TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War on American Water:

Seven States Hit as IRGC Infrastructure Goes Dark Before the Storm

HIGH. Five months into the Iran conflict — Day 157 since February 28, 2026 — what began as isolated PLC manipulation at a single Pennsylvania water authority in 2023 has metastasized into a coordinated campaign striking municipal water systems across seven U.S. states in a single week. Simultaneously, Iranian APT infrastructure — Pioneer Kitten, Cavern Manticore — is being quietly refreshed with zero corresponding campaign activity: the digital equivalent of reloading before the next volley.

I am a
My sector

DateDevelopmentSignificance
2026-07-31Scale confirmation — the water system campaign expanded from 30+ Minnesota systems (July 26–27) to seven U.S. statesThe largest confirmed Iranian ICS operation against U.S. soil ever documented
2026-08-01Infrastructure refresh without campaign reporting — Pioneer Kitten (UNC757), Iran's most prolific initial access broker, updated its operational infrastructure with zero corresponding campaign activityHistorically, this pattern precedes new exploitation waves within 14 days
2026-08-03 – 2026-08-04New critical vulnerabilities in the kill chain — CVE-2026-18577 (N-able N-central authentication bypass) actively exploited; CVE-2026-18574 (Check Point Security Management takeover) discoveredBoth align perfectly with documented Iranian TTPs — Check Point gives attackers the ability to rewrite firewall policies
2026-08-02 – 2026-08-04Cobalt Strike DNS tunneling and Remcos RAT C2 on Iranian hosts — fresh C2 using port 53 DNS tunneling (a MuddyWater/OilRig signature) went active; Remcos RAT C2 on ASN 213790 (Tehran) and ASN 44436 active since August 2Enables credential theft and surveillance operations
2026-07-28Cavern Manticore (MOIS) posture refresh — the MOIS-affiliated destructive capability holder updated its profile without a corresponding campaign announcementConsistent with preparation for a follow-on destructive operation
2026-08-01 to 2026-08-03APT42 (IRGC-IO) campaigns actively updated — BELLACIAO and SHELLAFEL campaigns updated with continued targeting of energy, government, and healthcare sectorsCoordinated operational tempo across IRGC cyber elements
2026-08-04BINDCLOAK enters the Middle East energy space — a previously undocumented East Asia-linked malware family (BINDCLOAK/TELESHIM/MIXEDKEY) is actively targeting Middle East government and energy entitiesCreates misattribution risk and introduces token manipulation TTPs into the regional threat landscape
This weekAI-autonomous offensive operations are no longer theoretical — a documented campaign using DeepSeek/Hermes Agent demonstrated fully autonomous target selection and exploitationAttributed to a Chinese actor, but the open-source tooling is immediately transferable to Iranian operators

PhaseTimeframeCyber Activity
Conflict begins2026-02-28Day 0 — cyber operations commence as an asymmetric tool
Initial ICS disruption2026-07-26 – 2026-07-2930+ Minnesota water systems attacked; Cavern Manticore (MOIS) profile refreshed; CyberAv3ngers confirmed in coordinated PLC attacks
Scale confirmation & advisories2026-07-30 – 2026-07-31CISA emergency PLC advisory plus 3 ICS advisories (Schneider IGSS, Toptech fuel terminals, Mitsubishi CC-Link); campaign confirmed across 7 U.S. states with FBI/EPA joint warning
Silent reload & espionage refresh2026-08-01 – 2026-08-03Pioneer Kitten (UNC757) infrastructure silently updated; APT42 BELLACIAO/SHELLAFEL campaigns updated; fresh APT IOCs on ASN 213790; CVE-2026-18577 added to CISA KEV
Current (Day 157)2026-08-04Cobalt Strike DNS C2 goes live on Iranian hosts; CVE-2026-18574 Check Point management bypass disclosed; BINDCLOAK backdoor targets Middle East energy/government

Actor: CyberAv3ngers (IRGC-affiliated proxy). Targets: Municipal water and wastewater systems across 7 U.S. states. Technique: Exploitation of internet-exposed PLCs (Rockwell Allen-Bradley, Siemens S7-1200) using default credentials and known vulnerabilities.

The attack methodology is deliberately unsophisticated — and that's the point. By targeting the weakest links in America's water infrastructure (4,148 internet-exposed EtherNet/IP hosts, 70%+ in the U.S.), CyberAv3ngers demonstrates that catastrophic disruption doesn't require zero-days. It requires neglect.

The campaign forced boil-water notices, disconnected PLCs from SCADA networks, and modified operational parameters — crossing the line from espionage into physical-world impact. This is coercive signaling: Iran demonstrating it can touch American communities at the tap.

T1190T1078

Actor: Pioneer Kitten / Fox Kitten / UNC757 (IRGC-linked). Status: Infrastructure updated August 1 — no visible campaign. Historical pattern: Silent updates precede new exploitation waves by 7–14 days.

Pioneer Kitten is Iran's premier initial access broker, specializing in exploiting VPN appliances (Fortinet, Cisco, Ivanti, Check Point) and selling access to ransomware affiliates. Their operational model — exploit perimeter devices, establish persistence, monetize or hand off to destructive operators — makes them the tip of the spear for any escalation.

The August 1 profile update without corresponding campaign reporting is a pre-positioning indicator. Combined with CVE-2026-18574 (Check Point management takeover) and CVE-2026-18577 (N-able RMM bypass), Pioneer Kitten has fresh ammunition.

T1133T1078.001

Malware: Remcos RAT, Cobalt Strike BEACON. Infrastructure: ASN 213790 ("Limited Network," Tehran), ASN 44436 (Toosee Ertebatat Damavand), ASN 51396 (Pfcloud UG).

