TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Enters Its Most Dangerous Phase:

What CISOs Must Do in the Next 72 Hours

CRITICAL. Six months into the US-Iran conflict, the cyber dimension has reached an inflection point. On 31 August, an Iranian hacking group calling itself "APT IRAN" posted a direct threat on Telegram naming energy, water, and telecommunications — approximately 24 hours before kinetic strikes resumed between the US and Iran following a month-long pause. This is backed by demonstrated capability: a successful hack that disabled a British power plant for four days in August, and an active FBI investigation into Iranian-linked cyberattacks on municipal water systems across seven or more US states.

I am a
My sector

DevelopmentSignificance
Kinetic escalation resumed. After a month-long pause, the US launched strikes against Iranian coastal positions around the Strait of Hormuz on 1–2 September. Iran responded with missiles targeting US bases in Jordan, the UAE, Kuwait, Bahrain, and Kurdistan. Iranian state media reported civilian casualties. The Iranian rial collapsed to a record low of 2.20 million to the dollar — a 10% drop in a single week.Economic pressure increases the likelihood of an asymmetric cyber response
Explicit cyber threat declaration. The "APT IRAN" Telegram channel issued a direct threat against US energy, water, and telecommunications on 31 August — approximately 24 hours before kinetic strikes resumed. This pattern of cyber signaling preceding kinetic action is consistent with pre-positioned capabilities awaiting activation orders.More alarming than the historical IRGC pattern of declaratory signaling after kinetic events
Six Rockwell ICS advisories in a single batch. CISA published advisories ICSA-26-244-01 through ICSA-26-244-06 on 1 September, covering RSLinx Classic, ControlLogix 5580, CompactLogix, GuardLogix, FactoryTalk Activation Manager, and Historian ME — the exact ICS/OT products deployed across US water and energy infrastructure and the exact products Iranian actors have been probing.Target-rich environment in exactly the product families under Iranian targeting
PaperCut CVE-2026-81578 weaponized. A CVSS 9.8 improper access control vulnerability in PaperCut MF/NG, chainable with CVE-2026-82078 (CVSS 9.4) for unauthenticated remote code execution, was added to CISA's KEV catalog on 31 August. A public Metasploit module now makes exploitation trivial.Exploitation now accessible to any threat actor, including Iranian groups known to opportunistically adopt newly weaponized vulnerabilities
New Iranian espionage actor identified. Google Threat Intelligence disclosed UNC7033, a suspected Iranian espionage cluster active since 5 July 2026, using the ClickFix social engineering technique and multi-platform malware to target US think-tank and policy personnel.First use of ClickFix by an Iranian actor; multi-platform capability is also unusual for this threat actor community
Nimbus Manticore expanded its toolset. Check Point Research revealed that Nimbus Manticore (UNC1549, Smoke Sandstorm, Imperial Kitten) has deployed a new SSH tunneling utility and a C++ backdoor resembling the TWOSTROKE malware family, targeting organizations in the Middle East and Europe.Persistent, encrypted access channels that blend with legitimate administrative traffic
Key Iranian actor groups have gone operationally silent. MOIS-linked MuddyWater and Cavern Manticore have entered extended operational silence — a pattern historically preceding destructive operations. Separately, APT42's TAMECAT nuclear espionage campaign infrastructure was refreshed as recently as 2 September but is generating no visible collection indicators.Silence combined with infrastructure refresh suggests improved operational security ahead of anticipated activity

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026US initiates hostilities against Iran; cyber operations expected as asymmetric response.
Water campaign & UK power plant precedentLate Jul – Aug 2026FBI opens investigation into water system cyberattacks in 7+ US states; Iranian hackers disable a UK power plant for 4 days — demonstrated capability against Western energy infrastructure; CISA issues alert on AI-enhanced Iranian ICS/PLC exploitation (Aug 19).
Vulnerability weaponization & new actorAug 27–30, 2026UNC7033 last observed IOC activity (new Iranian espionage actor targeting US think tanks via ClickFix); Google Threat Intelligence publishes UNC7033 profile; Newsweek reports on Iran's "hidden weapon" against US infrastructure.
Declaratory threat & kinetic resumptionAug 31 – Sep 1, 2026"APT IRAN" Telegram threat against US energy, water, telecom — ~24 hours before kinetic resumption; CISA adds PaperCut CVE-2026-81578 to KEV with public Metasploit module; Check Point reveals Nimbus Manticore's expanded toolset; US strikes Iranian coastal positions around the Strait of Hormuz; Iran strikes US bases in Jordan, UAE, Kuwait, Bahrain, and Kurdistan; CISA publishes 6 Rockwell Automation ICS advisories.
Current (Day ~187) — economic pressure mountsSep 2, 2026CISA adds 7 new KEVs to the catalog; Iranian rial hits a record low of 2.20M/$1 — economic pressure increases likelihood of asymmetric cyber response.

