TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Is Active:

The Next Wave Is Coming

CRITICAL. The US and Iran are in open warfare since Sep 2. Iran has compromised 100+ US water systems and shut down a UK energy facility - and three CVSS 9.8+ vulnerabilities in VPN/CI-CD/DevOps infra are under active or imminent exploitation, the exact surface Iranian actors have historically weaponized.

I am a
My sector

DevelopmentSignificance
100+ US water systems compromised - largest confirmed Iranian ICS operation against US infrastructure.Demonstrates capability at scale
GitLab CVE-2026-85706 (CVSS 10.0) - unauthenticated file read - added to KEV Sep 11; probing confirmed within 24h.CI/CD secrets and source code exposed
JFrog Artifactory triple-chain active since mid-August - full admin takeover.Enables supply chain poisoning at scale
Check Point VPN dual RCE (CVSS 9.8) - Dutch NCSC warns exploitation is imminent.Widely deployed across government/military/enterprise
MuddyWater silent for 38 days during the most significant kinetic escalation.Historically precedes operational surges
APT42 updated TAMECAT nuclear campaign via LNK lures.Intensifying IRGC collection against nuclear/aerospace/energy
New Iran-sourced C2 IP stood up Sep 14 in Tehran.Active infrastructure expansion during the escalation window

PhaseTimeframeCyber Activity
Destructive precedent setJul 2026Iran-linked hackers shut down a UK energy facility.
Silence begins, exploitation startsAug 2026MuddyWater goes silent (Aug 7); JFrog exploitation begins; hacktivist silence begins.
Open warfare resumesSep 1-2, 2026CISA discloses 100+ water systems compromised; US strikes Strait of Hormuz, Iran retaliates.
Vulnerability surge, kinetic peakSep 5-11, 2026CISA adds 10 CVEs to KEV; missiles strike US airbase in Jordan.
Current (Day 198)Sep 12-14, 2026APT42 updates TAMECAT; Check Point exploitation imminent; new C2 stood up.

MuddyWater (Mercury, Seedworm) is the most operationally prolific Iranian APT, with Donut shellcode capable of destructive payloads (T1485/T1486) - a departure from espionage. Targets financial, construction, government, telecom across UAE, France, China.

Silent 38 days as of Sep 14 - previous cycles show MuddyWater quiet before surging. Treat as pre-positioning, not stand-down.

T1055T1485T1486T1059.007

GitLab (CVSS 10.0): unauthenticated arbitrary file read via the commits API - exposes credentials, secrets, tokens. Probing confirmed within 24h; CISA gave agencies 3 days to patch.

JFrog triple-chain: anonymous token access + scope bypass + auth bypass = full admin, active since mid-August - the supply-chain class Pioneer Kitten pursues against DIB.

Check Point VPN dual RCE: negotiation bypass and ASN.1 decoder overflow. No PoC yet, but Dutch NCSC rates exploitation HIGH.

T1190T1552.001T1195.002T1133

APT42 updated TAMECAT nuclear espionage via LNK lures. APT33 expanded targeting across aerospace, automotive, chemical, energy in 9 locations. UNC1549 refreshed targeting of aerospace, energy, transportation, utilities. Pioneer Kitten updated GitHub-based DIB phishing.

T1566.001T1204.002T1190T1583.001

Handala/UNC5203, DieNet, 313 Team, and NoName057(16) show an anomalous 12-day silence following Sep 2, vs. the historical 48-72h hacktivist surge pattern - likely an OPSEC pause before coordinated release. 313 Team briefly appeared in SOCMINT Sep 13.

T1583.005T1498

Cyber Av3ngers - the IRGC group behind the 2023 Unitronics PLC campaign - has scaled that playbook dramatically. The 100+ water system compromise follows their methodology at a scale far exceeding 2023.

T0831T0826T1489

ScenarioProbabilityBasis
MuddyWater operational surge (destructive) within 7-14 days70-85%38-day silence mirrors pre-surge patterns
Iranian exploitation of Check Point VPN within 7-10 days70-85%Iranian actors exploit VPN CVEs within days-weeks historically
Escalation of ICS/OT attacks beyond water systems70-85%100+ water systems demonstrate capability at scale
Coordinated hacktivist IO campaign (DDoS, defacement, leaks)40-60%12-day silence is anomalous vs. 48-72h pattern
Supply chain compromise via JFrog/GitLab40-60%Pioneer Kitten's DIB focus plus active exploitation
Satellite comms disruption at forward military locations40-60%iDirect advisory plus military-comms targeting history
Destructive attack against UK/European energy infra20-35%July UK shutdown was a proof of concept
AI-augmented phishing/exploit development20-35%No direct evidence yet, but global LLM-offensive trend

1. Iranian C2 Infrastructure Monitoring:

Hunt for connections to confirmed C2 IPs below - Agentemis/Cobalt Strike/Cactus crossover. T1071.001 T1573.002

3. GitLab Exploitation Detection (CVE-2026-85706):

Monitor web logs for POST requests to the commits API with file.path params - confirmed pattern. Alert on unauthenticated API access returning file contents. T1190 T1552.001

4. JFrog Artifactory Compromise Indicators:

Audit admin accounts since Aug 1; search for malicious plugins; check unauthorized SSH keys. T1078 T1505.003

5. Check Point VPN Pre-Positioning:

Deploy detection now: monitor anomalous VPN negotiation and certificate/crash errors on Security Gateways. T1190 T1133

6. Relvora[.]boats Domain Cluster:

15 subdomains under relvora[.]boats - trojan-downloader infra. Block parent domain and subdomains at DNS/proxy.

