TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Hits Sustained High Tempo:

What CISOs Must Know Now

HIGH. Five months into the Iran-Israel conflict, Iranian cyber operations are diversifying and accelerating rather than winding down. A new Cisco Secure FMC vulnerability (CVE-2026-20316) creates an immediate exploitation window matching Pioneer Kitten's known rapid-weaponization pattern, while five distinct Iranian espionage campaigns refreshed within 48 hours and ASN 213790 has become a signature infrastructure cluster hosting APT C2, Cactus ransomware, and anomalous Russian GRU-tagged activity side by side. Pro-Iran hacktivist groups have now been silent for more than 9 days — historically a precursor to destructive escalation.

I am a
My sector

DevelopmentSignificance
CVE-2026-20316 added to CISA KEV (Cisco Secure FMC static credentials)Unauthenticated access to firewall management — Pioneer Kitten historically weaponizes Cisco vulns within days
5 Iranian espionage campaigns refreshed in 48 hoursAPT42, PULSAR KITTEN, and unnamed MOIS groups running concurrent operations across 17+ countries
ASN 213790 infrastructure expansion — new C2 nodes activatedTehran-based hosting cluster now shows APT C2, Cactus ransomware, and anomalous APT28-tagged activity
7 ICS/OT advisories including Siemens S7-1500 GNU/Linux subsystem vulnsDirectly relevant to Cyber Av3ngers' known targeting of Siemens PLCs
TWOSTROKE malware campaign expanding to Azerbaijan and TurkeyGeographic expansion of Iranian espionage beyond the immediate Israel theater
Cavern Manticore "Operation Epic Fury" confirmed destructive campaign against Israeli government/ITActive wiper deployment; pre-stage destructive attack response playbooks immediately
Pro-Iran hacktivist silence extends beyond 9 daysHistorical precursor to escalation toward destructive operations

PhaseTimeframeCyber Activity
Escalation begins2026-02-28Iran-Israel conflict begins; cyber operations commence in parallel
Hacktivist silence beginsJul 21Last observed activity from pro-Iran hacktivist groups (Handala, Cyber Toufan) — silence persists to present
KEV surge & targeting confirmationJul 27Three critical CVEs added to CISA KEV; PULSAR KITTEN confirmed targeting aerospace, defense, and transportation
Destructive capability & OT expansionJul 28Cavern Manticore (MOIS) "Operation Epic Fury" confirmed as a destructive campaign against Israeli government/IT; 7 ICS advisories published
Current — infrastructure validationJul 29, 2026Four Cobalt Strike/Sliver C2 nodes refreshed on Iranian ASNs; CVE-2026-20316 (Cisco FMC) added to KEV; 5 espionage campaigns updated; PULSAR KITTEN spear-phishing against transportation/telecom; TWOSTROKE campaign confirmed expanding to the Caucasus

CISA added CVE-2026-20316 to the KEV catalog on July 29. Cisco Secure Firewall Management Center contains static low-privileged credentials that allow unauthenticated remote login. While rated CVSS 5.3 (Medium), Cisco elevated the Security Impact Rating to HIGH due to privilege escalation chaining potential with other FMC vulnerabilities.

Why this matters: FMC is the central management plane for Cisco firewall infrastructure. Compromise means attackers can modify firewall policies, disable logging, and blind defenders — all without triggering standard authentication alerts. Pioneer Kitten (IRGC-affiliated, also tracked as UNC757) has a documented pattern of rapidly weaponizing Cisco, Fortinet, and Ivanti vulnerabilities. Expect scanning within 7 days.

T1078.001T1552.001T1068

Two high-confidence (97%) APT command-and-control IPs on ASN 213790 ("Limited Network," Tehran) were refreshed on July 29, joining previously tracked infrastructure on the same autonomous system. This ASN now hosts active APT C2 nodes, Cactus ransomware infrastructure, LockBit-tagged infrastructure targeting financial services and government, and anomalous APT28 (Russian GRU) tagging on Tehran-geolocated IPs.

The APT28 tagging on Iranian infrastructure is a significant analytical finding — it suggests either automated classifier misattribution, shared hosting between Russian and Iranian actors, or deliberate false-flag tradecraft. The convergence of Russian and Iranian indicators on the same infrastructure warrants dedicated monitoring.

T1071T1571

PULSAR KITTEN (IRGC-affiliated, active since 2023) received a profile update confirming active spear-phishing campaigns against a German branch of a U.S. transportation company, with infrastructure overlap to Iraqi telecom targeting. The actor deploys SilkySand and SurveyAgent malware and has demonstrated capability against aerospace, defense, telecom, transportation, and energy sectors across the US, UK, UAE, Israel, Turkey, Pakistan, and Thailand.

