| Development | Significance |
|---|---|
| Kinetic escalation resumed. After a month-long pause, the US launched strikes against Iranian coastal positions around the Strait of Hormuz on 1–2 September. Iran responded with missiles targeting US bases in Jordan, the UAE, Kuwait, Bahrain, and Kurdistan. Iranian state media reported civilian casualties. The Iranian rial collapsed to a record low of 2.20 million to the dollar — a 10% drop in a single week. | Economic pressure increases the likelihood of an asymmetric cyber response |
| Explicit cyber threat declaration. The "APT IRAN" Telegram channel issued a direct threat against US energy, water, and telecommunications on 31 August — approximately 24 hours before kinetic strikes resumed. This pattern of cyber signaling preceding kinetic action is consistent with pre-positioned capabilities awaiting activation orders. | More alarming than the historical IRGC pattern of declaratory signaling after kinetic events |
| Six Rockwell ICS advisories in a single batch. CISA published advisories ICSA-26-244-01 through ICSA-26-244-06 on 1 September, covering RSLinx Classic, ControlLogix 5580, CompactLogix, GuardLogix, FactoryTalk Activation Manager, and Historian ME — the exact ICS/OT products deployed across US water and energy infrastructure and the exact products Iranian actors have been probing. | Target-rich environment in exactly the product families under Iranian targeting |
| PaperCut CVE-2026-81578 weaponized. A CVSS 9.8 improper access control vulnerability in PaperCut MF/NG, chainable with CVE-2026-82078 (CVSS 9.4) for unauthenticated remote code execution, was added to CISA's KEV catalog on 31 August. A public Metasploit module now makes exploitation trivial. | Exploitation now accessible to any threat actor, including Iranian groups known to opportunistically adopt newly weaponized vulnerabilities |
| New Iranian espionage actor identified. Google Threat Intelligence disclosed UNC7033, a suspected Iranian espionage cluster active since 5 July 2026, using the ClickFix social engineering technique and multi-platform malware to target US think-tank and policy personnel. | First use of ClickFix by an Iranian actor; multi-platform capability is also unusual for this threat actor community |
| Nimbus Manticore expanded its toolset. Check Point Research revealed that Nimbus Manticore (UNC1549, Smoke Sandstorm, Imperial Kitten) has deployed a new SSH tunneling utility and a C++ backdoor resembling the TWOSTROKE malware family, targeting organizations in the Middle East and Europe. | Persistent, encrypted access channels that blend with legitimate administrative traffic |
| Key Iranian actor groups have gone operationally silent. MOIS-linked MuddyWater and Cavern Manticore have entered extended operational silence — a pattern historically preceding destructive operations. Separately, APT42's TAMECAT nuclear espionage campaign infrastructure was refreshed as recently as 2 September but is generating no visible collection indicators. | Silence combined with infrastructure refresh suggests improved operational security ahead of anticipated activity |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | US initiates hostilities against Iran; cyber operations expected as asymmetric response. |
| Water campaign & UK power plant precedent | Late Jul – Aug 2026 | FBI opens investigation into water system cyberattacks in 7+ US states; Iranian hackers disable a UK power plant for 4 days — demonstrated capability against Western energy infrastructure; CISA issues alert on AI-enhanced Iranian ICS/PLC exploitation (Aug 19). |
| Vulnerability weaponization & new actor | Aug 27–30, 2026 | UNC7033 last observed IOC activity (new Iranian espionage actor targeting US think tanks via ClickFix); Google Threat Intelligence publishes UNC7033 profile; Newsweek reports on Iran's "hidden weapon" against US infrastructure. |
| Declaratory threat & kinetic resumption | Aug 31 – Sep 1, 2026 | "APT IRAN" Telegram threat against US energy, water, telecom — ~24 hours before kinetic resumption; CISA adds PaperCut CVE-2026-81578 to KEV with public Metasploit module; Check Point reveals Nimbus Manticore's expanded toolset; US strikes Iranian coastal positions around the Strait of Hormuz; Iran strikes US bases in Jordan, UAE, Kuwait, Bahrain, and Kurdistan; CISA publishes 6 Rockwell Automation ICS advisories. |
