TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War Machine Reawakens:

MuddyWater Breaks 39-Day Silence as Kinetic Strikes Intensify

HIGH. Day 200 of the US-Iran conflict. After 39 days of silence, MuddyWater resurfaced with fresh PowerStats backdoor samples targeting European allied infrastructure. A CVSS 9.8 Cisco Secure Email Gateway zero-day is under active exploitation, CrowdStrike confirmed Iranian wiper attacks hit UAE/Saudi Arabia/Bahrain, and 8 ICS advisories dropped in a single day affecting maritime and power grid systems. No diplomatic de-escalation signals exist - the cyber tempo is accelerating.

I am a
My sector

DevelopmentSignificance
MuddyWater's 39-day silence is over. Five fresh PowerStats backdoor samples appeared Sep 14-16, marking a return to...Consistent with European allied base reconnaissance
Cisco Secure Email Gateway CVE-2026-76461 is being exploited in the wild. Pre-auth SQL injection to root RCE (CVSS 9.8)...Functionally an open door for organizations running Cisco SEG
BANISHED KITTEN's Gulf wiper campaign is confirmed. CrowdStrike validates wiper deployment against UAE, Saudi Arabia, and...Significant geographic expansion from historical US/Israel/Albania targeting
Eight ICS advisories dropped in a single day, affecting Wartsila FOS-Onboard, Schneider SCADAPack x70, Siemens Reyrolle...All directly relevant to energy and maritime operations in the conflict zone
UNC6446/Imperial Kitten refreshed its aerospace phishing campaign with new ScreenConnect delivery infrastructure Sep 16.Active IRGC-linked retooling against defense industrial base
Zero ceasefire or negotiation signals detected.Cyber threat trajectory remains upward

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026US-Iran kinetic conflict begins.
Gulf wipers, UK energy attackApr - Jul 2026BANISHED KITTEN deploys wipers in UAE/KSA/Bahrain; Iran-linked attack shuts down a UK energy facility for 4 days.
Policy response, water systems compromisedAug - Sep 1, 2026UK briefs energy chiefs and proposes supply-chain legislation; CISA discloses 100+ US water systems compromised by Cyber Av3ngers.
Kinetic escalation, zero-day exploitation beginsSep 2-14, 2026Iran strikes Kuwait, Bahrain, Jordan; CVE-2026-76461 added to KEV; MuddyWater's PowerStats samples first created.
Current (Day 200) - convergenceSep 15-16, 2026CrowdStrike confirms BANISHED KITTEN wipers; Sophos confirms Cisco SEG exploitation; 8 ICS advisories published; UNC6446 refreshes...

MuddyWater's 39-day silence was retooling, not retirement. Five fresh PowerStats samples (Sep 14-16) represent a deliberate reversion from ransomware-focused operations (DinDoor/Cactus) to classic espionage - during kinetic escalation, MOIS priorities shift from revenue to intelligence collection.

PowerStats communicates over HTTP to C2...

T1059.001T1071.001T1566.001

CVE-2026-76461 requires no authentication - a crafted email exploits insufficient AsyncOS validation, achieving root command execution. Confirmed active exploitation via CISA KEV plus independent Sophos confirmation.

APT34/OilRig and MuddyWater have documented history exploiting Cisco products. A CVSS 9.8 pre-auth RCE on an email gateway...

T1190T1059T1068

CrowdStrike confirms BANISHED KITTEN's (Cotton Sandstorm, Handala Hack Team) April 2026 wiper attacks against UAE, Saudi Arabia, and Bahrain government/manufacturing were real and destructive - a significant expansion from historical US/Israel/Albania targeting. UAE, Saudi Arabia, and Bahrain all host allied military facilities. Organizations...

T1485T1486T1491.002

Eight ICS advisories in a single day is not routine. Wartsila FOS-Onboard (maritime fleet ops - Strait of Hormuz risk), Schneider SCADAPack x70 (energy/water SCADA), and Siemens Reyrolle 7SR5 (substation protection relays - same class of attack behind the 2015/2016 Ukraine blackouts) are all...

