TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Didn't Pause —

It Reloaded

HIGH. The six-day silence since Iran's last confirmed cyberattack on U.S. water infrastructure isn't a ceasefire — it's a reload. Now 163 days into the active U.S.-Iran conflict, CyberAv3ngers have confirmed compromise of 30+ U.S. water facilities across six states, IRGC-linked operators have refreshed Cobalt Strike/Remcos command infrastructure, and three critical vulnerabilities (CVSS 9.6–10.0) have entered active exploitation. Washington's "semi-negotiating" posture with Tehran provides no de-escalation signal — historically, Iranian cyber operations increase during negotiations as leverage.

I am a
My sector

DevelopmentWhy It Matters
CyberAv3ngers confirm 30+ U.S. water facility compromises (Jul 26–Aug 4)IRGC-affiliated operators executed confirmed PLC manipulation across 6 states; 36 Minnesota utilities hit — largest ICS/OT destructive campaign of the conflict to date
Void Manticore (Handala) silent for 152 daysMOIS-affiliated destructive group last active Mar 11; extended absence assessed as infrastructure rebuild or access stockpiling ahead of coordinated strike
APT42 BELLACIAO/SHELLAFEL web shell campaigns (Aug 1–3)IRGC-IO credential harvesting and web shell deployment across 8 verticals — government, think tanks, and media directly targeted
Agentemis-tagged Cobalt Strike C2 infrastructure refreshed (Aug 6–10)IRGC-linked operators are actively maintaining — not abandoning — pre-positioned access
CVE-2026-8037 (Progress LoadMaster, CVSS 9.6) added to CISA KEV792 exploitation attempts from 65 IPs across 18 countries in 41 days; unauthenticated RCE
CVE-2026-16812 (Arista VeloCloud Orchestrator, CVSS 10.0) actively exploitedSD-WAN orchestrator compromise = full network control
Sandworm private APN→PLC destruction playbook published by CERT.PLDemonstrates cellular-router pivot that bypasses IT/OT segmentation — directly transferable to Iranian ICS operators
Shared malware hash links two Iranian C2 clustersEvidence of unified IRGC operator running both Cobalt Strike (lateral movement) and Remcos RAT (surveillance) from converged infrastructure
U.S.-Iran "semi-negotiating" status confirmed (Aug 10)Historical pattern: Iranian cyber operations increase during negotiations as leverage tools — no de-escalation signal

PhaseTimeframeCyber Activity
Conflict initiationFeb 28, 2026U.S.-Iran kinetic conflict begins.
Stryker wiper operationMar 11, 2026Void Manticore/Handala (MOIS-affiliated) executes the Stryker wiper operation — the last confirmed destructive op; the group has been silent since.
Water infrastructure campaignJul 26 – Aug 4, 2026CyberAv3ngers (IRGC-affiliated) compromise 30+ U.S. water treatment facilities across 6 states, including 36 Minnesota utilities, via PLC manipulation; Iran restarts hostilities Jul 29 after a brief U.S. pause in firing.
Espionage & infrastructure refreshAug 1–10, 2026APT42 BELLACIAO/SHELLAFEL web shell campaigns hit 8 verticals (Aug 1–3); Agentemis Cobalt Strike C2 refreshed on Iranian ASNs (Aug 6–10); CVE-2026-8037 added to CISA KEV (Aug 7).
Current (Day 163)Aug 10, 2026U.S. confirms "semi-negotiating" status with Tehran; Israel rejects 15-point Gaza plan. No de-escalation signal — cyber ops expected to continue.

The IRGC-affiliated CyberAv3ngers confirmed compromise of 30+ water treatment facilities across six U.S. states between July 26 and August 4, with 36 Minnesota utilities specifically targeted via PLC manipulation. The group exploited Unitronics PLCs — the same vector used in their 2023 Aliquippa, PA attack, now scaled dramatically.

The six-day pause since August 4 should not be interpreted as cessation. Three scenarios explain the silence: (a) operational repositioning to a new sector, (b) attacks occurring but not yet publicly reported, or (c) access stockpiling for a coordinated strike timed to diplomatic breakdown.

Two high-confidence Cobalt Strike BEACON C2 servers geolocated in Iran remain active, both tagged "Agentemis" — a label associated with IRGC pre-positioning operations: 217.60.241[.]17 (ASN 51396, Pfcloud UG) on port 443, confidence 98%; and 87.107.191[.]39 (ASN 44436, Toosee Ertebatat Damavand) on port 53 (DNS tunneling), confidence 88%.

