| Development | Significance |
|---|---|
| CISA added four new KEVs Sep 22, including two CVSS... | Perimeter devices are under sustained multi-vendor pressure |
| MuddyWater surfaced five fresh malware samples... | Retail MSPs often serve government and defense clients |
| An Iran-hosted C2 server (62.60.226[.]10) validated... | Running DarkComet RAT and Keitaro TDS for victim profiling |
| Seven Siemens ICS advisories dropped, including auth... | Directly relevant to military and government facility operations |
| Pro-Iranian hacktivist groups went silent for a fourth... | An anomalous pause during active conflict that historically precedes... |
| UNC4444 and UNC2428 received significantly expanded targeting... | Consistent with a conflict-escalation posture toward broad economic... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | Iran-US conflict begins; kinetic and cyber operations commence in... |
| BANISHED KITTEN wipers validated | Apr 2026 | BANISHED KITTEN conducts destructive wiper attacks against UAE, Saudi... |
| GlobalProtect exploitation begins | Sep 19, 2026 | UNC6779 begins active exploitation of Palo Alto GlobalProtect... |
| KEV surge, ICS advisories, fresh malware | Sep 22-23, 2026 | CISA adds 4 KEVs (Check Point x2, Arista VeloCloud CVSS 10.0); 7... |
| Current (Day ~209) - C2 validated, targeting expands | Sep 24, 2026 | Iran-hosted C2 validated active with ceasefire-retaliation tags... |
CVE-2026-85102 and CVE-2026-85103 (both CVSS 9.8) are pre-auth RCE vulnerabilities in VPN negotiation and certificate handling; a companion management flaw (CVE-2026-93616) was disclosed simultaneously. CISA confirmed active exploitation.
Fox Kitten and APT33 have historically been among the fastest adopters of edge device exploits...
CVE-2026-93952 allows an unauthenticated attacker to access privileged internal functionality on VCO, compromising confidentiality, integrity, and availability of the orchestrator and every device it manages. VCO controls SD-WAN routing, traffic inspection, and segmentation across the entire WAN.
For government and military networks using...
MuddyWater (Seedworm, TEMP.Zagros, Static Kitten) is a MOIS-affiliated group historically targeting government, defense, and energy. Five fresh "derohe" malware samples tagged to U.S. retail mark a departure - either a supply-chain pivot through retail MSPs serving higher-value clients, or a broadened coercive mandate targeting civilian...
The validated C2 at 62.60.226[.]10 (Femo IT Solutions, Iran) runs DarkComet RAT and Keitaro TDS - notable because Keitaro filters and redirects traffic based on victim profiling, sending high-value targets to exploit chains while researchers see benign content. Its explicit tagging to ceasefire-retaliation planning marks it as pre-positioning...
BANISHED KITTEN, Cyber Av3ngers, DieNet, and UWAYS QARANI have produced zero public claims for four consecutive days - anomalous during active kinetic conflict. Historical precedent: before the 2023 Cyber Av3ngers campaign against Unitronics PLCs, hacktivist noise dropped as operations shifted from visible disruption to quiet APT...
| Probability | Scenario |
|---|---|
| 70% | Iranian APT operational tempo continues to increase — the... |
| 60% | Check Point Quantum CVE-2026-85102/85103 is weaponized by Iranian... |
| 55% | UNC6779 exploitation of Palo Alto GlobalProtect CVE-2026-0257 expands... |
| 50% | BANISHED KITTEN's operational pause ends with a retooled wiper... |
| 45% | Arista VeloCloud CVE-2026-93952 is exploited in a targeted attack... |
| 40% | Iranian actors leverage Siemens ICS vulnerabilities (Industrial Edge... |
Add the following validated indicators to your perimeter blocklists...
Block the above at perimeter firewalls, proxies, and DNS. Hashes...
62.60.226[.]10 via HTTP/HTTPS using DarkComet RAT protocol, with Keitaro TDS performing victim profiling and redirection. Detection: Monitor for HTTP/HTTPS connections to 62.60.226[.]10 and ASN 214351 broadly. DarkComet typically uses distinctive HTTP headers and beacon intervals. Keitaro TDS redirections produce characteristic 302 redirect chains. Hunt query: Search proxy/firewall logs for any connection to ASN 214351 (Femo IT Solutions, Iran) in the past 30 days. Search for DarkComet process injection patterns (T1055) in EDR telemetry.process_name:rclone.exe OR dns_query:wasabi in EDR. VPN logs: accounts with last authentication >90 days ago that are still enabled.- Audit Check Point gateways protecting banking infrastructure for patch status; verify SWIFT segmentation from VPN-connected segments
- Patch GlobalProtect, Check Point, and Arista VeloCloud across all OT perimeters; audit third-party ICS integrator access
- Emergency patch Check Point gateways protecting clinical VPN access; review Desigo CC BMS deployments for patient safety implications
- Commission a threat hunt for Fox Kitten dormant VPN access; patch Arista VCO immediately in government SD-WAN deployments
- Brief teams on GitHub-based lure technique; audit repository access from corporate networks
The Iran conflict cyber theater is exhibiting a pattern experienced analysts recognize: transition from noisy, visible operations to quiet, deliberate pre-positioning. MuddyWater is refreshing its tooling. APT34 infrastructure is active. Iran-hosted C2 tagged to retaliation planning is validated and communicating. Hacktivist groups have gone silent. And the perimeter devices Iranian actors have historically weaponized faster than anyone else now carry three new critical-to-perfect-score...