK power plant attack begins (~Aug 19) and is restored after a 4-day outage (Aug 23) — the first confirmed multi-day ICS disruption of Western critical infrastructure.
Supply chain evolution & new actor disclosedAug 26–27, 2026FBI opens investigation into a Kansas water utility supplier breach — supply-chain evolution of the CyberAv3ngers campaign (Aug 26); UNC7033 disclosed and CISA publishes 6 ICS advisories (Aug 27).
Current (Day 181) — Cactus pipeline activeAug 28, 2026Cactus C2 infrastructure confirmed active on a Tehran ASN — the MuddyWater-to-Cactus ransomware pipeline is operational.

Attribution: Iranian state-nexus (HIGH confidence based on 4 independent sources + geopolitical context + IRGC declaratory statement). The specific unit responsible has not been publicly named — candidates include SPECTRAL KITTEN (Agrius family, IRGC-affiliated) and CyberAv3ngers (IRGC-CEC).

Motivation: explicit retaliation for UK allowing US to use British military bases for "defensive operations" against Iran.

Impact: four-day operational shutdown of power generation. Recovery required staff to "battle" systems back online — suggesting either data destruction or significant manipulation of stored data.

Precedent: this is the first time an Iranian actor has achieved a multi-day disruption of Western critical infrastructure. Previous Iranian ICS operations (Unitronics/water, 2023) caused brief disruptions. This represents an order-of-magnitude escalation in both duration and target significance.

T1489T1485T1565.001

A newly disclosed Iranian espionage cluster is impersonating US think tanks and news outlets to target policy researchers and intelligence analysts. The technique chain is novel for Iranian actors: initial access via spearphishing with service impersonation; execution via ClickFix social engineering that tricks victims into running platform-specific commands; staging via encrypted malware payloads pre-staged in browser storage mechanisms; and multi-platform capability spanning Windows and macOS.

Why this matters for CISOs: if your organization employs analysts who research Iran policy, Middle East geopolitics, or defense strategy, they are in UNC7033's targeting aperture. The ClickFix technique bypasses traditional email security because the malicious action occurs through user-initiated clipboard paste into a terminal.

T1566.003T1204.002T1027.013T1074.001

The MOIS-affiliated MuddyWater group continues to operate a dual-purpose pipeline: espionage access is handed off to Cactus ransomware operators for monetization. Active C2 infrastructure on Tehran-based ASN 213790 is scanning targets in healthcare, manufacturing, and technology sectors. This represents the convergence of state espionage and criminal ransomware — organizations face both data theft and encryption in a single intrusion.

T1071T1571T1595.002

Seven distinct Iranian-affiliated actors and campaigns are simultaneously tracked this cycle:

ActorAffiliationCurrent Activity
SPECTRAL KITTEN / AgriusIRGCUK power plant attack (assessed)
CyberAv3ngers / HYDRO KITTENIRGC-CECWater/energy supply chain (FBI investigation)
MuddyWater / Mango SandstormMOISDinDoor C2 active; Cactus handoff
UNC7033Iran (unspecified)ClickFix espionage against think tanks
APT34 / OilRigMOISProfile updated 28 Aug; monitoring for new IOCs
Pioneer Kitten / UNC757IRGCQuiet — possible post-exploitation phase
APT39 / ChaferMOISProfile updated 28 Aug

Pioneer Kitten's quiet period is notable given active KEVs for VPN appliances within their historical wheelhouse — possible post-exploitation phase rather than inactivity.

PredictionProbabilityTimeframeBasis
Iranian IO actors claim UK power plant attack via Telegram70%Within 7 daysHistorical pattern: claims timed for political leverage
CyberAv3ngers probe US water/energy infrastructure50%Ongoing (window open since 26 Aug)IRGC statement + historical targeting pattern
NCSC/GCHQ publish technical details of UK attack40%Within 14 daysStandard UK government disclosure timeline
UNC7033 IOCs published by Google30%Within 7 daysActor report created 27 Aug; IOC publication typically follows
Next IRGC public threat triggers new operation within 11 days60%Upon next statementSingle data point but operationally validated
Iranian actors exploit newly disclosed ICS vulnerabilities (Fuel-Boss, OTTO)45%Within 30 daysHistorical precedent: CyberAv3ngers exploited Unitronics within days of disclosure

ClickFix Detection (UNC7033):

Alert on PowerShell or Terminal commands initiated immediately following browser clipboard operations Detection logic: Browser process → clipboard write → terminal/PowerShell process spawn within 30 seconds Hunting hypothesis: "Are any analyst workstations executing PowerShell commands that were pasted from browser context, particularly after visiting think tank or news impersonation domains?"

