TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Didn't End With the Ceasefire —

It Accelerated

HIGH. The kinetic ceasefire between the United States, Israel, and Iran was supposed to reduce tensions. In cyberspace, it has done the opposite. 167 days into sustained Iranian cyber operations, water utilities across six U.S. states have been compromised in a coordinated campaign, Israeli INCD reports cyber incidents running at 3x year-over-year tempo, and Tehran has developed a new hybrid intelligence model that converts Telegram conversations into insider access at military installations.

I am a
My sector

DateDevelopmentSignificance
August 4, 2026FBI/EPA confirmed HYDRO KITTEN (CyberAv3ngers/IRGC-CEC) compromised 36+ water utilities across 6+ U.S. statesEscalation from single-state to coordinated national campaign
August 6, 2026Shin Bet reports Telegram-based HUMINT-cyber recruitment targeting Israeli military basesNew Iranian doctrine converging human intelligence and cyber-enabled social engineering
August 11, 2026CVE-2026-20349 added to CISA KEV — active exploitation of Cisco ASA/FTD SSL VPN; Cactus ransomware sample linked to MuddyWater (MOIS) infrastructurePerimeter device exploitation continues; ransomware-as-cover confirmed
August 12, 2026Pioneer Kitten / Fox Kitten ThreatStream profile updated — active perimeter exploitation ongoingFortinet vulnerability weaponization window now open following August 13 patches
August 13–14, 2026Israeli INCD chief confirms 4,800 cyber incidents/month (3x year-over-year); 14 CISA ICS advisories for Siemens and Johnson Controls; APT34 tooling refresh confirmed activeSustained maximum tempo; expanded OT attack surface; active Iranian APT tooling
August 13–14, 2026APT42 (Charming Kitten/IRGC-IO) BELLACIAO backdoor deployments and credential theft operations confirmed at elevated tempoOperational pace aligns with 3x surge; targeting spans government, defense, and civil society

PhaseTimeframeCyber Activity
Kinetic conflict escalationFeb 28, 2026Kinetic conflict escalation begins between Iran, the U.S., and Israel.
Sustained tempo surgeJun 2026Israeli INCD records 4,800 hostile cyber incidents/month — a 3x year-over-year increase — across multiple Iranian APTs.
Water utility campaignJul 26 – Aug 6, 2026HYDRO KITTEN/CyberAv3ngers (IRGC-CEC) begins coordinated water facility attacks; FBI/EPA confirm 36+ Minnesota utilities compromised across 6+ states (Aug 4); CSIS publishes analysis confirming multi-state campaign scope (Aug 6); Shin Bet reports Telegram-based HUMINT-cyber recruitment targeting Israeli military bases (Aug 6).
Perimeter exploitation & infrastructure refreshAug 11–12, 2026CVE-2026-20349 (Cisco ASA/FTD) added to CISA KEV; Cactus ransomware linked to MuddyWater infrastructure on ASN 213790 (Aug 11); Pioneer Kitten/Fox Kitten ThreatStream profile updated, active perimeter exploitation ongoing (Aug 12).
Current (Day 167) — maximum tempoAug 13–14, 2026Fortinet patches critical FortiWeb/FortiManager auth bypass; 14 CISA ICS advisories published for Siemens and Johnson Controls; APT34/Hexane tooling refresh confirmed active; APT42 BELLACIAO deployments at elevated tempo.

Attribution: IRGC Cyber-Electronic Command (IRGC-CEC). Aliases: CyberAv3ngers, HYDRO KITTEN.

What began as a localized incident in Minnesota has been confirmed as a coordinated campaign spanning at least six U.S. states. The attackers are manipulating programmable logic controllers (PLCs) — primarily Unitronics devices — to cause physical water service disruptions. This is not data theft or espionage. This is a destructive operation designed to demonstrate Iran's ability to impact American daily life.

TTPs: exploitation of internet-facing SCADA interfaces, abuse of default PLC credentials, endpoint denial of service, and external defacement as a signature calling card.

Why it matters for CISOs: if your organization operates any water, wastewater, or utility infrastructure — or depends on municipal water systems for facility operations — you are in the blast radius. The geographic expansion from one state to six indicates pre-positioned access that may extend further.

T1190T1078T1499T1491.002

Attribution: Iranian Ministry of Intelligence and Security (MOIS). Aliases: MuddyWater, TEMP.Zagros, UNC3313, Mango Sandstorm, MUDDY ION.

MuddyWater continues to operate at high tempo, with a confirmed link between their infrastructure (ASN 213790) and a fresh Cactus ransomware sample. This aligns with the established Iranian playbook: use ransomware as cover for destructive or espionage operations, generating revenue while obscuring state attribution.