A critical discovery this cycle: hash 6bb3c19f1ed89ba8150785d5804b641b80d04d60fa5ed3f589d98621ffe4b23b appears in both the Agentemis Cobalt Strike configuration AND a Remcos RAT C2 node at 172.94.9[.]74 (ASN 213790, port 8279). This convergence indicates a single operator maintaining dual-tool capability — Remcos for persistent surveillance, Cobalt Strike for lateral movement and pre-positioning.

Translation for CISOs: an IRGC-linked operator is actively maintaining command infrastructure that can both watch your network silently (Remcos) and move laterally when given the order (Cobalt Strike). The infrastructure refresh during active diplomatic talks means they are keeping options open.

T1071.001T1071.004T1219

Three vulnerabilities demand immediate executive attention: CVE-2026-8037 (Progress LoadMaster, CVSS 9.6) — CISA KEV as of Aug 7, 792 exploitation attempts, unauthenticated command injection; CVE-2026-16812 (Arista VeloCloud Orchestrator, CVSS 10.0) — actively exploited, SD-WAN orchestrator compromise means full network control; CVE-2026-9198 (Langflow AI platform, CVSS 9.8) — on CISA KEV, an AI/ML infrastructure exploitation vector.

Historical pattern: Pioneer Kitten/Fox Kitten (IRGC contractor) consistently exploits new network appliance KEVs within 7–14 days of publication. The clock started August 7.

T1190

CERT.PL disclosed a Sandworm attack on Polish energy infrastructure using a novel kill chain: Fortinet VPN → Teltonika cellular router → private APN → Wago PLC → Siemens PLCs. The objective was purely destructive — steam turbine and water treatment shutdown.

This matters for Iran-focused defenders because CyberAv3ngers have demonstrated PLC targeting capability, Pioneer Kitten has demonstrated Fortinet VPN exploitation capability, cellular-connected devices in OT environments create "shadow bridges" invisible to network monitoring, and the private APN pivot bypasses every traditional IT/OT segmentation architecture.

MOIS-affiliated Void Manticore (operating as "Handala") has been silent since the Stryker wiper operation on March 11 — 152 days. This extended absence from a previously highly active destructive group is assessed as one of three possibilities: infrastructure rebuild after operational exposure; activity below current collection thresholds (Telegram, private channels); or access stockpiling for a coordinated destructive strike timed to diplomatic failure.

The third scenario is the most dangerous and aligns with MOIS operational doctrine of patient pre-positioning followed by synchronized destruction.

ScenarioProbabilityTimeframeTrigger
Pioneer Kitten exploits CVE-2026-8037 (LoadMaster) or CVE-2026-16812 (VeloCloud) for initial access70%7–14 daysKEV publication + historical pattern
Coordinated Iranian cyber retaliation against energy or financial sector if "semi-negotiations" collapse60%48–72 hours post-collapseDiplomatic breakdown
Handala/Void Manticore resurfaces with destructive wiper against Israeli target50%2–4 weeksDiplomatic failure or Israeli military escalation
Agentemis C2 refresh indicates imminent activation of pre-positioned DIB network access40%7–21 daysConflict escalation or intelligence tasking
Iranian adoption of Sandworm-style private APN→PLC pivot against U.S. energy infrastructure35%30–90 daysTTP transfer and capability development

ATT&CK TechniqueWhat to HuntDetection Logic
T1071.001 (C2 via HTTPS)Cobalt Strike BEACON to 217.60.241[.]17:443Alert on any outbound HTTPS to this IP; check proxy logs for malleable C2 profiles
T1071.004 (C2 via DNS)DNS tunneling to 87.107.191[.]39:53Monitor for high-entropy DNS queries, abnormal TXT record volumes, or direct DNS to non-corporate resolvers
T1219 (Remote Access Software)Remcos RAT beaconing to 172.94.9[.]74:8279Alert on outbound connections to port 8279; inspect for Remcos handshake patterns
T1190 (Exploit Public-Facing Application)LoadMaster API exploitation (CVE-2026-8037)WAF rules for command injection in LoadMaster management API; monitor for unexpected process spawning on LoadMaster appliances
T1588.002 (Obtain Capabilities: Tool)Cobalt Strike loader deploymentYARA rules for Cobalt Strike stager; monitor for rundll32/regsvr32 loading unsigned DLLs
T1056.001 (Keylogging)Remcos keylogger module activationEDR alerts for API hooking (SetWindowsHookEx); unusual clipboard access patterns
IOC Blocking Table:
217.60.241[.]1787.107.191[.]39172.94.9[.]74192.42.116[.]58192.42.116[.]105146.70.139[.]154