The convergence of three factors makes Iranian attacks on US critical infrastructure the most probable and consequential cyber threat of this conflict: demonstrated capability — the four-day disruption of a British power plant was described by UK officials as a "warning shot," and the FBI investigation into water system attacks across 7+ US states (Minnesota alone reporting 30+ facilities) confirms sustained operational activity against municipal SCADA, particularly Unitronics PLCs; explicit intent — the "APT IRAN" Telegram declaration names energy, water, and telecommunications specifically, suggesting pre-selected target sets; and expanding vulnerability surface — six simultaneous Rockwell Automation ICS advisories (RSLinx Classic, ControlLogix 5580, CompactLogix, GuardLogix, FactoryTalk Activation Manager, Historian ME) cover products deployed across US water treatment, power generation, and manufacturing. The Historian ME advisory (ICSA-26-244-06) is particularly concerning — an out-of-bounds write vulnerability that could enable RCE.

Key actors: Cyber Av3ngers (IRGC-affiliated, responsible for previous Unitronics PLC attacks), SPECTRAL KITTEN (observed targeting Rockwell products in energy and industrial environments), and the broader IRGC Cyber-Electronic Command apparatus.

Notable absence: Cyber Av3ngers and the IOCONTROL malware family have gone silent despite the active FBI investigation into water system attacks — anomalous, and may indicate an operational security improvement, a rebrand, or a transition to more sophisticated tooling ahead of a larger operation.

T1190T0831T0826

UNC7033 represents a new dimension of Iranian cyber operations during this conflict: strategic intelligence collection on US policy positions. Active since 5 July 2026, this actor impersonates US think tanks and news outlets to deliver multi-platform malware (Windows and macOS) using the ClickFix social engineering technique — a first for Iranian actors. ClickFix tricks users into copying and pasting attacker-supplied commands into their terminal or PowerShell prompt, bypassing traditional email attachment detection.

The targeting of think-tank and policy personnel during an active military conflict is strategically significant. Successful compromise would give Iran insight into US negotiation positions, military strategy deliberations, and potential ceasefire terms.

T1204.001T1059.001T1059.006T1566.002

Nimbus Manticore (UNC1549, Smoke Sandstorm, Imperial Kitten) has expanded its toolset with a new SSH tunneling utility and a C++ backdoor resembling the TWOSTROKE malware family. This group targets organizations in the Middle East and Europe, with known focus on aviation, financial technology, and defense sectors. The SSH tunneling capability is significant because it enables persistent, encrypted access channels that blend with legitimate administrative traffic — making detection substantially harder in environments where SSH is routinely used for system management.

T1572T1071.001T1041

While not exclusively an Iranian threat, the PaperCut vulnerability chain (CVE-2026-81578, CVSS 9.8 + CVE-2026-82078, CVSS 9.4) deserves immediate attention. The chain enables unauthenticated remote code execution against PaperCut MF/NG print management servers. With a public Metasploit module available and CISA KEV listing confirmed, exploitation is now accessible to any threat actor — including Iranian groups known to opportunistically adopt newly weaponized vulnerabilities for initial access. PaperCut servers are widely deployed in government agencies, healthcare systems, universities, and enterprises. Previous PaperCut vulnerabilities (CVE-2023-27350) were rapidly adopted by both ransomware operators and state-sponsored actors.

T1190T1059T1078

Two MOIS-linked actor groups — MuddyWater and Cavern Manticore — have entered extended operational silence. Historically, periods of quiet from these groups have preceded destructive operations. Combined with the absence of Cyber Av3ngers reporting despite ongoing water system attacks, and the lack of any Iranian cyber activity against Gulf state allies (despite kinetic strikes on US bases in those countries), the pattern suggests pre-positioning rather than inactivity.

Similarly, APT42's CALANQUE ION / TAMECAT nuclear espionage campaign has produced no new technical indicators despite the nuclear issue being central to the conflict. The campaign infrastructure was refreshed as recently as 2 September, suggesting active operations that are simply not generating visible collection — a sign of improved operational security.