Active CVE: CVE-2026-20349 (Cisco ASA/FTD SSL VPN) — confirmed actively exploited and added to CISA's Known Exploited Vulnerabilities catalog on August 11.

T1486T1071.001

Attribution: Iranian state-sponsored (MOIS-linked). Aliases: APT34, Hexane, Chrysene, Helix Kitten, OilRig.

APT34's tooling remains operationally active, with a confirmed IOC refresh on August 14. Their targeting spans energy, government, telecommunications, and defense sectors. A parallel campaign using compromised Israeli websites as watering holes to steal credentials and deploy new malware is targeting construction, energy, manufacturing, and utilities sectors.

T1059.001T1105T1189

Attribution: UNC757 (Iranian nexus). Aliases: Pioneer Kitten, Fox Kitten, Parisite, RUBIDIUM.

Pioneer Kitten's ThreatStream profile was updated August 12, indicating continued activity. This actor historically weaponizes Fortinet and other perimeter device vulnerabilities within 48–72 hours of disclosure. With Fortinet's August 13 patches for critical FortiWeb/FortiManager authentication bypass flaws, the exploitation window is open now.

T1190

Attribution: IRGC Intelligence Organization (IRGC-IO). Aliases: APT42, Charming Kitten.

Active campaigns include BELLACIAO backdoor deployment and credential theft operations. APT42's operational tempo aligns with the broader 3x surge documented by Israeli INCD.

Attribution: likely IRGC-IO or MOIS (unconfirmed).

Iran has developed a new intelligence doctrine that uses Telegram as a recruitment platform to convert social media contacts into physical insider threats at military installations. Shin Bet reports a "significant increase" in Iran-linked espionage cases. This represents a convergence of traditional human intelligence and cyber-enabled social engineering that bypasses purely technical defenses.

Separately, 14 CISA ICS advisories published August 13 expand the OT attack surface Iranian actors can exploit:

ProductVendorImpact
Siveillance VideoSiemensRemote Code Execution — surveillance systems in government/military facilities
MetasysJohnson ControlsPersistent malicious payload injection — building automation in government, military, CI
AirwallJohnson ControlsAuth bypass, data decryption — segmentation appliance, enables lateral movement
Desigo DXR/PXCSiemensDenial of Service — HVAC/building controllers, physical disruption potential
License ServerSiemensPrivilege escalation + arbitrary read — lateral movement enabler
HIPASE-250ANDRITZDevice data read / workstation access — industrial process control

Johnson Controls Metasys is deployed extensively in U.S. government buildings and military facilities — CyberAv3ngers has demonstrated willingness to manipulate building automation and industrial control systems.

T1566.004

ScenarioTimeframeProbabilityBasis
Additional U.S. water/energy sector targeting reports as CISA completes incident responseNext 48 hours85–90%Six-state campaign scope suggests additional undisclosed victims
HYDRO KITTEN infrastructure rotation on known ASNs (34918, 213790)Next 48 hours70–80%Standard operational security after public attribution
Pioneer Kitten exploitation of Fortinet FortiWeb/FortiManager auth bypassNext 72 hours65–75%Historical pattern: 48–72 hour weaponization window
Destructive operation by Agrius/SPECTRAL KITTEN against Israeli critical infrastructureNext 7 days35–45%Conspicuous silence during maximum tempo period; historical pattern of silence before destructive ops
Additional U.S. critical infrastructure targeting (any sector)Next 7 days75–85%Sustained tempo, expanded geographic scope, pre-positioned access
Iranian HUMINT-cyber operation generating counterintelligence arrests in Israel, triggering retaliatory cyber escalationNext 30 days50–60%Shin Bet reporting indicates active investigations

