TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Is Shifting Gears:

Your Perimeter Is the Target

ELEVATED (trending toward HIGH). Two critical perimeter vulnerabilities hit CISA KEV in 48 hours - including a perfect CVSS 10.0 - while MuddyWater deploys fresh malware against an unusual sector, new Iran-hosted C2 tagged to ceasefire-retaliation planning goes active, and pro-Iranian hacktivists go silent for a fourth consecutive day. The pattern is unmistakable: noisy activity goes quiet, APT groups refresh tooling, edge exploits get weaponized within days. We are in the quiet-before-the-storm window right now.

I am a
My sector

DevelopmentSignificance
CISA added four new KEVs Sep 22, including two CVSS...Perimeter devices are under sustained multi-vendor pressure
MuddyWater surfaced five fresh malware samples...Retail MSPs often serve government and defense clients
An Iran-hosted C2 server (62.60.226[.]10) validated...Running DarkComet RAT and Keitaro TDS for victim profiling
Seven Siemens ICS advisories dropped, including auth...Directly relevant to military and government facility operations
Pro-Iranian hacktivist groups went silent for a fourth...An anomalous pause during active conflict that historically precedes...
UNC4444 and UNC2428 received significantly expanded targeting...Consistent with a conflict-escalation posture toward broad economic...

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran-US conflict begins; kinetic and cyber operations commence in...
BANISHED KITTEN wipers validatedApr 2026BANISHED KITTEN conducts destructive wiper attacks against UAE, Saudi...
GlobalProtect exploitation beginsSep 19, 2026UNC6779 begins active exploitation of Palo Alto GlobalProtect...
KEV surge, ICS advisories, fresh malwareSep 22-23, 2026CISA adds 4 KEVs (Check Point x2, Arista VeloCloud CVSS 10.0); 7...
Current (Day ~209) - C2 validated, targeting expandsSep 24, 2026Iran-hosted C2 validated active with ceasefire-retaliation tags...

CVE-2026-85102 and CVE-2026-85103 (both CVSS 9.8) are pre-auth RCE vulnerabilities in VPN negotiation and certificate handling; a companion management flaw (CVE-2026-93616) was disclosed simultaneously. CISA confirmed active exploitation.

Fox Kitten and APT33 have historically been among the fastest adopters of edge device exploits...

T1190T1133T1078

CVE-2026-93952 allows an unauthenticated attacker to access privileged internal functionality on VCO, compromising confidentiality, integrity, and availability of the orchestrator and every device it manages. VCO controls SD-WAN routing, traffic inspection, and segmentation across the entire WAN.

For government and military networks using...

T1190

MuddyWater (Seedworm, TEMP.Zagros, Static Kitten) is a MOIS-affiliated group historically targeting government, defense, and energy. Five fresh "derohe" malware samples tagged to U.S. retail mark a departure - either a supply-chain pivot through retail MSPs serving higher-value clients, or a broadened coercive mandate targeting civilian...

T1566.001T1059.001T1071.001

The validated C2 at 62.60.226[.]10 (Femo IT Solutions, Iran) runs DarkComet RAT and Keitaro TDS - notable because Keitaro filters and redirects traffic based on victim profiling, sending high-value targets to exploit chains while researchers see benign content. Its explicit tagging to ceasefire-retaliation planning marks it as pre-positioning...

T1071.001T1105T1583.006

BANISHED KITTEN, Cyber Av3ngers, DieNet, and UWAYS QARANI have produced zero public claims for four consecutive days - anomalous during active kinetic conflict. Historical precedent: before the 2023 Cyber Av3ngers campaign against Unitronics PLCs, hacktivist noise dropped as operations shifted from visible disruption to quiet APT...

ProbabilityScenario
70%Iranian APT operational tempo continues to increase — the...
60%Check Point Quantum CVE-2026-85102/85103 is weaponized by Iranian...
55%UNC6779 exploitation of Palo Alto GlobalProtect CVE-2026-0257 expands...
50%BANISHED KITTEN's operational pause ends with a retooled wiper...
45%Arista VeloCloud CVE-2026-93952 is exploited in a targeted attack...
40%Iranian actors leverage Siemens ICS vulnerabilities (Industrial Edge...

Immediate Blocking Actions:

Add the following validated indicators to your perimeter blocklists...

IOC Blocking Table:
62.60.226[.]1043.231.4[.]745.205.1[.]36

Block the above at perimeter firewalls, proxies, and DNS. Hashes...