Exploited vulnerabilities: CVE-2021-44228 (Log4Shell), CVE-2021-26084 (Confluence), CVE-2021-34473 (ProxyShell), CVE-2022-47966 (ManageEngine), CVE-2018-13379 (FortiGate), CVE-2022-26134 (Confluence), CVE-2022-0847 (Dirty Pipe).

T1566.001T1190T1219T1041

APT42 (IRGC Intelligence Organization) is confirmed running at least two concurrent campaign tracks: BELLACIAO/SHELLAFEL — targeting chemical, energy, government, healthcare, and manufacturing sectors — and TAMECAT — targeting defense and aerospace. This dual-track approach indicates significant operational capacity and suggests APT42 has compartmentalized teams running independent missions simultaneously.

T1199T1566.001

Seven ICS advisories published July 28 include critical vulnerabilities in Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP — specifically in the GNU/Linux subsystem. This introduces IT-style attack vectors (Linux exploitation) into OT controllers. Cyber Av3ngers (UNC5203, IRGC-affiliated) have historically targeted Siemens PLCs in water treatment and energy infrastructure — the new Linux subsystem vulnerabilities provide exactly the kind of IT-OT convergence attack surface this group exploits.

Additional advisories cover MikroTik RouterOS brute-force vulnerabilities, Siemens Desigo CC (building automation), and Siemens S7-PLCSIM Advanced (denial of service).

T1595T1110T0831

Handala, Cyber Toufan, and BANISHED KITTEN (Cotton Sandstorm, IRGC-affiliated) have maintained anomalous silence since approximately July 21 — now exceeding 9 days. Historical pattern analysis shows that extended hacktivist silence has preceded escalation to destructive operations (wipers, large-scale data leaks) timed to geopolitical trigger events. This silence should not be interpreted as reduced threat — it should be treated as a warning indicator.

ScenarioProbabilityTimeframeBasis
Pioneer Kitten scanning for CVE-2026-20316 (Cisco FMC)75%7 daysHistorical pattern of rapid Cisco/Fortinet/Ivanti exploitation
Cyber Av3ngers incorporating S7-1500 Linux subsystem vulns into toolkit50%30 daysGroup's established focus on Siemens PLCs + new attack surface
PULSAR KITTEN expanding spear-phishing to aerospace/defense targets45%14 daysActor profile explicitly includes these sectors; transportation campaign is active
Coordinated hacktivist wiper/IO operation following silence period35%7–14 daysHistorical precedent; extended silence as escalation precursor
Russia-Iran shared infrastructure confirmed (ASN 213790)30%30 daysAnomalous APT28 tagging on Tehran IPs; requires further collection

1. Cisco FMC Static Credential Exploitation (CVE-2026-20316):

Hunt hypothesis: Threat actors are authenticating to FMC instances using static/default credentials from untrusted source IPs. Detection: Monitor FMC authentication logs for logins from non-administrative source IPs; alert on any successful authentication using built-in low-privilege accounts. Action: If FMC is internet-exposed, treat as compromised until verified.

2. ASN 213790 / ASN 215930 Communications:

Hunt hypothesis: Compromised internal hosts are beaconing to Iranian C2 infrastructure. Detection: Create network detection rules for any inbound or outbound traffic to ASN 213790 ("Limited Network") and ASN 215930 ("Cipher Operations Beograd") — both geolocated Tehran. Action: Any hit should trigger immediate host isolation and forensic triage.

3. PULSAR KITTEN Spear-Phishing Indicators:

Hunt hypothesis: Employees in transportation, telecom, or aerospace roles are receiving targeted phishing with SilkySand/SurveyAgent payloads. Detection: Monitor for AnyDesk installations not provisioned by IT (T1219); hunt for unknown executables making outbound connections to cloud email APIs (T1041). Action: Review email gateway logs for attachments from unknown senders targeting transportation/aerospace business units.

4. Siemens S7-1500 / MikroTik OT Reconnaissance:

Hunt hypothesis: Threat actors are scanning for exposed S7-1500 controllers or brute-forcing MikroTik routers in OT segments. Detection: Monitor for Modbus/S7comm scanning from IT network segments toward OT; alert on MikroTik authentication failure spikes (T1110). Action: Verify OT network segmentation; confirm no S7-1500 or MikroTik devices are reachable from the internet.