ScenarioProbabilityBasis
Iranian cyber operations against US critical infrastructure (water, energy, telecom)75%Explicit threat declaration issued ~24 hours before kinetic resumption, pre-positioned capabilities in water systems, FBI-confirmed ongoing attacks, UK power plant precedent
Iranian espionage campaign against US policy/think-tank community60%UNC7033 active since July, ClickFix technique deployed, strategic value of understanding US negotiation positions during active conflict
Destructive wiper deployment against Israeli or Gulf state targets25%Kinetic strikes on Gulf state bases but zero cyber activity against those targets — absence may indicate pre-positioning; MOIS-linked actors (MuddyWater, Cavern Manticore) in operational silence
Opportunistic exploitation of PaperCut CVE-2026-81578 by Iranian or Iranian-aligned actors55%Public Metasploit module, CISA KEV listing, Iranian history of adopting newly weaponized vulns for initial access (cf. previous PaperCut exploitation in 2023)
Exploitation of Rockwell ICS vulnerabilities (ICSA-26-244 series) in targeted attack40%Six advisories in exact product families under Iranian targeting, but no confirmed exploitation yet; vulnerability details may require time to weaponize

ICS/OT Network Traffic:

Anomalous connections to Rockwell ControlLogix, CompactLogix, and GuardLogix controllers from non-OT network segments Unitronics PCOM protocol traffic from unexpected sources — this is the protocol used in previous Cyber Av3ngers water system attacks Rockwell CIP (Common Industrial Protocol) commands from unauthorized IP addresses Any outbound connections from ICS/SCADA segments to internet-facing infrastructure

ClickFix Social Engineering Indicators:

PowerShell or bash commands executed from browser contexts (e.g., powershell.exe spawned by chrome.exe, msedge.exe, or firefox.exe) Clipboard-paste command execution patterns — users copying commands from web pages into terminals Domains impersonating US think tanks: watch for typosquats and lookalikes of Brookings Institution, CSIS, RAND Corporation, and Council on Foreign Relations

PaperCut Exploitation:

Unauthenticated access to PaperCut MF/NG admin interfaces Unexpected configuration changes on PaperCut servers (especially since 28 August) Class loading events or unusual Java process execution on PaperCut hosts

SSH Tunneling and Persistent Access:

New or unexpected SSH tunnels, particularly from servers that do not normally initiate SSH connections Long-duration SSH sessions to external IP addresses SSH connections from web-facing servers or DMZ hosts to internal infrastructure

Iranian Infrastructure Indicators:

Connections to mscertscript[.]info — known Iranian C2 domain Connections to company[.]claims or reliaquest[.]claims DNS queries for domains mimicking Microsoft certificate services or security update infrastructure

Detection Rules to Deploy:

Suricata/Snort: Rules for Unitronics PCOM protocol anomalies and Rockwell CIP unauthorized write commands EDR: Alert on powershell.exe or cmd.exe spawned by browser processes with clipboard-paste timing patterns SIEM: Correlation rule for PaperCut admin login from external IP + configuration change within 5 minutes Network: Alert on SSH tunnels with session duration >4 hours to external IPs from DMZ or OT-adjacent hosts DNS: Block and alert on mscertscript[.]info and monitor for certificate-services-themed domain registrations ---

ThreatATT&CK
ICS/OT Network TrafficT1190 T0831 T0826
ClickFix Social Engineering IndicatorsT1204.001 T1059.001 T1059.006 T1566.002
PaperCut ExploitationT1190 T1059 T1078
SSH Tunneling and Persistent AccessT1572 T1071.001 T1041
Iranian Infrastructure IndicatorsT1583.001
IOC Blocking Table:
mscertscript[.]infocompany[.]claimsreliaquest[.]claimshxxps://mscertscript[.]info/upgrade.phphxxp://mscertscript[.]info/upgrade.php