ATT&CK TechniqueDetection FocusContext
T1190 — Exploit Public-Facing ApplicationMonitor Cisco ASA/FTD, Fortinet FortiWeb/FortiManager, Unitronics PLC web interfaces for exploitation attemptsPrimary Iranian initial access vector; CVE-2026-20349 actively exploited
T1078 — Valid AccountsAlert on default credential usage on PLCs, building automation systems; monitor for credential stuffing against OT web interfacesHYDRO KITTEN uses default PLC credentials
T1059.001 — PowerShellDetect encoded/obfuscated PowerShell execution on endpoints, especially in energy/government environmentsAPT34 tradecraft signature
T1105 — Ingress Tool TransferMonitor for unusual binary downloads to endpoints, particularly Windows executables from non-standard sourcesAPT34/Hexane active tooling deployment
T1071.001 — Web ProtocolsInspect outbound HTTPS to known Iranian C2 ASNs (34918, 213790); look for beaconing patternsMuddyWater and HYDRO KITTEN C2
T1189 — Drive-by CompromiseMonitor for redirects to compromised Israeli websites from corporate browsing; inspect for credential harvesting formsActive Iranian watering hole campaign
T1566.004 — Spearphishing via ServiceMonitor Telegram usage by personnel with access to sensitive systems; flag recruitment-pattern conversationsHUMINT-cyber hybrid model
T1486 — Data Encrypted for ImpactCactus ransomware detection; monitor for mass file encryption events, especially on systems connected to Iranian-linked infrastructureRansomware-as-cover for state operations
Hunting Hypotheses:
HUNT 01
HYDRO KITTEN has pre-positioned access in water utilities beyond the six confirmed states.
HYDRO KITTEN has pre-positioned access in water utilities beyond the six confirmed states. - Hunt: Query for Unitronics PLC web interface access from external IPs; review VPN logs for anomalous connections to SCADA segments; check for default credential usage on any internet-facing OT device.
HUNT 02
Pioneer Kitten is actively exploiting the new Fortinet vulnerabilities within your envi...
Pioneer Kitten is actively exploiting the new Fortinet vulnerabilities within your environment. - Hunt: Review FortiWeb/FortiManager authentication logs for bypass attempts; check for unauthorized admin account creation; inspect SSL VPN session logs for anomalous geographic origins.
HUNT 03
APT34 tooling is present on endpoints in energy/government networks.
APT34 tooling is present on endpoints in energy/government networks. - Hunt: Scan for APT34/Hexane/OilRig indicators available via Anomali ThreatStream (request the August 14 IOC refresh package); review PowerShell execution logs for obfuscated commands; check for beaconing to unfamiliar domains on energy/government network segments.
HUNT 04
MuddyWater is using Cactus ransomware as cover for espionage in your environment.
MuddyWater is using Cactus ransomware as cover for espionage in your environment. - Hunt: Correlate any ransomware alerts with connections to ASN 213790; review pre-encryption lateral movement for data staging/exfiltration patterns inconsistent with pure ransomware motivation.
HUNT 05
Compromised Israeli websites are being used to harvest credentials from your users.
Compromised Israeli websites are being used to harvest credentials from your users. - Hunt: Review web proxy logs for connections to Israeli domains (.co.il) that triggered credential prompts; check for new OAuth application consents; review MFA bypass attempts following browsing sessions.

Financial Services
Banking, Wire Transfer Systems
Primary threats
Credential theft campaigns via compromised websites (APT34, unnamed Iranian espionage group); ransomware-as-cover operations (MuddyWater/Cactus).
Secondary threat
Monitor for anomalous OAuth consent grants; credential stuffing against online banking portals from Middle Eastern IP ranges.
Actions
  • Enforce hardware MFA on all customer-facing and internal banking platforms
  • Deploy behavioral analytics on wire transfer systems
  • Review third-party connections to Israeli financial institutions for watering hole exposure
  • Ensure ransomware playbooks account for state-sponsored actors who may not negotiate
Energy
SCADA/HMI, Grid PLCs
Primary threat
HYDRO KITTEN/CyberAv3ngers targeting utility PLCs; APT34 active tooling targeting energy sector; LOGJAM malware tagged energy/utilities.
Secondary threat
Monitor any external connection attempts to OT subnets; PLC configuration changes outside maintenance windows; DNS queries to known Iranian C2 infrastructure from OT-adjacent systems.
Actions
  • Audit all internet-facing SCADA/HMI interfaces — remove from public internet immediately if exposed
  • Verify Unitronics PLC firmware versions and change all default credentials
  • Segment OT networks from IT with unidirectional gateways where possible
  • Patch Cisco ASA/FTD (CVE-2026-20349) on all perimeter devices protecting OT segments
Healthcare
EHR Systems, Building Automation
Primary threat
Ransomware-as-cover (Cactus via MuddyWater infrastructure); building automation compromise (Johnson Controls Metasys in hospital facilities); supply chain risk from compromised medical device vendors.
Secondary threat
Monitor building automation system alerts; unusual HVAC/environmental control changes; ransomware precursor activity (mass file enumeration, shadow copy deletion).
Actions
  • Verify Johnson Controls Metasys and Airwall patch status on all hospital building management systems
  • Ensure medical device network segments cannot reach the internet directly
  • Validate backup integrity for patient records and clinical systems
  • Brief incident response teams on state-sponsored ransomware scenarios where decryption keys may never be provided
Government
Classified Systems, Government Facilities
Primary threat
APT34/APT42 credential theft and espionage; Johnson Controls building automation exploitation in government facilities; Telegram-based HUMINT recruitment of cleared personnel; Pioneer Kitten perimeter exploitation.
Secondary threat
Monitor Telegram usage by cleared personnel; anomalous VPN sessions from unexpected geolocations; building automation configuration changes; PowerShell execution on domain controllers.
Actions
  • Patch all Fortinet FortiWeb/FortiManager instances within 48 hours
  • Audit Johnson Controls Metasys deployments in government buildings for unauthorized access
  • Issue a personnel security advisory on Telegram-based recruitment approaches
  • Review all VPN authentication logs for Cisco ASA/FTD exploitation indicators
  • Enforce phishing-resistant MFA (FIDO2) on all privileged accounts
Aviation / Logistics
Supply Chain, CPDLC Systems
Primary threat
Supply chain compromise through compromised vendor websites; APT34 targeting of transportation/logistics; potential (unconfirmed) CPDLC/ATN-B1 aviation protocol exploitation.
Secondary threat
Monitor unusual data flows from logistics management platforms; vendor portal credential reuse; any anomalous connections to aviation operational technology systems.
Actions
  • Review all vendor portal connections for watering hole indicators
  • Audit supply chain management systems for unauthorized access
  • Ensure air-gapped systems remain truly isolated
  • Validate integrity of flight operations and logistics planning systems
No sector cards match the selected filters.

