TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Isn't Slowing Down:

Your Perimeter Is the Battlefield

ELEVATED (trending toward HIGH). Unchanged from Sep 24, but multiple indicators suggest an imminent shift to HIGH. Four IRGC- and MOIS-linked actor groups are simultaneously active across destructive, espionage, and influence operations. HYDRO KITTEN's ZodiacRAT and ScratchWiper have been confirmed against an Israeli engineering firm, BANISHED KITTEN's Gulf wiper claims were validated as "likely valid," and Cisco Secure Firewall Management Center now carries a 7-CVE exposure including a perfect CVSS 10.0.

I am a
My sector

DateDevelopmentSignificance
Sep 16...Cisco discloses...Cisco FMC now...
Sep 19...IRGC-linked UNC6779...Energy and utility...
Sep 22...CISA adds 4 KEVs...Active exploitation...
Sep 23–24...MuddyWater (MOIS)...MOIS operational...
Sep 24...CrowdStrike confirms...First confirmed...
Sep 24...CrowdStrike assesses...Destructive operatio...
Sep 24...CISA adds CVE-2026-5...Full account takeove...
Sep 24...IMPERIAL KITTEN...Infrastructure...
Sep 25...CVE-2026-48842...Email credential...
Sep 25...CARBONATO botnet...Paradigm shift...

PhaseTimeframeCyber Activity
Initial EscalationFeb 28 - Mar 2026Conflict begins...
Destructive Operatio...Mar - Apr 2026HYDRO KITTEN deploys...
Infrastructure...Jun 2026IMPERIAL KITTEN...
Perimeter Exploitati...Jul - Aug 2026Cisco FMC CVE-2026-2...
KEV Surge and...Sep 19-24, 2026UNC6779 exploits...
Current - Sustained...Sep 25, 2026Cisco FMC reaches...

CrowdStrike confirmed HYDRO KITTEN (Cyber Av3ngers) deployed ZodiacRAT (Go-based RAT, Telegram C2) and ScratchWiper (C++ data destruction tool) against an Israeli engineering firm between March-April. This moves the group beyond IO bluster into real destructive operations.

The wiper toolkit is shared with IMPERIAL KITTEN, indicating...

T1485T1071.001T1190

Cisco FMC now carries seven CVEs: CVE-2026-20131 (10.0, RCE, in KEV), CVE-2026-20242 (9.8, unauth RCE via deserialization), CVE-2026-76420 (9.0, root via AJP impersonation), CVE-2026-20341 (9.1, root via sftunnel deserialization), plus three more (8.3-8.6). FMC is the centralized management plane for all Cisco FTD firewalls - compromise means...

T1068T1190

WSO2 (CVE-2026-5430, CVSS 10.0): JWT algorithm confusion enables full account takeover including admin accounts - no credentials required. CISA confirmed active exploitation.

Roundcube (CVE-2026-48842, CVSS 8.1): pre-auth SQLi actively exploited with 523,000+ instances exposed. China-aligned...

T1078T1114

Discovered spreading via exposed Docker daemons on port 2375, CARBONATO uses Hermes Agent - a legitimate, MIT-licensed AI framework - as its post-exploitation platform. A 39-line persona file ("GH0ST"/SOUL.md) defines its malicious behavior, not code - making binary-level and signature-based detection nearly ineffective. It prioritizes stealing...

T1528T1583.006

IMPERIAL KITTEN registered FIFA World Cup-themed domains in June for credential harvesting, targeting defense, energy, financial services, government, telecom, and maritime sectors. CrowdStrike identified this group as the first Iran-nexus adversary demonstrating cloud-conscious tradecraft - understanding OAuth flows and cloud identity...

T1583.001T1528

ProbabilityScenarioBasis
70–80%...HYDRO KITTEN continu...Sustained pattern...
50–65%...Cisco FMC September...Deserialization...
40–60%...IMPERIAL KITTEN...World Cup timing...
40–60%...Additional Iranian...523K exposed instanc...
30–40%...MuddyWater breaks...MuddyWater's operati...
20–30%...AI agent weaponizati...Technique is trivial...

Technique IDTechnique NameWhat to MonitorContext
T1190...Exploit Public-Facin...FMC management...Primary initial...
T1078 /...Valid Accounts /...JWT token anomalies...WSO2 CVE-2026-5430...
T1550.001...Use Alternate...Forged JWT tokens...Direct detection...
T1485...Data DestructionRapid file deletion...HYDRO KITTEN and...
T1486...Data Encrypted for...Ransomware indicator...Iranian actors...
T1059.001...PowerShellPowerShell-based...ZodiacRAT delivery...
T1583.001...Acquire Infrastructu...Newly registered...IMPERIAL KITTEN...
T1068...Exploitation for...FMC sftunnel deseria...Cisco FMC CVE...
T1528...Steal Application...Exfiltration of...CARBONATO specifical...
T1114...Email CollectionBulk mailbox access...Roundcube CVE-2026-4...
IOC Blocking Table:
45.86.5[.]10846.148.36[.]40151.232.109[.]19780.210.185[.]185.238.21[.]131172.94.9[.]1682.185.35[.]12237.220.6[.]115109.169.61[.]8

Block the above...

