| Development | Significance |
|---|---|
| CVE-2026-20316 added to CISA KEV (Cisco Secure FMC static credentials) | Unauthenticated access to firewall management — Pioneer Kitten historically weaponizes Cisco vulns within days |
| 5 Iranian espionage campaigns refreshed in 48 hours | APT42, PULSAR KITTEN, and unnamed MOIS groups running concurrent operations across 17+ countries |
| ASN 213790 infrastructure expansion — new C2 nodes activated | Tehran-based hosting cluster now shows APT C2, Cactus ransomware, and anomalous APT28-tagged activity |
| 7 ICS/OT advisories including Siemens S7-1500 GNU/Linux subsystem vulns | Directly relevant to Cyber Av3ngers' known targeting of Siemens PLCs |
| TWOSTROKE malware campaign expanding to Azerbaijan and Turkey | Geographic expansion of Iranian espionage beyond the immediate Israel theater |
| Cavern Manticore "Operation Epic Fury" confirmed destructive campaign against Israeli government/IT | Active wiper deployment; pre-stage destructive attack response playbooks immediately |
| Pro-Iran hacktivist silence extends beyond 9 days | Historical precursor to escalation toward destructive operations |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Escalation begins | 2026-02-28 | Iran-Israel conflict begins; cyber operations commence in parallel |
| Hacktivist silence begins | Jul 21 | Last observed activity from pro-Iran hacktivist groups (Handala, Cyber Toufan) — silence persists to present |
| KEV surge & targeting confirmation | Jul 27 | Three critical CVEs added to CISA KEV; PULSAR KITTEN confirmed targeting aerospace, defense, and transportation |
| Destructive capability & OT expansion | Jul 28 | Cavern Manticore (MOIS) "Operation Epic Fury" confirmed as a destructive campaign against Israeli government/IT; 7 ICS advisories published |
| Current — infrastructure validation | Jul 29, 2026 | Four Cobalt Strike/Sliver C2 nodes refreshed on Iranian ASNs; CVE-2026-20316 (Cisco FMC) added to KEV; 5 espionage campaigns updated; PULSAR KITTEN spear-phishing against transportation/telecom; TWOSTROKE campaign confirmed expanding to the Caucasus |
CISA added CVE-2026-20316 to the KEV catalog on July 29. Cisco Secure Firewall Management Center contains static low-privileged credentials that allow unauthenticated remote login. While rated CVSS 5.3 (Medium), Cisco elevated the Security Impact Rating to HIGH due to privilege escalation chaining potential with other FMC vulnerabilities.
Why this matters: FMC is the central management plane for Cisco firewall infrastructure. Compromise means attackers can modify firewall policies, disable logging, and blind defenders — all without triggering standard authentication alerts. Pioneer Kitten (IRGC-affiliated, also tracked as UNC757) has a documented pattern of rapidly weaponizing Cisco, Fortinet, and Ivanti vulnerabilities. Expect scanning within 7 days.
Two high-confidence (97%) APT command-and-control IPs on ASN 213790 ("Limited Network," Tehran) were refreshed on July 29, joining previously tracked infrastructure on the same autonomous system. This ASN now hosts active APT C2 nodes, Cactus ransomware infrastructure, LockBit-tagged infrastructure targeting financial services and government, and anomalous APT28 (Russian GRU) tagging on Tehran-geolocated IPs.
The APT28 tagging on Iranian infrastructure is a significant analytical finding — it suggests either automated classifier misattribution, shared hosting between Russian and Iranian actors, or deliberate false-flag tradecraft. The convergence of Russian and Iranian indicators on the same infrastructure warrants dedicated monitoring.
PULSAR KITTEN (IRGC-affiliated, active since 2023) received a profile update confirming active spear-phishing campaigns against a German branch of a U.S. transportation company, with infrastructure overlap to Iraqi telecom targeting. The actor deploys SilkySand and SurveyAgent malware and has demonstrated capability against aerospace, defense, telecom, transportation, and energy sectors across the US, UK, UAE, Israel, Turkey, Pakistan, and Thailand.
Exploited vulnerabilities: CVE-2021-44228 (Log4Shell), CVE-2021-26084 (Confluence), CVE-2021-34473 (ProxyShell), CVE-2022-47966 (ManageEngine), CVE-2018-13379 (FortiGate), CVE-2022-26134 (Confluence), CVE-2022-0847 (Dirty Pipe).
APT42 (IRGC Intelligence Organization) is confirmed running at least two concurrent campaign tracks: BELLACIAO/SHELLAFEL — targeting chemical, energy, government, healthcare, and manufacturing sectors — and TAMECAT — targeting defense and aerospace. This dual-track approach indicates significant operational capacity and suggests APT42 has compartmentalized teams running independent missions simultaneously.
Seven ICS advisories published July 28 include critical vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP — specifically in the GNU/Linux subsystem. This introduces IT-style attack vectors (Linux exploitation) into OT controllers. Cyber Av3ngers (UNC5203, IRGC-affiliated) have historically targeted Siemens PLCs in water treatment and energy infrastructure — the new Linux subsystem vulnerabilities provide exactly the kind of IT-OT convergence attack surface this group exploits.
Additional advisories cover MikroTik RouterOS brute-force vulnerabilities, Siemens Desigo CC (building automation), and Siemens S7-PLCSIM Advanced (denial of service).