Block the above at perimeter firewalls, proxies, and DNS — the two URLs are Iranian C2 callback endpoints (HTTPS and HTTP variants). File hash indicators (SHA-256/MD5) associated with this reporting period are available via Anomali ThreatStream Next-Gen — do not rely on unverified hashes from third-party sources during this elevated threat period. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01
Hypothesis: Iranian actors have pre-positioned access in water/energy OT networks and a...
Hunt for dormant reverse shells, scheduled tasks with future execution dates, and newly created service accounts on ICS jump boxes and engineering workstations. Look for Unitronics PLC configuration changes that occurred in the past 30 days without corresponding change tickets.
HUNT 02
Hypothesis: UNC7033 ClickFix lures are targeting personnel with policy or government advisory roles.
Hunt in email logs and web proxy logs for visits to domains impersonating think tanks or policy organizations. Correlate with any subsequent PowerShell or Python execution on those users' endpoints. Check browser local storage for encrypted blobs that could be pre-staged payloads.
HUNT 03
Hypothesis: Nimbus Manticore SSH tunnels are active in environments with Middle East bu...
Hunt for SSH processes running on non-standard ports, SSH connections from application servers (not admin jump boxes), and SSH keys created in the past 60 days that don't correspond to known administrators.
HUNT 04
Hypothesis: PaperCut servers have already been compromised via CVE-2026-81578.
Audit all PaperCut MF/NG instances for configuration changes since 28 August. Check for new admin accounts, modified print policies, or unexpected outbound network connections from PaperCut hosts.

Financial Services
SWIFT Infrastructure, Middle East Operations
Primary threats
Nimbus Manticore (Imperial Kitten) has demonstrated sustained interest in financial technology targets. The expanded TWOSTROKE toolset with SSH tunneling capabilities poses a direct threat to financial institutions, especially those with Middle Eastern operations or correspondent banking relationships.
Actions
  • Audit all SSH keys and tunnels across trading platforms, payment processing systems, and SWIFT-connected infrastructure — revoke any keys not tied to a named administrator with an active access request
  • Review third-party connections to fintech partners in the Middle East and Europe for signs of lateral movement or anomalous data transfers
  • Deploy enhanced monitoring on SWIFT messaging interfaces
  • Conduct a tabletop exercise simulating an Iranian destructive attack on core banking systems, including wiper deployment via compromised SSH tunnels
Energy
Rockwell ICS, SCADA/PLC Systems
Primary threat
Energy is explicitly named in the Iranian threat declaration and is the sector with the most demonstrated Iranian capability — including the four-day UK power plant disruption.
Actions
  • Isolate all Rockwell Automation ICS devices (RSLinx Classic, ControlLogix, CompactLogix, GuardLogix, FactoryTalk, Historian ME) from corporate networks; verify no direct internet connectivity to any PLC or HMI
  • Apply patches for ICSA-26-244-01 through ICSA-26-244-06 on an emergency basis
  • Deploy network monitoring at the OT/IT boundary tuned for Rockwell CIP protocol anomalies and unauthorized write commands
  • Implement allowlisting for all engineering workstation communications to PLCs
Healthcare
Print Infrastructure, Patient Records
Primary threat
Healthcare organizations are high-value targets for both ransomware operators exploiting conflict chaos and state-sponsored actors seeking disruption. PaperCut MF/NG is widely deployed for print management of patient records and administrative documents.
Actions
  • Patch all PaperCut MF/NG instances for CVE-2026-81578 and CVE-2026-82078; audit PaperCut admin accounts for unauthorized additions since 28 August
  • If patching is not immediately possible, restrict PaperCut admin interface access to internal management VLANs only
  • Review all internet-facing services for healthcare-specific systems (EHR portals, telehealth platforms, medical device gateways) and verify they are not running vulnerable Rockwell or PaperCut components
  • Update incident response plans for scenarios involving Iranian-linked destructive attacks on healthcare IT
Government
Policy Staff, Think-Tank Partnerships
Primary threat
Government agencies face a dual threat: direct targeting of infrastructure and espionage operations aimed at policy personnel. UNC7033's ClickFix campaign specifically targets think-tank and policy advisory personnel — many of whom rotate between government service and private-sector advisory roles.
Actions
  • Issue a security awareness alert to all personnel with policy, diplomatic, or national security roles about ClickFix social engineering — warn against copying commands from web pages into terminals
  • Block execution of PowerShell and bash commands initiated from browser processes on endpoints assigned to policy staff
  • Audit email logs for the past 30 days for messages impersonating Brookings Institution, CSIS, RAND Corporation, Council on Foreign Relations, or similar organizations
  • Assess organizational exposure through think-tank partnerships, advisory board memberships, and staff with dual academic/government roles
Aviation / Logistics
SSH Infrastructure, Supply Chain
Primary threat
Nimbus Manticore (UNC1549) has documented targeting of aviation and defense logistics. The group's expanded SSH tunneling and TWOSTROKE-variant capabilities are designed for persistent access in complex enterprise environments typical of aviation supply chains.
Actions
  • Audit all SSH configurations on flight operations systems, cargo management platforms, and supply chain integration points; alert on any new SSH keys created in the past 60 days without corresponding change tickets
  • Review network segmentation between passenger-facing systems, flight operations, and cargo/logistics platforms
  • Deploy enhanced monitoring on any systems with connectivity to Middle Eastern or European aviation partners
  • Conduct a threat hunt specifically for TWOSTROKE indicators across aviation IT and OT environments
No sector cards match the selected filters.