5. APT42 Trusted Relationship Abuse:

Hunt hypothesis: Compromised partner/vendor accounts are being used to send phishing to internal users. Detection: Monitor for emails from known partner domains with unusual attachment types or links to credential harvesting pages (T1199). Action: Implement partner email domain anomaly detection; verify MFA on all federated trust relationships.

ThreatATT&CK
1. Cisco FMC Static Credential Exploitation (CVE-2026-20316)T1078.001 T1552.001
2. ASN 213790 / ASN 215930 CommunicationsT1071 T1571
3. PULSAR KITTEN Spear-Phishing IndicatorsT1219 T1041 T1566.001 T1059
4. Siemens S7-1500 / MikroTik OT ReconnaissanceT1110 T1595 T0831
5. APT42 Trusted Relationship AbuseT1199 T1566.001
IOC Blocking Table:
77.90.185[.]2877.90.185[.]24862.60.130[.]237185.93.89[.]752.188.214[.]142

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1078.001
1. Cisco FMC Static Credential Exploitation (CVE-2026-20316)
Hunt hypothesis: Threat actors are authenticating to FMC instances using static/default credentials from untrusted source IPs. Detection: Monitor FMC authentication logs for logins from non-administrative source IPs; alert on any successful authentication using built-in low-privilege accounts. Action: If FMC is internet-exposed, treat as compromised until verified.
HUNT 02 · T1071
2. ASN 213790 / ASN 215930 Communications
Hunt hypothesis: Compromised internal hosts are beaconing to Iranian C2 infrastructure. Detection: Create network detection rules for any inbound or outbound traffic to ASN 213790 ("Limited Network") and ASN 215930 ("Cipher Operations Beograd") — both geolocated Tehran. Action: Any hit should trigger immediate host isolation and forensic triage.
HUNT 03 · T1219
3. PULSAR KITTEN Spear-Phishing Indicators
Hunt hypothesis: Employees in transportation, telecom, or aerospace roles are receiving targeted phishing with SilkySand/SurveyAgent payloads. Detection: Monitor for AnyDesk installations not provisioned by IT (T1219); hunt for unknown executables making outbound connections to cloud email APIs (T1041). Action: Review email gateway logs for attachments from unknown senders targeting transportation/aerospace business units.
HUNT 04 · T1110
4. Siemens S7-1500 / MikroTik OT Reconnaissance
Hunt hypothesis: Threat actors are scanning for exposed S7-1500 controllers or brute-forcing MikroTik routers in OT segments. Detection: Monitor for Modbus/S7comm scanning from IT network segments toward OT; alert on MikroTik authentication failure spikes (T1110). Action: Verify OT network segmentation; confirm no S7-1500 or MikroTik devices are reachable from the internet.
HUNT 05 · T1199
5. APT42 Trusted Relationship Abuse
Hunt hypothesis: Compromised partner/vendor accounts are being used to send phishing to internal users. Detection: Monitor for emails from known partner domains with unusual attachment types or links to credential harvesting pages (T1199). Action: Implement partner email domain anomaly detection; verify MFA on all federated trust relationships.

Financial Services
Ransomware Convergence, ASN 213790/215930
Primary threats
Cactus ransomware operating from Iranian infrastructure (ASN 213790, ASN 215930); LockBit-tagged infrastructure on the same ASN targeting financial services
Actions
  • Block ASN 213790 and ASN 215930 at perimeter; review ransomware playbooks
  • Verify offline backup integrity; monitor for data exfiltration preceding encryption (double-extortion pattern)
Energy
Siemens S7-1500, PLC Targeting
Primary threat
Cyber Av3ngers (UNC5203) targeting Siemens PLCs; APT42 BELLACIAO campaign explicitly targeting energy sector; PULSAR KITTEN targeting energy organizations
Actions
  • Audit all Siemens S7-1500 firmware versions (V3.1.6 is vulnerable); implement CISA CI Fortify isolation guidance for vital OT systems
  • Segment SCADA from corporate IT; deploy OT-specific anomaly detection
Healthcare
Webshell Detection, BELLACIAO
Primary threat
APT42 BELLACIAO/SHELLAFEL campaign explicitly lists healthcare as a target sector
Actions
  • Review webshell detection capabilities — BELLACIAO is a .NET webshell; audit internet-facing web applications for unauthorized file uploads
  • Monitor for anomalous IIS/Apache worker processes spawning cmd.exe or PowerShell
Government
Destructive Campaigns, Epic Fury
Primary threat
Cavern Manticore (MOIS) "Operation Epic Fury" destructive/wiper campaign; multiple Iranian espionage campaigns targeting government across 17+ countries; ASN 213790 C2 infrastructure
Actions
  • Activate destructive attack playbooks; verify system recovery capabilities
  • Implement enhanced monitoring for lateral movement and credential harvesting; brief staff on spear-phishing from trusted-relationship abuse
Aviation / Logistics
International Subsidiaries, Spear-Phishing
Primary threat
PULSAR KITTEN actively spear-phishing transportation companies via international subsidiaries; a tracked 2026 Iran Conflict campaign is targeting aerospace
Actions
  • Brief international subsidiary security teams on PULSAR KITTEN TTPs; monitor for AnyDesk installations
  • Hunt for SilkySand/SurveyAgent malware indicators; review email security for subsidiary-to-HQ communication paths