Cactus/MuddyWater C2 Monitoring:

Monitor for command injection patterns against internet-facing applications (T1190) Alert on scanning activity from known Cactus infrastructure Hunting hypothesis: "Do we have any inbound connections from Tehran-based ASNs that correlate with vulnerability scanning or exploitation attempts against our web applications?"

ICS/OT Network Monitoring:

Verify segmentation between IT and OT networks — any bridge is a potential attack path Monitor for anomalous commands to PLCs (Rockwell, Siemens, Mitsubishi) Hunting hypothesis: "Are there any unauthorized connections from IT network segments to OT/SCADA systems, particularly from hosts that have communicated with external IPs in the last 30 days?"

ThreatATT&CK
ClickFix Detection (UNC7033)T1204.002 T1059.001
Cactus/MuddyWater C2 MonitoringT1190 T1595.002
ICS/OT Network MonitoringT1489 T1565.001
IOC Blocking Table:
77.90.185[.]118185.93.89[.]4377.90.185[.]248176.123.87[.]16

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1071
Hunt for Iranian Infrastructure Connections
Query all network telemetry (last 30 days) for connections to ASN 213790 ("Limited Network," Tehran). Any connection to this ASN from corporate or OT networks should be treated as a potential Iranian APT pre-positioning indicator.
HUNT 02 · T1204.002
Analyst workstations executing pasted PowerShell commands
Are any analyst workstations executing PowerShell commands that were pasted from browser context, particularly after visiting think tank or news impersonation domains?
HUNT 03 · T1190
Tehran-based scanning correlated with web application exploitation
Do we have any inbound connections from Tehran-based ASNs that correlate with vulnerability scanning or exploitation attempts against our web applications?
HUNT 04 · T1489
Unauthorized IT-to-OT connections
Are there any unauthorized connections from IT network segments to OT/SCADA systems, particularly from hosts that have communicated with external IPs in the last 30 days?

Financial Services
SWIFT/Wire Systems, EWS/M365
Primary threat
MuddyWater/Cactus ransomware pipeline with confirmed C2 targeting US financial services via DinDoor backdoor (Deno JavaScript runtime).
Actions
  • Audit for Deno runtime processes on endpoints — Deno is not standard in financial environments and its presence is anomalous
  • Review Exchange/M365 configurations for EWS API abuse (MuddyWater's preferred persistence mechanism)
  • Ensure wire transfer and SWIFT systems are segmented from general corporate networks
  • Validate that ransomware playbooks account for dual-purpose intrusions (data theft precedes encryption)
Energy
Generation, Fuel Management, Fleet Systems
Primary threat
SPECTRAL KITTEN/CyberAv3ngers targeting generation and distribution infrastructure. UK power plant attack confirms destructive capability and willingness.
Actions
  • Conduct an emergency audit of all internet-exposed ICS/SCADA interfaces — zero tolerance for direct exposure
  • Review All-Line Fuel-Boss deployments if present in fuel management systems — apply network segmentation immediately
  • Verify Rockwell Automation OTTO Fleet Manager credentials are not default
  • Establish or validate 24/7 OT monitoring capability — Iranian attacks have occurred outside business hours
  • Pre-position incident response retainers with ICS-specialized firms
Healthcare
Patient Portals, Backup Infrastructure
Primary threat
Cactus ransomware (via MuddyWater handoff) actively scanning healthcare targets from Tehran infrastructure.
Actions
  • Block identified Cactus IPs at perimeter immediately
  • Audit internet-facing medical device interfaces and patient portal applications for command injection vulnerabilities
  • Ensure backup systems are air-gapped — Cactus operators specifically target backup infrastructure
  • Review third-party vendor access (medical device manufacturers, EHR providers) for lateral movement risk
Government
Policy Analysts, Municipal Utilities, VPN
Primary threats
Multi-vector — APT34/OilRig espionage, UNC7033 think tank impersonation targeting policy staff, CyberAv3ngers targeting municipal water/fuel systems.
Actions
  • Brief all policy analysts working on Iran/Middle East portfolios on the ClickFix social engineering technique
  • Implement clipboard monitoring on analyst workstations (detect paste-to-terminal patterns)
  • Audit VPN appliance patch status — Pioneer Kitten historically exploits Citrix NetScaler and Ivanti vulnerabilities
  • Municipal utilities: verify Unitronics and similar PLCs are not internet-accessible; confirm CISA ICS advisory mitigations applied
Aviation / Logistics
Fleet Management, Booking Systems
Primary threat
APT39/Chafer targeting transportation sector; Rockwell OTTO Fleet Manager vulnerabilities in warehouse/logistics automation.
Actions
  • Audit autonomous mobile robot (AMR) and fleet management systems for default credentials and internet exposure
  • Review supply chain vendor access to logistics management platforms
  • Ensure cargo handling and fuel management systems (Fuel-Boss) are network-segmented
  • Monitor for reconnaissance against booking/reservation systems — APT39 has historically targeted airline passenger data
No sector cards match the selected filters.