| Current (Day ~187) — economic pressure mounts | Sep 2, 2026 | CISA adds 7 new KEVs to the catalog; Iranian rial hits a record low of 2.20M/$1 — economic pressure increases likelihood of asymmetric cyber response. |
The convergence of three factors makes Iranian attacks on US critical infrastructure the most probable and consequential cyber threat of this conflict: demonstrated capability — the four-day disruption of a British power plant was described by UK officials as a "warning shot," and the FBI investigation into water system attacks across 7+ US states (Minnesota alone reporting 30+ facilities) confirms sustained operational activity against municipal SCADA, particularly Unitronics PLCs; explicit intent — the "APT IRAN" Telegram declaration names energy, water, and telecommunications specifically, suggesting pre-selected target sets; and expanding vulnerability surface — six simultaneous Rockwell Automation ICS advisories (RSLinx Classic, ControlLogix 5580, CompactLogix, GuardLogix, FactoryTalk Activation Manager, Historian ME) cover products deployed across US water treatment, power generation, and manufacturing. The Historian ME advisory (ICSA-26-244-06) is particularly concerning — an out-of-bounds write vulnerability that could enable RCE.
Key actors: Cyber Av3ngers (IRGC-affiliated, responsible for previous Unitronics PLC attacks), SPECTRAL KITTEN (observed targeting Rockwell products in energy and industrial environments), and the broader IRGC Cyber-Electronic Command apparatus.
Notable absence: Cyber Av3ngers and the IOCONTROL malware family have gone silent despite the active FBI investigation into water system attacks — anomalous, and may indicate an operational security improvement, a rebrand, or a transition to more sophisticated tooling ahead of a larger operation.
UNC7033 represents a new dimension of Iranian cyber operations during this conflict: strategic intelligence collection on US policy positions. Active since 5 July 2026, this actor impersonates US think tanks and news outlets to deliver multi-platform malware (Windows and macOS) using the ClickFix social engineering technique — a first for Iranian actors. ClickFix tricks users into copying and pasting attacker-supplied commands into their terminal or PowerShell prompt, bypassing traditional email attachment detection.
The targeting of think-tank and policy personnel during an active military conflict is strategically significant. Successful compromise would give Iran insight into US negotiation positions, military strategy deliberations, and potential ceasefire terms.
Nimbus Manticore (UNC1549, Smoke Sandstorm, Imperial Kitten) has expanded its toolset with a new SSH tunneling utility and a C++ backdoor resembling the TWOSTROKE malware family. This group targets organizations in the Middle East and Europe, with known focus on aviation, financial technology, and defense sectors. The SSH tunneling capability is significant because it enables persistent, encrypted access channels that blend with legitimate administrative traffic — making detection substantially harder in environments where SSH is routinely used for system management.
While not exclusively an Iranian threat, the PaperCut vulnerability chain (CVE-2026-81578, CVSS 9.8 + CVE-2026-82078, CVSS 9.4) deserves immediate attention. The chain enables unauthenticated remote code execution against PaperCut MF/NG print management servers. With a public Metasploit module available and CISA KEV listing confirmed, exploitation is now accessible to any threat actor — including Iranian groups known to opportunistically adopt newly weaponized vulnerabilities for initial access. PaperCut servers are widely deployed in government agencies, healthcare systems, universities, and enterprises. Previous PaperCut vulnerabilities (CVE-2023-27350) were rapidly adopted by both ransomware operators and state-sponsored actors.
Two MOIS-linked actor groups — MuddyWater and Cavern Manticore — have entered extended operational silence. Historically, periods of quiet from these groups have preceded destructive operations. Combined with the absence of Cyber Av3ngers reporting despite ongoing water system attacks, and the lack of any Iranian cyber activity against Gulf state allies (despite kinetic strikes on US bases in those countries), the pattern suggests pre-positioning rather than inactivity.
