| Date | Development | Significance |
|---|---|---|
| Sep 16... | Cisco discloses... | Cisco FMC now... |
| Sep 19... | IRGC-linked UNC6779... | Energy and utility... |
| Sep 22... | CISA adds 4 KEVs... | Active exploitation... |
| Sep 23–24... | MuddyWater (MOIS)... | MOIS operational... |
| Sep 24... | CrowdStrike confirms... | First confirmed... |
| Sep 24... | CrowdStrike assesses... | Destructive operatio... |
| Sep 24... | CISA adds CVE-2026-5... | Full account takeove... |
| Sep 24... | IMPERIAL KITTEN... | Infrastructure... |
| Sep 25... | CVE-2026-48842... | Email credential... |
| Sep 25... | CARBONATO botnet... | Paradigm shift... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Initial Escalation | Feb 28 - Mar 2026 | Conflict begins... |
| Destructive Operatio... | Mar - Apr 2026 | HYDRO KITTEN deploys... |
| Infrastructure... | Jun 2026 | IMPERIAL KITTEN... |
| Perimeter Exploitati... | Jul - Aug 2026 | Cisco FMC CVE-2026-2... |
| KEV Surge and... | Sep 19-24, 2026 | UNC6779 exploits... |
| Current - Sustained... | Sep 25, 2026 | Cisco FMC reaches... |
CrowdStrike confirmed HYDRO KITTEN (Cyber Av3ngers) deployed ZodiacRAT (Go-based RAT, Telegram C2) and ScratchWiper (C++ data destruction tool) against an Israeli engineering firm between March-April. This moves the group beyond IO bluster into real destructive operations.
The wiper toolkit is shared with IMPERIAL KITTEN, indicating...
Cisco FMC now carries seven CVEs: CVE-2026-20131 (10.0, RCE, in KEV), CVE-2026-20242 (9.8, unauth RCE via deserialization), CVE-2026-76420 (9.0, root via AJP impersonation), CVE-2026-20341 (9.1, root via sftunnel deserialization), plus three more (8.3-8.6). FMC is the centralized management plane for all Cisco FTD firewalls - compromise means...
WSO2 (CVE-2026-5430, CVSS 10.0): JWT algorithm confusion enables full account takeover including admin accounts - no credentials required. CISA confirmed active exploitation.
Roundcube (CVE-2026-48842, CVSS 8.1): pre-auth SQLi actively exploited with 523,000+ instances exposed. China-aligned...
Discovered spreading via exposed Docker daemons on port 2375, CARBONATO uses Hermes Agent - a legitimate, MIT-licensed AI framework - as its post-exploitation platform. A 39-line persona file ("GH0ST"/SOUL.md) defines its malicious behavior, not code - making binary-level and signature-based detection nearly ineffective. It prioritizes stealing...
IMPERIAL KITTEN registered FIFA World Cup-themed domains in June for credential harvesting, targeting defense, energy, financial services, government, telecom, and maritime sectors. CrowdStrike identified this group as the first Iran-nexus adversary demonstrating cloud-conscious tradecraft - understanding OAuth flows and cloud identity...
| Probability | Scenario | Basis |
|---|---|---|
| 70–80%... | HYDRO KITTEN continu... | Sustained pattern... |
| 50–65%... | Cisco FMC September... | Deserialization... |
| 40–60%... | IMPERIAL KITTEN... | World Cup timing... |
| 40–60%... | Additional Iranian... | 523K exposed instanc... |
| 30–40%... | MuddyWater breaks... | MuddyWater's operati... |
| 20–30%... | AI agent weaponizati... | Technique is trivial... |
| Technique ID | Technique Name | What to Monitor | Context |
|---|---|---|---|
| T1190... | Exploit Public-Facin... | FMC management... | Primary initial... |
| T1078 /... | Valid Accounts /... | JWT token anomalies... | WSO2 CVE-2026-5430... |
| T1550.001... | Use Alternate... | Forged JWT tokens... | Direct detection... |
| T1485... | Data Destruction | Rapid file deletion... | HYDRO KITTEN and... |
| T1486... | Data Encrypted for... | Ransomware indicator... | Iranian actors... |
| T1059.001... | PowerShell | PowerShell-based... | ZodiacRAT delivery... |
| T1583.001... | Acquire Infrastructu... | Newly registered... | IMPERIAL KITTEN... |
| T1068... | Exploitation for... | FMC sftunnel deseria... | Cisco FMC CVE... |
| T1528... | Steal Application... | Exfiltration of... | CARBONATO specifical... |
| T1114... | Email Collection | Bulk mailbox access... | Roundcube CVE-2026-4... |
Block the above...
api.telegram[.]org from servers that should not have Telegram access. Correlate with PowerShell execution chains (T1059.001)./root/.hermes/SOUL.md and environment variables containing CARBONATO_API_KEY. Monitor for unexpected AI API key usage (OpenAI, Anthropic, Google, Groq) from containerized workloads.- Audit WSO2 deployments for JWT algorithm pinning; validate SWIFT segmentation from FMC-managed segments
- Patch GlobalProtect immediately; segment ICS/OT from Cisco FMC-managed IT networks
- Patch Roundcube to 1.6.16+/1.7.1+; ensure backups are isolated from FMC-managed networks
- Audit Cisco FMC deployments given systemic 7-CVE exposure; validate wiper detection for ScratchWiper/ZeroShred/BiBiWiper/GoneXML
- Audit perimeter VPN/firewall appliances against HYDRO/IMPERIAL KITTEN's exploitation chain; segment cargo systems from FMC zones
Nearly seven months into this conflict, Iranian cyber operations are not winding down - they are maturing. The confirmation of ZodiacRAT and ScratchWiper deployment, the validation of BANISHED KITTEN's Gulf wiper campaign, and IMPERIAL KITTEN's methodical infrastructure staging all point to actors that have moved past initial chaos into sustained, professional offensive operations. Meanwhile the vulnerability landscape is working against defenders: a single Cisco FMC deployment carries seven...