Block the above at perimeter firewalls, proxies, and DNS. Hashes: 6bb3c19f1ed89ba8150785d5804b641b80d04d60fa5ed3f589d98621ffe4b23b. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1071.001
Is Agentemis already inside?
Search 90 days of DNS logs for queries to ASN 44436 (Toosee Ertebatat Damavand) or ASN 51396 (Pfcloud UG). Any hit warrants immediate IR escalation.
HUNT 02
Shadow cellular bridges
Inventory all cellular-connected devices on corporate/OT networks. Any Teltonika router, industrial cellular gateway, or IoT device with a SIM card that bridges to internal networks is a potential Sandworm-style pivot point.
HUNT 03 · T1190
LoadMaster exposure
Query asset inventory for Progress LoadMaster instances. Cross-reference with external attack surface scan. Any internet-facing, unpatched instance is a confirmed exploitation target (792 attempts already observed).
HUNT 04 · T1219
Remcos on academic infrastructure
Monitor for connections to ASN 213790 ("Limited Network"). This ASN hosts repurposed Iranian academic infrastructure used for C2.

Financial Services
Banking, Payment Processing
Primary threat
Coordinated Iranian retaliation against financial infrastructure if diplomacy collapses (60% probability). Iranian actors have historically targeted SWIFT-connected systems and payment processors during escalation phases.
Secondary threat
AiTM session hijacking targeting payroll and treasury functions — Payroll Pirates TTP overlaps with Iranian device-code phishing.
Actions
  • Verify SD-WAN orchestrator patching (CVE-2026-16812) — VeloCloud is widely deployed in branch banking architectures
  • Review all third-party LoadMaster deployments in payment processing chains; confirm vendor patching status
  • Conduct tabletop exercise for simultaneous DDoS + destructive wiper scenario against core banking systems
Energy
Grid PLCs, OT Networks
Primary threat
ICS/OT destruction via PLC manipulation — directly demonstrated by CyberAv3ngers against water utilities and now templated by Sandworm's private APN pivot against energy PLCs.
Secondary threat
Wago and Siemens PLC firmware integrity; unexpected PLC mode changes (run → stop).
Actions
  • Inventory all cellular-connected devices in OT environments (Teltonika routers, industrial gateways, EV chargers); verify SIM provenance
  • Implement detection for the VPN → cellular router → private APN lateral movement pattern; audit Fortinet VPN configurations for known exploitation vectors
  • Commission assessment of private APN exposure across all generation and transmission facilities; identify shadow cellular bridges
Healthcare
EHR, Telehealth Infrastructure
Primary threats
Ransomware operators — including Iranian-affiliated Pioneer Kitten, known to sell access to ransomware gangs — exploiting network appliance vulnerabilities for initial access to hospital networks.
Secondary threat
Pioneer Kitten initial access broker activity; any credential sale matching healthcare organization domains.
Actions
  • Patch Progress LoadMaster (CVE-2026-8037) in any healthcare load-balancing deployment; these are common in EHR and telehealth architectures
  • Audit Langflow/AI platform deployments (CVE-2026-9198) — increasingly common in clinical decision support systems
  • Verify that medical IoT devices with cellular connectivity (patient monitors, infusion pumps with SIM cards) are segmented from clinical networks
Government
Policy, Diplomacy-Adjacent Agencies
Primary threats
APT42 credential harvesting and web shell deployment targeting policy organizations, think tanks, and government agencies involved in Iran diplomacy.
Secondary threat
Agentemis C2 beaconing from any .gov or .mil network; DNS tunneling to Iranian ASNs.
Actions
  • Hunt for BELLACIAO/SHELLAFEL web shells on internet-facing Exchange and SharePoint servers; review IIS logs for anomalous .aspx file creation
  • Enforce phishing-resistant MFA (FIDO2) for all personnel involved in Iran policy — APT42 specifically targets this community with device-code phishing
  • Conduct purple team exercise simulating APT42 TTP chain: spearphish → device-code phishing → M365 session hijack → lateral movement
Aviation / Logistics
DIB Contractors, CI/CD Pipelines
Primary threat
Pre-positioned access activation in defense industrial base networks; SD-WAN compromise enabling supply chain disruption.
Secondary threat
Pioneer Kitten exploitation of network appliances for initial access to aerospace/defense contractors.
Actions
  • Patch Arista VeloCloud Orchestrator (CVE-2026-16812, CVSS 10.0) — SD-WAN is foundational to logistics network architecture
  • Review all JetBrains TeamCity instances (CVE-2026-63077, CVSS 9.8) in CI/CD pipelines for defense software development
  • Conduct threat hunt specifically for Remcos RAT and Cobalt Strike beaconing from DIB network segments; focus on ASN 213790 and ASN 51396 connections