Patch Cisco ASA/FTD devices for CVE-2026-20349 — actively exploited by Iranian actors for SSL VPN compromise.
Incident Responder
Patch Johnson Controls Metasys and Airwall — CISA advisories confirm RCE and authentication bypass in building automation systems deployed in government/military facilities.
ICS / OT
Deploy the APT34/OilRig IOC package (request the August 14 refresh via Anomali ThreatStream) to all endpoint detection platforms and network security tools.
SOC Analyst
Expand HYDRO KITTEN monitoring nationally — update correlation rules from Minnesota-specific to all U.S. water utility telemetry; alert on any Unitronics PLC web interface access from external IPs.
SOC Analyst
Block or alert on ASN 34918 and ASN 213790 at network perimeter — confirmed Iranian C2 infrastructure.
Incident Responder
Patch Fortinet FortiWeb/FortiManager — critical authentication bypass; Pioneer Kitten historically weaponizes within 48–72 hours of disclosure.
Incident Responder
No immediate actions for the selected roles.
Brief counterintelligence and HR teams on the Iranian Telegram-based recruitment model targeting military/government personnel — issue a personnel security advisory.
CISO / Exec
Validate M365/cloud detection rules — verify OAuth consent monitoring, calendar-based C2 detection, and Entra ID anomaly rules are functioning; absence of alerts during a surge period may indicate detection gaps.
SOC Analyst
Conduct a threat hunt for Pioneer Kitten indicators across all Fortinet and SonicWall devices — check for unauthorized admin accounts, anomalous VPN sessions, and web shell artifacts.
Threat Hunter
Audit all internet-facing OT/ICS devices — remove unnecessary internet exposure; change all default credentials on PLCs, HMIs, and building automation controllers.
ICS / OT
Review web proxy logs for connections to compromised Israeli websites (.co.il domains) that may be serving credential harvesting pages.
SOC Analyst
No 7-day actions for the selected roles.
Commission an OT/ICS security assessment — the convergence of 14 CISA ICS advisories with active Iranian OT targeting demands a comprehensive review of building automation and industrial control system security posture.
CISO / Exec
Update incident response playbooks for state-sponsored ransomware scenarios — traditional ransomware IR assumes a financially motivated actor who will negotiate; Iranian ransomware-as-cover operations may be purely destructive.
Incident Responder
Audit Siemens Desigo DXR/PXC controller firmware across all facilities — the DoS vulnerability could enable physical disruption of HVAC and building systems.
ICS / OT
Review cyber insurance coverage for state-sponsored attacks — many policies exclude "acts of war"; confirm coverage applicability given the current Iran conflict classification.
CISO / Exec
Deliver a board-level briefing on the sustained Iranian cyber campaign — communicate that the ceasefire has not reduced cyber risk; request authorization for accelerated OT security investment.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Iran's cyber campaign is not winding down. It is expanding geographically (one state to six), evolving doctrinally (pure cyber to HUMINT-cyber hybrid), and intensifying operationally (4,800 incidents per month against Israel alone). The ceasefire created a paradox: by pausing kinetic operations, it freed Iranian cyber units to concentrate entirely on digital warfare. The next 30 days will likely bring additional disclosures of compromised infrastructure, potential destructive operations from currently-silent Iranian actors, and continued exploitation of newly disclosed vulnerabilities. The organizations that act on this intelligence today will be the ones that avoid becoming tomorrow's headline.

1
If you operate OT/ICS systems — particularly water, energy, or building automation — you are an active target, not a theoretical one.
2
If you rely on Cisco, Fortinet, or SonicWall perimeter devices — Iranian actors are exploiting these faster than most organizations can patch them.
3
If your personnel use Telegram or have security clearances — the threat now includes social engineering for physical insider recruitment, not just phishing for credentials.
No items found.