Block Cactus C2 IPs (77.90.185[.]118, 185.93.89[.]43, 77.90.185[.]248) at perimeter; add to SIEM for a 30-day retrospective hunt.
SOC Analyst
Hunt for any historical connections to ASN 213790 across all network telemetry — escalate any hits as potential Iranian pre-positioning.
Threat Hunter
Verify All-Line Fuel-Boss and Rockwell OTTO Fleet Manager systems are not internet-exposed; apply emergency segmentation if found.
ICS / OT
Brief executive leadership: Iran has demonstrated willingness and capability to shut down Western power infrastructure for multiple days. Elevate organizational threat posture.
CISO / Exec
No immediate actions for the selected roles.
Deploy a ClickFix detection rule — alert on PowerShell/Terminal commands initiated from browser clipboard context on analyst and executive workstations.
SOC Analyst
Audit all Rockwell Automation deployments for weak/default credentials; apply CISA ICS advisory mitigations.
ICS / OT
Brief allied partners and sector ISACs on the 11-day IRGC threat-to-action predictive indicator — any future IRGC public cyber threat should trigger immediate defensive posture elevation.
CISO / Exec
Validate the ICS/OT incident response playbook — confirm the retainer with an ICS-specialized IR firm; tabletop a 4-day power/water outage scenario.
Incident Responder
No 7-day actions for the selected roles.
Establish collection capability for Iranian Telegram channels (Handala, Cyber Toufan, CyberAv3ngers) to close the IO/BDA visibility gap.
Threat Hunter
Commission a technical assessment mapping UK power plant attack TTPs (once published by NCSC) against your own ICS/OT architecture.
CISO / Exec
Deploy Deno runtime detection across endpoints — presence of Deno in non-development environments is a high-fidelity MuddyWater/DinDoor indicator.
SOC Analyst
Review cyber insurance coverage for state-sponsored destructive attacks — many policies exclude "acts of war"; confirm coverage position given confirmed Iranian state operations.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

One hundred eighty-one days into this conflict, Iran has moved from probing to destroying. The UK power plant shutdown is not an endpoint — it is a proof of concept. The IRGC has publicly stated that US power grids are next, and they delivered on their last threat in 11 days. It has now been five days since the UK power plant attack, and no Iranian-affiliated group has publicly claimed responsibility — abnormal, since Iranian hacktivist proxies (Handala, Cyber Toufan, CyberAv3ngers) typically claim operations within 48–72 hours to maximize psychological and political impact. The absence of a claim suggests deliberate deniability — Tehran wants the capability demonstrated but maintains plausible distance. This is more dangerous than a claimed attack, because it signals that Iran is willing to conduct destructive operations against Western infrastructure without the self-imposed constraint of public attribution. The escalation ceiling just rose. Every CISO in energy, water, healthcare, financial services, and government should be asking one question today: if the same operation that hit that UK power plant hit my organization tomorrow, would we survive four days?

1
If the answer isn't an immediate and confident yes, the time to act is now — not after the next IRGC press conference.
2
The IRGC delivered on their last public threat within 11 days. Treat any future declaratory statement as an operational countdown.
3
The silence since the UK attack is the signal, not the reassurance — deliberate deniability raises the ceiling for what comes next.
No items found.