T1190T0890T0831

SPECTRAL KITTEN/Agrius (Rockwell ICS targeting), pro-Iran hacktivist DDoS groups (DieNet, 313 Team, NoName057), and TRACER KITTEN telecom CDR espionage are all conspicuously absent during peak kinetic escalation. In threat intelligence, absence is signal - when actors who should be active go quiet, the most dangerous explanation is usually...

ScenarioProbabilityRationale
MuddyWater escalation from espionage to destructive operations35%PowerStats is reconnaissance tooling, but DinDoor/Cactus capability remains available. Kinetic intensification would trigger the shift...
BANISHED KITTEN new wiper deployment against allied infrastructure45%Gulf expansion confirmed. IO campaign active. Next wave likely targets allied military support infrastructure in Kuwait, Bahrain, or Jordan.
ICS/OT incident in the energy sector30%UK precedent (July 2026), Schneider/Siemens/Wärtsilä vulnerabilities unpatched, SPECTRAL KITTEN silence during peak utility. Attack surface...
Coordinated hacktivist DDoS surge against allied government and financial services55%Absence of DDoS during kinetic exchange is historically anomalous. Expect synchronized campaign within 48–72 hours.
Iranian exploitation of Cisco SEG CVE-2026-76461 against government/defense targets40%Active exploitation confirmed. Iranian actors have documented Cisco exploitation history. Pre-auth RCE on email gateways is a high-value...

IOC Blocking Table:
185.93.89[.]106217.219.162[.]11446.100.94[.]21787.107.68[.]231185.88.177[.]4045.89.60[.]44

Block the above at perimeter firewalls, proxies, and DNS. Hashes: e38e8b6cb12ffb8774aa3359adb7c561041a3bc625465b41f6045075775c82da...

Hunting Hypotheses:
HUNT 01 · T1059.001
Hypothesis 1: MuddyWater PowerStats beaconing
Search for PowerShell processes making HTTP callbacks to unknown external infrastructure. PowerStats uses encoded PowerShell commands and HTTP-based C2. Detection: EDR telemetry for powershell.exe with -enc or -encodedcommand flags spawning network connections. SIEM correlation of PowerShell script block logging (Event ID 4104) with outbound HTTP to uncategorized domains. IOC hashes to block/alert: - e38e8b6cb12ffb8774aa3359adb7c561041a3bc625465b41f6045075775c82da - 3c97340d6aab2a0455c54ec155745eeebd163bd1e4af253c5edd058359360398 - 5860cf61e79a7bf7578f005044ce0a7012b5e7b265de487851c0bfa1150925b7 - e95309ebd6effb7a8d6c92dd937f83639b251d7e326998b32896a035abecc6cb - a0d7e7f16dc3887edded09aafd79292ab6b6896b7f8b05fb5cee766b2fe1656d
HUNT 02 · T1190
Hypothesis 2: Cisco SEG exploitation (CVE-2026-76461)
Monitor Cisco Secure Email Gateway logs for anomalous SQL errors, unexpected process spawning from the email parsing engine, or new root-level processes. Detection: Cisco AsyncOS syslogs for SQL injection patterns. Network monitoring for outbound connections from SEG appliances to unknown infrastructure. File integrity monitoring on SEG filesystem for unauthorized modifications.
HUNT 03 · T1090.003
Hypothesis 3: Iranian anonymization infrastructure
Alert on connections to ASN 213790 ("Limited Network") and known Iranian ISP ASNs (58224, 201691, 209783, 21341). IOC to watchlist: 185.93.89[.]106 (Tor exit node, ASN 213790, confidence 99) Additional Iranian infrastructure IPs to monitor: - 217.219.162[.]114 - 46.100.94[.]217 - 87.107.68[.]231
HUNT 04 · T1485
Hypothesis 4: Wiper pre-staging (BANISHED KITTEN TTPs)
Hunt for indicators of GoneXML, ZeroShred, BiBiWiper, MisleadingAxe, PhantomBlade, or WovenMist malware families. Look for mass file deletion patterns, MBR/VBR modification attempts, or deployment of legitimate remote access tools (NetBird, ZeroTier) used as persistence mechanisms. Detection: Volume shadow copy deletion (vssadmin delete shadows), unusual schtasks or service creation deploying unknown binaries, NetBird or ZeroTier agents appearing on endpoints where they are not sanctioned.
HUNT 05 · T1528
Hypothesis 5: Cloud token theft and OAuth abuse
Monitor for anomalous OAuth token grants, application consent prompts, or SAML assertion manipulation — particularly in Microsoft 365 and Entra ID environments. Detection: Azure AD sign-in logs for impossible travel, new OAuth app registrations, or consent grants to unfamiliar applications. Review NIST IR 8587 guidance for token binding implementation.