Block Agentemis C2 IPs (217.60.241[.]17, 87.107.191[.]39) and Remcos C2 (172.94.9[.]74) at perimeter firewall with 90-day TTL.
SOC Analyst
Verify all Progress LoadMaster instances are patched against CVE-2026-8037 (CISA deadline: Aug 10); isolate any unpatched instances from the internet immediately.
Incident Responder
Add ASN 213790 ("Limited Network") to enhanced monitoring — any outbound connection triggers a P2 alert and analyst review.
SOC Analyst
Deploy hash 6bb3c19f1ed89ba8150785d5804b641b80d04d60fa5ed3f589d98621ffe4b23b to the EDR blocklist across all endpoints.
SOC Analyst
Confirm the incident response retainer is active and the IR team is briefed on the Iranian destructive playbook (wiper + PLC manipulation).
CISO / Exec
No immediate actions for the selected roles.
Audit and patch all Arista VeloCloud Orchestrator instances against CVE-2026-16812 (CVSS 10.0); isolate if a patch is unavailable.
Incident Responder
Implement detection for private APN lateral movement: Fortinet VPN → cellular router admin → SSH tunnel to non-routable OT networks.
SOC Analyst
Inventory all cellular-connected IoT/OT devices; verify SIM card provenance; disable unnecessary proactive SIM features.
ICS / OT
Deploy JetBrains TeamCity detection for CVE-2026-63077 exploitation; monitor for unauthorized project creation or build modification.
SOC Analyst
Update IR playbooks to include the cellular/APN pivot scenario; ensure OT incident response covers PLC firmware verification.
Incident Responder
No 7-day actions for the selected roles.
Commission an assessment of private APN exposure — identify all cellular routers bridging corporate/OT networks to mobile carrier APNs.
CISO / Exec
Conduct a tabletop exercise: simultaneous Iranian wiper deployment + ICS/OT PLC manipulation + DDoS against public-facing services.
CISO / ExecIncident Responder
Expand threat intelligence collection to cover Farsi-language Telegram channels for Handala/Void Manticore/Cyber Toufan early warning.
SOC Analyst
Implement network-level SIM card anomaly detection for IoT/OT devices — monitor for unexpected AT command execution or network downgrade (4G→2G).
ICS / OT
Brief the board on Iranian cyber conflict posture; ensure cyber insurance coverage explicitly includes state-sponsored destructive attacks.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The U.S.-Iran conflict is 163 days old. Iranian cyber operators have demonstrated they will attack American critical infrastructure — not theoretically, but confirmed across 30+ water facilities in six states. The diplomatic status of "semi-negotiating" provides zero de-escalation assurance; historically, Iranian cyber operations intensify during negotiations as leverage tools. This week's intelligence tells a clear story: infrastructure is being refreshed, not abandoned. New exploitation vectors (CVSS 9.6–10.0) are entering active use, and a newly published attack technique — the private APN pivot — shows how adversaries can reach your PLCs through paths your network monitoring cannot see. The question is not whether Iranian operators will strike again. It's whether your organization will detect the pre-positioning before the order comes.

1
Is your Progress LoadMaster patched against CVE-2026-8037? 792 exploitation attempts have already been logged — assume compromise if not.
2
Do you have shadow cellular bridges in your OT environment? The Sandworm private-APN pivot bypasses every IT/OT segmentation control you've built.
3
Maintain elevated defensive posture. No stand-down until a confirmed ceasefire includes cyber-specific provisions — Void Manticore's 152-day silence is preparation, not absence.
No items found.