7. ICS/OT Monitoring Priorities:

AVEVA - patch per ICSA-26-253-01. ST Engineering iDirect - patch per ICSA-26-183-01. MikroTik - monitor UDP btest and kernel restarts. Water PLCs - audit Unitronics access. T0831 T0826 T1489

IOC Blocking Table:
95.38.176[.]143217.60.241[.]1787.248.153[.]5545.147.77[.]21094.184.37[.]6877.90.185[.]118185.93.89[.]4377.90.185[.]248176.46.152[.]46192.253.248[.]65relvora[.]boatsalovesvisciukai[.]lt

Block above at perimeter/DNS. Hashes withheld pending verification - via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01
MuddyWater pre-positioned DinDoor implants during 38-day silence
Deno runtime execution, ASN213790 connections.
HUNT 02
GitLab exploited via CVE-2026-85706 to harvest credentials
Unauthenticated API calls to commits endpoint.
HUNT 03
JFrog backdoored via triple-chain exploit since August
Admin accounts created after Aug 1, unknown plugins, unauthorized SSH keys.
HUNT 04
Iranian actors probing Check Point VPN vulnerabilities
Malformed VPN negotiation attempts, ASN.1 parsing errors, gateway restarts.
HUNT 05
Satellite terminals compromised via iDirect vulnerabilities
Unauthorized config changes, anomalous outbound traffic from terminal IPs.

Financial Services
SWIFT-Bank
Primary threat
MuddyWater's Donut shellcode (destructive payloads) is a documented financial targeting vector; 100+ water systems show willingness to escalate.
Actions
  • Hunt Donut shellcode; verify backups
Energy
Pipeline-Grid
Primary threat
UK energy shutdown and 100+ water systems establish active destructive operations against Western energy/utility infra. AVEVA adds a direct vector.
Actions
  • Patch AVEVA; audit IT/OT segment
Healthcare
DICOM-EHR
Primary threat
CISA advisories for Orthanc DICOM/CareCam - CareCam takeover is a surveillance vector for Iranian BDA collection; MuddyWater/Cactus adds ransomware risk.
Actions
  • Patch Orthanc/CareCam; segment clinical; validate EHR backups
Government
CI/CD-Nuke
Primary threat
Primary target for APT42/TAMECAT and Pioneer Kitten phishing. GitLab CVSS 10.0 endangers CI/CD with classified source/credentials.
Actions
  • Emergency-patch GitLab; patch Check Point
Aviation / Logistics
CI/CD-Sat
Primary threat
UNC1549 and APT33 both list aerospace/transportation as primary targets. UNC6446's GitHub phishing targets aerospace defense personnel.
Actions
  • Brief staff on phishing; patch satellite
No sector cards match the selected filters.

Block confirmed Iranian C2 IPs (see IOC table below).
SOC Analyst
Patch GitLab to 19.3.2+ - CVSS 10.0 actively exploited.
Incident Responder
Patch Check Point VPN to R82.20 - exploitation assessed imminent.
Incident Responder
Patch JFrog Artifactory to 7.161.20+ - triple-chain confirmed since Aug 15.
Incident Responder
Patch FortiOS/MikroTik - PivotC2 RAT confirmed on FortiOS.
Incident Responder
Elevate posture to CRITICAL; activate crisis comms.
CISO / Exec
No immediate actions for the selected roles.
Hunt for MuddyWater DinDoor/Deno beacons on ASN213790 - 38-day silence is a pre-positioning indicator.
Threat Hunter
Patch AVEVA and ST Engineering iDirect per ICSA-26-253-01 and ICSA-26-183-01.
ICS / OT
Audit hacktivist IO channels - silence is anomalous.
SOC Analyst
Patch AVEVA, ST Engineering, Orthanc/CareCam; segment medical IoT.
ICS / OT
Tabletop a destructive attack (wiper/ransomware/DDoS).
CISO / ExecIncident Responder
No 7-day actions for the selected roles.
Assess DIB CI/CD security; harden IT/OT - OT compromise has safety implications.
CISO / Exec
Evaluate VPN diversity; consider zero-trust.
CISO / Exec
Prepare comms templates for a destructive attack; review insurance exclusions.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

198 days into a conflict now escalated to open warfare, the cyber dimension is operational, not theoretical. Over 100 US water systems compromised. A UK energy facility shut down. Iranian C2 infrastructure expanding in real time. The most prolific Iranian APT group silent in a pattern that historically precedes its most destructive operations. Three critical vulnerability classes - VPN, CI/CD, DevOps - are under active or imminent exploitation, the exact attack surface Iranian actors have spent years learning to exploit.

1
Patch the critical vulnerabilities today. Block the known C2 infrastructure today.
2
Hunt for pre-positioned implants this week.
3
Pressure-test your incident response plans before they are tested for real.
No items found.