Hunting Hypotheses:
HUNT 01 · T1190
Hunt 1: Edge Device Exploitation (Check Point & Arista)
Hypothesis: Iranian actors are exploiting CVE-2026-85102/85103 on Check Point Quantum gateways to establish initial access, then harvesting VPN credentials for persistent access. Detection: Monitor Check Point gateway logs for anomalous VPN certificate negotiation failures, unexpected admin sessions, and configuration exports. For Arista VCO, alert on any unauthenticated API calls to orchestrator management endpoints. Correlate with outbound connections to known Iranian ASNs (214351, 44889, 58224). Hunt query: Search network telemetry for connections from Check Point gateway management IPs to external IPs not in your approved management list. Search for VeloCloud Orchestrator API calls originating from non-management subnets.
HUNT 02 · T1566.001
Hunt 2: MuddyWater Maldoc Delivery
Hypothesis: MuddyWater is delivering derohe-family malware via spearphishing emails with malicious document attachments that spawn PowerShell or cmd.exe for second-stage payload retrieval. Detection: Alert on Office processes (WINWORD.EXE, EXCEL.EXE) spawning PowerShell, cmd.exe, or wscript.exe. Monitor for XML files with embedded macros arriving via email. Deploy YARA rules for the five SHA-256 hashes listed above. Hunt query: Search email gateway logs for attachments with XML/DOCX extensions from unfamiliar senders targeting retail, commercial, or MSP-related business units. Search EDR for the specific hashes.
HUNT 03 · T1071.001
Hunt 3: Iran-Hosted C2 Communication
Hypothesis: Compromised endpoints are beaconing to 62.60.226[.]10 via HTTP/HTTPS using DarkComet RAT protocol, with Keitaro TDS performing victim profiling and redirection. Detection: Monitor for HTTP/HTTPS connections to 62.60.226[.]10 and ASN 214351 broadly. DarkComet typically uses distinctive HTTP headers and beacon intervals. Keitaro TDS redirections produce characteristic 302 redirect chains. Hunt query: Search proxy/firewall logs for any connection to ASN 214351 (Femo IT Solutions, Iran) in the past 30 days. Search for DarkComet process injection patterns (T1055) in EDR telemetry.
HUNT 04 · T1133
Hunt 4: Fox Kitten Dormant Access in VPN Infrastructure
Hypothesis: Fox Kitten/Pioneer Kitten may have established persistent VPN access in defense industrial base networks months ago and is waiting for activation. Indicators include Rclone-based exfiltration to Wasabi cloud storage and fake-resume lure repositories on GitHub/Gitea. Detection: Audit VPN authentication logs for dormant accounts that authenticated months ago and have not been used since. Search for Rclone process execution or Wasabi S3 endpoint connections. Review GitHub/Gitea repositories accessible to your organization for recently created repositories containing resume-themed content. Hunt query: process_name:rclone.exe OR dns_query:wasabi in EDR. VPN logs: accounts with last authentication >90 days ago that are still enabled.
HUNT 05 · T1190
Hunt 5: ICS/OT Pre-Positioning
Hypothesis: Iranian actors (SPECTRAL KITTEN, Cyber Av3ngers) are probing Siemens Industrial Edge Management and Desigo CC BMS installations for authentication bypass and code execution opportunities. Detection: Monitor OT network segments for unexpected connections to Siemens Industrial Edge Management interfaces from IT subnets or external IPs. Alert on Desigo CC client code execution events. Review lwIP-based device firmware versions against advisory thresholds. Hunt query: Search OT network monitoring for Siemens device management port traffic from unauthorized sources. Audit BMS access logs for anomalous sessions. ---

Financial Services
SWIFT, Trading Infrastructure
Primary threat
APT34 and newly expanded UNC2428 actively targeting financial services; APT34's confirmed...
Actions
  • Audit Check Point gateways protecting banking infrastructure for patch status; verify SWIFT segmentation from VPN-connected segments
Energy
SCADA, ICS, VPN Perimeters
Primary threat
Highest-priority sector. UNC6779 actively exploiting GlobalProtect; any of three edge device CVEs...
Actions
  • Patch GlobalProtect, Check Point, and Arista VeloCloud across all OT perimeters; audit third-party ICS integrator access
Healthcare
Clinical VPN, Building Management
Primary threat
UNC4444 and UNC2428 both added healthcare to targeting profiles; many hospitals run older Check...
Actions
  • Emergency patch Check Point gateways protecting clinical VPN access; review Desigo CC BMS deployments for patient safety implications
Government
Defense Industrial Base
Primary threats
Full spectrum of Iranian operations: espionage, destructive attacks, and 165-day Fox Kitten...
Actions
  • Commission a threat hunt for Fox Kitten dormant VPN access; patch Arista VCO immediately in government SD-WAN deployments
Aviation / Logistics
Aerospace, GitHub Supply Chain
Primary threat
UNC6446 conducting aerospace phishing via GitHub lure repositories; UNC4444 added aerospace and...
Actions
  • Brief teams on GitHub-based lure technique; audit repository access from corporate networks
No sector cards match the selected filters.

Apply Check Point hotfixes sk1000117/sk1000118 to all Quantum...
Incident Responder
Patch Arista VeloCloud Orchestrator per Security Advisory 0183...
Incident Responder
Block IP 62.60.226[.]10 at perimeter firewalls - validated...
SOC Analyst
Ingest MuddyWater SHA-256 hashes into EDR blocklists and email...
SOC Analyst
No immediate actions for the selected roles.
Review Siemens Industrial Edge Management for auth bypass per...
ICS / OT
Audit third-party ICS integrator access per FBI/CISA fact...
ICS / OT
Harden VPN concentrator configurations across Check Point...
Incident Responder
Brief business units on MuddyWater retail targeting; assess...
CISO / Exec
No 7-day actions for the selected roles.
Commission a proactive threat hunt for Fox Kitten dormant VPN...
Threat Hunter
Conduct a tabletop exercise simulating simultaneous...
CISO / ExecIncident Responder
Review IR playbooks for destructive wiper scenarios - BANISHED...
Incident Responder
Evaluate edge device patch cadence given the velocity of...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The Iran conflict cyber theater is exhibiting a pattern experienced analysts recognize: transition from noisy, visible operations to quiet, deliberate pre-positioning. MuddyWater is refreshing its tooling. APT34 infrastructure is active. Iran-hosted C2 tagged to retaliation planning is validated and communicating. Hacktivist groups have gone silent. And the perimeter devices Iranian actors have historically weaponized faster than anyone else now carry three new critical-to-perfect-score...

1
Patch Check Point and Arista today.
2
Hunt for dormant access this month.
3
Assume the next phase has already begun - you just haven't found it yet.
No items found.