Block all inbound connections to Rockwell RSLinx Classic, ControlLogix, CompactLogix, GuardLogix, FactoryTalk, and Historian ME from non-OT network segments. Apply patches for ICSA-26-244-01 through ICSA-26-244-06.
SOC Analyst
Apply PaperCut emergency patches for CVE-2026-81578 and CVE-2026-82078 on all PaperCut MF/NG instances. Verify no unauthorized admin configuration changes occurred since 28 August.
Incident Responder
Implement 72-hour enhanced monitoring for all water utility and energy sector SCADA/PLC connections. Deploy Suricata/Snort rules for Unitronics PCOM protocol anomalies and Rockwell CIP unauthorized commands.
SOC Analyst
Block mscertscript[.]info, company[.]claims, and reliaquest[.]claims at DNS, proxy, and firewall layers. Deploy all IOCs from the blocking table to EDR and SIEM watchlists.
SOC Analyst
Brief executive leadership on the Iranian explicit cyber threat declaration and the pattern of cyber signaling preceding kinetic resumption. Request authorization for elevated cyber defense posture through at least 12 September.
CISO / Exec
No immediate actions for the selected roles.
Deploy detection rules for ClickFix social engineering patterns — monitor for PowerShell/bash commands initiated from browser contexts, particularly from domains impersonating US think tanks.
SOC Analyst
Audit all VPN gateway appliances (Palo Alto GlobalProtect, Citrix NetScaler) for current patch levels — Iranian actors share exploitation techniques for VPN appliances with other state-sponsored groups.
Incident Responder
Brief partner organizations and sector ISACs on the Iranian threat declaration. Share IOCs and detection guidance at TLP:GREEN.
CISO / Exec
Update incident response playbooks with Iranian destructive attack scenarios, including wiper deployment, ICS manipulation, and combined kinetic-cyber events. Pre-position forensic tooling on OT network jump boxes.
Incident Responder
No 7-day actions for the selected roles.
Segment all Rockwell Automation ICS devices onto isolated OT VLANs with no direct internet connectivity. Implement jump-box architecture with MFA for all remote OT maintenance.
ICS / OT
Commission an assessment of organizational exposure to Iranian ClickFix and TWOSTROKE espionage campaigns — evaluate think-tank partnerships, policy advisory relationships, and staff with dual academic/government roles.
CISO / Exec
Conduct a tabletop exercise simulating a coordinated Iranian cyber-kinetic attack: simultaneous ICS disruption at a water or energy facility, wiper deployment on corporate IT, and hacktivist defacement for information operations cover.
CISO / ExecIncident Responder
Implement network-level allowlisting for all engineering workstation communications to PLCs and RTUs. Establish out-of-band communication procedures for OT operations.
ICS / OT
No 30-day actions for the selected roles.
The Bottom Line

The US-Iran conflict is now six months old. For most of that time, Iranian cyber operations have been probing, testing, and pre-positioning. The convergence we are seeing in early September — resumed kinetic strikes, an explicit cyber threat declaration that preceded kinetic action by approximately 24 hours, six new ICS vulnerabilities in targeted product families, a weaponized print management exploit, a new espionage actor collecting on US policy positions, and expanded persistent access tooling — is not coincidental. It is the operational picture of a state preparing to use its cyber capabilities as a strategic weapon. The fact that the "APT IRAN" cyber threat declaration came before kinetic strikes resumed — not after — is the most significant temporal signal in this reporting period. It suggests pre-positioned capabilities ready for activation on short notice, not new operations being planned from scratch. The silence from key actors — Cyber Av3ngers, MuddyWater, Cavern Manticore — is not reassuring. It is the most concerning signal of all. These groups go quiet before they act.

1
Patch the critical vulnerabilities. Isolate the ICS networks.
2
Deploy the detection rules. Brief your executives.
3
Test your incident response plans. The threat is explicit, the capability is demonstrated, and the clock is running.
No items found.