Hunting Hypotheses:
HUNT 01 · T1059.001
Hunt for ZodiacRAT
Search for Go-compiled binaries with Telegram API beaconing patterns. Look for outbound connections to api.telegram[.]org from servers that should not have Telegram access. Correlate with PowerShell execution chains (T1059.001).
HUNT 02
Hunt for CARBONATO/GH0ST
Query container orchestration logs for Docker daemon connections on port 2375 from external IPs. Search for the file path /root/.hermes/SOUL.md and environment variables containing CARBONATO_API_KEY. Monitor for unexpected AI API key usage (OpenAI, Anthropic, Google, Groq) from containerized workloads.
HUNT 03
Hunt for FMC Compromise
Audit FMC management interface access logs for connections from non-management subnets. Check sftunnel connection state — if sftunnel is down, CVE-2026-76420 becomes exploitable. Review FMC audit logs for unexpected policy changes or new admin accounts.
HUNT 04
Hunt for WSO2 Token Forgery
Analyze JWT tokens in WSO2 logs for non-standard signing algorithms. Look for admin-level API calls from previously unseen source IPs. Audit identity broker configurations for algorithm pinning enforcement.
HUNT 05
Hunt for Roundcube Exploitation
Query web application logs for SQL injection patterns in Roundcube's virtuser_query plugin endpoints. Monitor for bulk mailbox access or mail forwarding rule creation post-authentication. Cross-reference with known UNK_MassTraction infrastructure patterns.
HUNT 06
Hunt for Iranian Wiper Pre-Staging
Monitor for lateral movement patterns consistent with wiper deployment preparation — specifically, enumeration of domain controllers, backup systems, and storage infrastructure. Look for staging of unknown C++ binaries in system directories.

Financial Services
SWIFT, API Gateways
Primary threat
IMPERIAL KITTEN explicitly targets financial services; WSO2 JWT bypass is especially dangerous...
Actions
  • Audit WSO2 deployments for JWT algorithm pinning; validate SWIFT segmentation from FMC-managed segments
Energy
SCADA, ICS/OT Networks
Primary threat
Primary IRGC-CEC target. UNC6779 actively exploiting GlobalProtect; HYDRO KITTEN has documented...
Actions
  • Patch GlobalProtect immediately; segment ICS/OT from Cisco FMC-managed IT networks
Healthcare
Webmail, Backup Systems
Primary threats
Dual threat: ransomware-as-cover for destructive intent, and Roundcube exploitation given...
Actions
  • Patch Roundcube to 1.6.16+/1.7.1+; ensure backups are isolated from FMC-managed networks
Government
Firewall Infrastructure
Primary threats
Targeted across all Iranian actor groups for espionage, destruction, and influence. Validated Gulf...
Actions
  • Audit Cisco FMC deployments given systemic 7-CVE exposure; validate wiper detection for ScratchWiper/ZeroShred/BiBiWiper/GoneXML
Aviation / Logistics
Logistics, Supply Chain
Primary threat
IMPERIAL KITTEN explicitly targets transportation and maritime sectors for both espionage and...
Actions
  • Audit perimeter VPN/firewall appliances against HYDRO/IMPERIAL KITTEN's exploitation chain; segment cargo systems from FMC zones
No sector cards match the selected filters.

Patch Cisco Secure FMC for CVE-2026-76420/20242/20341...
Incident Responder
Patch Roundcube Webmail to 1.6.16+/1.7.1+; assume credential...
Incident Responder
Block Docker daemon port 2375 exposure; hunt for...
SOC Analyst
Validate Palo Alto GlobalProtect patched against...
Incident Responder
No immediate actions for the selected roles.
Patch WSO2 identity products for CVE-2026-5430; audit JWT...
Incident Responder
Deploy detection for HYDRO KITTEN TTPs: YARA rules for...
SOC Analyst
Inventory all AI API keys; rotate any in plaintext or on...
Incident Responder
Build a unified detection rule set for Iranian wiper families...
SOC Analyst
No 7-day actions for the selected roles.
Commission an architectural assessment of Cisco FMC/FTD...
CISO / Exec
Conduct a tabletop exercise simulating a HYDRO KITTEN kill...
CISO / ExecIncident Responder
Enforce 72-hour patching SLAs for internet-facing perimeter...
CISO / Exec
Diversify OSINT intelligence sources - the current 5-day...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Nearly seven months into this conflict, Iranian cyber operations are not winding down - they are maturing. The confirmation of ZodiacRAT and ScratchWiper deployment, the validation of BANISHED KITTEN's Gulf wiper campaign, and IMPERIAL KITTEN's methodical infrastructure staging all point to actors that have moved past initial chaos into sustained, professional offensive operations. Meanwhile the vulnerability landscape is working against defenders: a single Cisco FMC deployment carries seven...

1
Patch Cisco FMC and Roundcube today.
2
Hunt for CARBONATO and HYDRO KITTEN indicators this week.
3
Treat your firewall management plane like Active Directory.
No items found.