Handala, Cyber Toufan, and BANISHED KITTEN (Cotton Sandstorm, IRGC-affiliated) have maintained anomalous silence since approximately July 21 — now exceeding 9 days. Historical pattern analysis shows that extended hacktivist silence has preceded escalation to destructive operations (wipers, large-scale data leaks) timed to geopolitical trigger events. This silence should not be interpreted as reduced threat — it should be treated as a warning indicator.
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Pioneer Kitten scanning for CVE-2026-20316 (Cisco FMC) | 75% | 7 days | Historical pattern of rapid Cisco/Fortinet/Ivanti exploitation |
| Cyber Av3ngers incorporating S7-1500 Linux subsystem vulns into toolkit | 50% | 30 days | Group's established focus on Siemens PLCs + new attack surface |
| PULSAR KITTEN expanding spear-phishing to aerospace/defense targets | 45% | 14 days | Actor profile explicitly includes these sectors; transportation campaign is active |
| Coordinated hacktivist wiper/IO operation following silence period | 35% | 7–14 days | Historical precedent; extended silence as escalation precursor |
| Russia-Iran shared infrastructure confirmed (ASN 213790) | 30% | 30 days | Anomalous APT28 tagging on Tehran IPs; requires further collection |
Hunt hypothesis: Threat actors are authenticating to FMC instances using static/default credentials from untrusted source IPs. Detection: Monitor FMC authentication logs for logins from non-administrative source IPs; alert on any successful authentication using built-in low-privilege accounts. Action: If FMC is internet-exposed, treat as compromised until verified.
Hunt hypothesis: Compromised internal hosts are beaconing to Iranian C2 infrastructure. Detection: Create network detection rules for any inbound or outbound traffic to ASN 213790 ("Limited Network") and ASN 215930 ("Cipher Operations Beograd") — both geolocated Tehran. Action: Any hit should trigger immediate host isolation and forensic triage.
Hunt hypothesis: Employees in transportation, telecom, or aerospace roles are receiving targeted phishing with SilkySand/SurveyAgent payloads. Detection: Monitor for AnyDesk installations not provisioned by IT (T1219); hunt for unknown executables making outbound connections to cloud email APIs (T1041). Action: Review email gateway logs for attachments from unknown senders targeting transportation/aerospace business units.
Hunt hypothesis: Threat actors are scanning for exposed S7-1500 controllers or brute-forcing MikroTik routers in OT segments. Detection: Monitor for Modbus/S7comm scanning from IT network segments toward OT; alert on MikroTik authentication failure spikes (T1110). Action: Verify OT network segmentation; confirm no S7-1500 or MikroTik devices are reachable from the internet.
Hunt hypothesis: Compromised partner/vendor accounts are being used to send phishing to internal users. Detection: Monitor for emails from known partner domains with unusual attachment types or links to credential harvesting pages (T1199). Action: Implement partner email domain anomaly detection; verify MFA on all federated trust relationships.
| Threat | ATT&CK |
|---|---|
| 1. Cisco FMC Static Credential Exploitation (CVE-2026-20316) | T1078.001 T1552.001 |
| 2. ASN 213790 / ASN 215930 Communications | T1071 T1571 |
| 3. PULSAR KITTEN Spear-Phishing Indicators | T1219 T1041 T1566.001 T1059 |
| 4. Siemens S7-1500 / MikroTik OT Reconnaissance | T1110 T1595 T0831 |
| 5. APT42 Trusted Relationship Abuse | T1199 T1566.001 |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Block ASN 213790 and ASN 215930 at perimeter; review ransomware playbooks
- Verify offline backup integrity; monitor for data exfiltration preceding encryption (double-extortion pattern)
- Audit all Siemens S7-1500 firmware versions (V3.1.6 is vulnerable); implement CISA CI Fortify isolation guidance for vital OT systems
- Segment SCADA from corporate IT; deploy OT-specific anomaly detection
- Review webshell detection capabilities — BELLACIAO is a .NET webshell; audit internet-facing web applications for unauthorized file uploads
- Monitor for anomalous IIS/Apache worker processes spawning cmd.exe or PowerShell
- Activate destructive attack playbooks; verify system recovery capabilities
- Implement enhanced monitoring for lateral movement and credential harvesting; brief staff on spear-phishing from trusted-relationship abuse
- Brief international subsidiary security teams on PULSAR KITTEN TTPs; monitor for AnyDesk installations
- Hunt for SilkySand/SurveyAgent malware indicators; review email security for subsidiary-to-HQ communication paths
77.90.185[.]28 and 77.90.185[.]248 at perimeter firewall — active APT C2 infrastructure, confidence 97%.62.60.130[.]237 — Cactus ransomware infrastructure on Iranian hosting.185.93.89[.]75 — LockBit-tagged infrastructure targeting financial services/government.Five months into this conflict, Iranian cyber operations are not winding down — they are diversifying and accelerating. Two distinct intelligence organizations (MOIS and IRGC) are running parallel campaigns across espionage, destructive operations, ransomware crossover, and ICS targeting. The convergence of a new Cisco FMC vulnerability with Pioneer Kitten's known exploitation patterns creates an immediate window of risk. The sustained hacktivist silence is not peace — it is preparation.