Similarly, APT42's CALANQUE ION / TAMECAT nuclear espionage campaign has produced no new technical indicators despite the nuclear issue being central to the conflict. The campaign infrastructure was refreshed as recently as 2 September, suggesting active operations that are simply not generating visible collection — a sign of improved operational security.
| Scenario | Probability | Basis |
|---|---|---|
| Iranian cyber operations against US critical infrastructure (water, energy, telecom) | 75% | Explicit threat declaration issued ~24 hours before kinetic resumption, pre-positioned capabilities in water systems, FBI-confirmed ongoing attacks, UK power plant precedent |
| Iranian espionage campaign against US policy/think-tank community | 60% | UNC7033 active since July, ClickFix technique deployed, strategic value of understanding US negotiation positions during active conflict |
| Destructive wiper deployment against Israeli or Gulf state targets | 25% | Kinetic strikes on Gulf state bases but zero cyber activity against those targets — absence may indicate pre-positioning; MOIS-linked actors (MuddyWater, Cavern Manticore) in operational silence |
| Opportunistic exploitation of PaperCut CVE-2026-81578 by Iranian or Iranian-aligned actors | 55% | Public Metasploit module, CISA KEV listing, Iranian history of adopting newly weaponized vulns for initial access (cf. previous PaperCut exploitation in 2023) |
| Exploitation of Rockwell ICS vulnerabilities (ICSA-26-244 series) in targeted attack | 40% | Six advisories in exact product families under Iranian targeting, but no confirmed exploitation yet; vulnerability details may require time to weaponize |
Anomalous connections to Rockwell ControlLogix, CompactLogix, and GuardLogix controllers from non-OT network segments Unitronics PCOM protocol traffic from unexpected sources — this is the protocol used in previous Cyber Av3ngers water system attacks Rockwell CIP (Common Industrial Protocol) commands from unauthorized IP addresses Any outbound connections from ICS/SCADA segments to internet-facing infrastructure
PowerShell or bash commands executed from browser contexts (e.g., powershell.exe spawned by chrome.exe, msedge.exe, or firefox.exe) Clipboard-paste command execution patterns — users copying commands from web pages into terminals Domains impersonating US think tanks: watch for typosquats and lookalikes of Brookings Institution, CSIS, RAND Corporation, and Council on Foreign Relations
Unauthenticated access to PaperCut MF/NG admin interfaces Unexpected configuration changes on PaperCut servers (especially since 28 August) Class loading events or unusual Java process execution on PaperCut hosts
New or unexpected SSH tunnels, particularly from servers that do not normally initiate SSH connections Long-duration SSH sessions to external IP addresses SSH connections from web-facing servers or DMZ hosts to internal infrastructure
Connections to mscertscript[.]info — known Iranian C2 domain Connections to company[.]claims or reliaquest[.]claims DNS queries for domains mimicking Microsoft certificate services or security update infrastructure
Suricata/Snort: Rules for Unitronics PCOM protocol anomalies and Rockwell CIP unauthorized write commands EDR: Alert on powershell.exe or cmd.exe spawned by browser processes with clipboard-paste timing patterns SIEM: Correlation rule for PaperCut admin login from external IP + configuration change within 5 minutes Network: Alert on SSH tunnels with session duration >4 hours to external IPs from DMZ or OT-adjacent hosts DNS: Block and alert on mscertscript[.]info and monitor for certificate-services-themed domain registrations ---
| Threat | ATT&CK |
|---|---|
| ICS/OT Network Traffic | T1190 T0831 T0826 |
| ClickFix Social Engineering Indicators | T1204.001 T1059.001 T1059.006 T1566.002 |
| PaperCut Exploitation | T1190 T1059 T1078 |
| SSH Tunneling and Persistent Access | T1572 T1071.001 T1041 |
| Iranian Infrastructure Indicators | T1583.001 |