Block IPs 77.90.185[.]28 and 77.90.185[.]248 at perimeter firewall — active APT C2 infrastructure, confidence 97%.
SOC Analyst
Block IP 62.60.130[.]237 — Cactus ransomware infrastructure on Iranian hosting.
SOC Analyst
Block IP 185.93.89[.]75 — LockBit-tagged infrastructure targeting financial services/government.
SOC Analyst
Audit ALL Cisco Secure FMC instances for CVE-2026-20316 — verify no static credential accounts are accessible from untrusted networks. Apply the Cisco patch immediately.
IAM Analyst
Deploy detection for any authentication to FMC using default/static accounts from non-administrative IPs.
SOC Analyst
Pre-stage destructive attack response playbook — Cavern Manticore (MOIS) "Operation Epic Fury" wiper campaign is active against government/IT sectors.
Incident Responder
No immediate actions for the selected roles.
Implement network detection rules for all traffic to/from ASN 213790 and ASN 215930 — treat entire ASNs as hostile.
SOC Analyst
Audit Siemens S7-1500 CPU 1518(F)-4 firmware — if running V3.1.6, schedule GNU/Linux subsystem patching. Isolate from IT network per CISA CI Fortify guidance.
ICS / OT
Deploy MikroTik RouterOS brute-force detection — rate-limit authentication attempts; verify no MikroTik devices are internet-exposed in OT segments.
ICS / OT
Implement enhanced email filtering for spear-phishing targeting transportation, aerospace, and telecom business units — PULSAR KITTEN campaign is active.
SOC Analyst
Audit all federated trust relationships and partner OAuth grants — Iranian actors confirmed abusing trusted relationships for phishing.
IAM Analyst
Hunt for unauthorized AnyDesk installations across the enterprise — PULSAR KITTEN deploys AnyDesk as a persistence mechanism.
Threat Hunter
No 7-day actions for the selected roles.
Commission an assessment of Russia-Iran cyber infrastructure convergence — determine if shared hosting on ASN 213790 represents operational collaboration.
CISO / Exec
Evaluate organizational exposure to space/satellite sector targeting — PULSAR KITTEN has a unique focus on this vertical.
CISO / Exec
Conduct a red team assessment of IT-to-OT segmentation with specific focus on Siemens S7-1500 GNU/Linux subsystem attack paths.
ICS / OT
Tabletop exercise: coordinated Iranian destructive attack scenario — wiper deployment following the hacktivist silence period, combined with FMC compromise for defender blinding.
Incident Responder
Brief the board on sustained Iranian cyber threat posture — five months of escalating operations with no de-escalation indicators.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Five months into this conflict, Iranian cyber operations are not winding down — they are diversifying and accelerating. Two distinct intelligence organizations (MOIS and IRGC) are running parallel campaigns across espionage, destructive operations, ransomware crossover, and ICS targeting. The convergence of a new Cisco FMC vulnerability with Pioneer Kitten's known exploitation patterns creates an immediate window of risk. The sustained hacktivist silence is not peace — it is preparation.

1
Is your Cisco Secure FMC patched? CVE-2026-20316 lets an unauthenticated attacker log in with static credentials — Pioneer Kitten historically weaponizes Cisco vulnerabilities within days of KEV listing.
2
Have you blocked ASN 213790 and ASN 215930? This single Tehran-based hosting cluster now serves APT C2, Cactus ransomware, and anomalous APT28-tagged infrastructure simultaneously.
3
Is your destructive-attack playbook staged? Cavern Manticore's "Operation Epic Fury" is an active wiper campaign — nine days of hacktivist silence historically precedes exactly this kind of escalation.
No items found.