Financial Services
SWIFT, Payment Systems
Primary threat
Iranian hacktivist DDoS historically targets banking during kinetic escalation. Current absence of...
Actions
  • Validate DDoS mitigation capacity; review SWIFT/interbank access controls
Energy
Grid Protection, SCADA
Primary threat
Iran already attacked UK energy infrastructure. Schneider SCADAPack x70 and Siemens Reyrolle 7SR5...
Actions
  • Inventory and isolate internet-facing SCADAPack/Reyrolle instances; verify OT/IT segmentation
Healthcare
Building Management, Medical Devices
Primary threats
Secondary but validated target - Cyber Av3ngers compromised 100+ water systems, demonstrating...
Actions
  • Audit Cisco SEG deployments; segment medical device networks from corporate IT
Government
Defense, Foreign Affairs
Primary threats
Primary target for APT42 (nuclear/defense phishing), MuddyWater (PowerStats espionage), and UNC6446...
Actions
  • Block MuddyWater PowerStats hashes; implement NIST IR 8587 token protection for cloud identity
Aviation / Logistics
Maritime, Avionics Supply Chain
Primary threat
UNC6446 refreshed aerospace phishing Sep 16. Maritime logistics through the Strait of Hormuz face...
Actions
  • Assess Wartsila FOS-Onboard fleet-wide; block unauthorized ScreenConnect installations
No sector cards match the selected filters.

Patch or isolate Cisco Secure Email Gateway for CVE-2026-76461...
Incident Responder
Ingest MuddyWater PowerStats hashes into EDR/SIEM; hunt for...
SOC Analyst
Add Iranian ASNs (213790, 58224, 201691, 209783, 21341) to...
SOC Analyst
Activate DDoS monitoring and pre-staged mitigation - absence...
SOC Analyst
No immediate actions for the selected roles.
Patch Schneider SCADAPack x70 and Siemens Reyrolle 7SR5...
ICS / OT
Assess and patch Wartsila FOS-Onboard across maritime fleet...
ICS / OT
Review Siemens Mendix SAML configs and implement NIST IR 8587...
IAM Analyst
Deploy detection rules for BANISHED KITTEN wiper TTPs - VSS...
SOC Analyst
No 7-day actions for the selected roles.
Commission an OT threat hunt for SPECTRAL KITTEN/Agrius...
Threat Hunter
Evaluate wiper resilience - test backup/recovery against...
CISO / Exec
Conduct a tabletop exercise simulating coordinated DDoS, wiper...
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

The Iran cyber threat is not theoretical. A UK energy facility was shut down for four days in July. Over 100 US water systems were compromised in September. Wiper malware hit three Gulf states in April. And this week, MuddyWater is back online with fresh espionage tooling, a critical Cisco email gateway zero-day is being exploited in the wild, and eight new ICS vulnerabilities affect the exact systems that keep power grids running and ships navigating the Strait of Hormuz. The 39-day silence...

1
Patch Cisco SEG today.
2
Hunt for PowerStats today.
3
Harden OT environments and prepare for wiper scenarios today. The threat is not waiting.
No items found.