Block the above at perimeter firewalls, proxies, and DNS — the two URLs are Iranian C2 callback endpoints (HTTPS and HTTP variants). File hash indicators (SHA-256/MD5) associated with this reporting period are available via Anomali ThreatStream Next-Gen — do not rely on unverified hashes from third-party sources during this elevated threat period. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Audit all SSH keys and tunnels across trading platforms, payment processing systems, and SWIFT-connected infrastructure — revoke any keys not tied to a named administrator with an active access request
- Review third-party connections to fintech partners in the Middle East and Europe for signs of lateral movement or anomalous data transfers
- Deploy enhanced monitoring on SWIFT messaging interfaces
- Conduct a tabletop exercise simulating an Iranian destructive attack on core banking systems, including wiper deployment via compromised SSH tunnels
- Isolate all Rockwell Automation ICS devices (RSLinx Classic, ControlLogix, CompactLogix, GuardLogix, FactoryTalk, Historian ME) from corporate networks; verify no direct internet connectivity to any PLC or HMI
- Apply patches for ICSA-26-244-01 through ICSA-26-244-06 on an emergency basis
- Deploy network monitoring at the OT/IT boundary tuned for Rockwell CIP protocol anomalies and unauthorized write commands
- Implement allowlisting for all engineering workstation communications to PLCs
- Patch all PaperCut MF/NG instances for CVE-2026-81578 and CVE-2026-82078; audit PaperCut admin accounts for unauthorized additions since 28 August
- If patching is not immediately possible, restrict PaperCut admin interface access to internal management VLANs only
- Review all internet-facing services for healthcare-specific systems (EHR portals, telehealth platforms, medical device gateways) and verify they are not running vulnerable Rockwell or PaperCut components
- Update incident response plans for scenarios involving Iranian-linked destructive attacks on healthcare IT
- Issue a security awareness alert to all personnel with policy, diplomatic, or national security roles about ClickFix social engineering — warn against copying commands from web pages into terminals
- Block execution of PowerShell and bash commands initiated from browser processes on endpoints assigned to policy staff
- Audit email logs for the past 30 days for messages impersonating Brookings Institution, CSIS, RAND Corporation, Council on Foreign Relations, or similar organizations
- Assess organizational exposure through think-tank partnerships, advisory board memberships, and staff with dual academic/government roles
- Audit all SSH configurations on flight operations systems, cargo management platforms, and supply chain integration points; alert on any new SSH keys created in the past 60 days without corresponding change tickets
- Review network segmentation between passenger-facing systems, flight operations, and cargo/logistics platforms
- Deploy enhanced monitoring on any systems with connectivity to Middle Eastern or European aviation partners
- Conduct a threat hunt specifically for TWOSTROKE indicators across aviation IT and OT environments
mscertscript[.]info, company[.]claims, and reliaquest[.]claims at DNS, proxy, and firewall layers. Deploy all IOCs from the blocking table to EDR and SIEM watchlists.The US-Iran conflict is now six months old. For most of that time, Iranian cyber operations have been probing, testing, and pre-positioning. The convergence we are seeing in early September — resumed kinetic strikes, an explicit cyber threat declaration that preceded kinetic action by approximately 24 hours, six new ICS vulnerabilities in targeted product families, a weaponized print management exploit, a new espionage actor collecting on US policy positions, and expanded persistent access tooling — is not coincidental. It is the operational picture of a state preparing to use its cyber capabilities as a strategic weapon. The fact that the "APT IRAN" cyber threat declaration came before kinetic strikes resumed — not after — is the most significant temporal signal in this reporting period. It suggests pre-positioned capabilities ready for activation on short notice, not new operations being planned from scratch. The silence from key actors — Cyber Av3ngers, MuddyWater, Cavern Manticore — is not reassuring. It is the most concerning signal of all. These groups go quiet before they act.