Three distinct infrastructure clusters are active: Remcos RAT C2 on port 8279 — commodity RAT used for credential theft and surveillance; Cobalt Strike on port 443 — standard HTTPS beaconing; Cobalt Strike on port 53 — DNS tunneling pattern characteristic of MuddyWater (MOIS) and OilRig, designed to evade network monitoring by disguising C2 as DNS traffic.

T1219T1571T1071.004T1572

Vulnerability: CVE-2026-18577 (CVSS 8.2) — Authentication bypass in N-able N-central. Status: Actively exploited; CISA KEV as of August 3. Observed TTPs: Admin takeover → Take Control feature abuse → Cloudflared tunnel persistence → VPN anonymization (Mullvad/NordVPN exit nodes).

This vulnerability is particularly dangerous because N-able N-central is deployed by managed service providers (MSPs) serving government and critical infrastructure clients. A single compromised N-central instance provides access to hundreds of managed endpoints. This is precisely the supply-chain access model that Pioneer Kitten has exploited repeatedly.

T1190T1572T1090

Vulnerability: CVE-2026-18574 — Authentication bypass in Check Point Security Management Server. Affected versions: R80 through R82.10. Status: No active exploitation confirmed — but impact is catastrophic.

An attacker exploiting this vulnerability gains the ability to execute arbitrary commands on the Security Management Server, effectively taking control of all firewall policies, gateway configurations, and admin credentials across the enterprise. For organizations using Check Point as their primary perimeter defense (common across Israeli government and Middle East critical infrastructure), this is an existential vulnerability.

T1190T1068

Actor: APT42 / Charming Kitten (IRGC-IO). Campaigns: BELLACIAO (webshell-based persistence), SHELLAFEL (credential harvesting). Targets: Energy sector, government agencies, healthcare organizations. Status: Campaigns actively updated August 1–3.

APT42 continues its persistent espionage mandate against high-value targets aligned with IRGC-IO collection priorities. The simultaneous update of both BELLACIAO and SHELLAFEL infrastructure during the water campaign period suggests coordinated operational tempo across IRGC cyber elements — espionage and disruption running in parallel.

Actor: Cavern Manticore (MOIS-affiliated). Status: Profile updated July 28 — no active campaign observed. Significance: Cavern Manticore is assessed to hold destructive wiper and data-destruction capabilities. A posture refresh without campaign activity mirrors the Pioneer Kitten pattern and suggests preparation rather than current operations.

Malware: BINDCLOAK, TELESHIM, MIXEDKEY (previously undocumented). Attribution: East Asia-linked (likely Chinese). Targets: Middle East government entities in the energy sector. Delivery: ISO files → multi-stage loader chain → reflective DLL injection.

While not Iranian, BINDCLOAK matters for two reasons: it targets the same Middle East energy/government space where Iranian APTs operate, creating potential for misattribution, and its token manipulation techniques (Windows access token theft for privilege escalation) represent a TTP that Iranian actors could adopt.

T1553.005T1134

ScenarioProbabilityTimeframeIndicators to Watch
Official USG attribution of water attacks to Iranian proxy70%5 daysState Department/OFAC statements; new sanctions designations
Pioneer Kitten launches new VPN/perimeter exploitation campaign60%14 daysNew Fortinet/Ivanti/Check Point exploitation in the wild; access-for-sale on dark web forums
Retaliatory Iranian cyber operation against Israeli critical infrastructure40%21 daysEscalation in diplomatic tensions; IRGC public statements; hacktivist activation
CVE-2026-18574 exploitation in the wild55%14 daysCheck Point advisory updates; Shodan/Censys scans for exposed management interfaces
Iranian adoption of AI-autonomous scanning/exploitation frameworks35%60 daysOpen-source LLM integration with vulnerability scanners; accelerated reconnaissance tempo
BINDCLOAK campaign expansion with potential Iran misattribution25%30 daysNew BINDCLOAK samples; ME energy sector incidents with ambiguous attribution

PriorityWhat to DetectATT&CK IDDetection Logic
CRITICALPLC communication anomaliesT1565.002Monitor for unauthorized writes to PLC registers; alert on parameter changes outside maintenance windows
CRITICALN-able N-central auth bypass attemptsT1190Monitor N-central authentication logs for admin session creation without valid credential exchange
HIGHCobalt Strike DNS tunnelingT1071.004, T1572Alert on DNS queries to Iranian ASNs (44436, 51396, 213790); detect high-entropy DNS TXT records; monitor port 53 traffic volume anomalies
HIGHCloudflared tunnel establishmentT1572Detect cloudflared service installation; monitor for outbound connections to Cloudflare Tunnel endpoints from non-standard hosts
HIGHRemcos RAT C2 beaconingT1219, T1571Monitor for connections on port 8279; detect Remcos registry persistence keys; alert on process injection from temp directories
MEDIUMToken manipulation / privilege escalationT1134.001, T1134.002Monitor CreateProcessWithToken and ImpersonateLoggedOnUser API calls from non-system processes
MEDIUMCheck Point management plane accessT1190, T1068Audit SmartConsole login events; alert on policy changes from unrecognized source IPs; monitor for new admin account creation
MEDIUMVPN exit node anonymizationT1090Flag authentication from known VPN provider IP ranges (Mullvad, NordVPN) to administrative interfaces
IOC Blocking Table:
77.90.185[.]24877.90.185[.]28172.94.9[.]7462.60.226[.]42217.60.241[.]1787.107.191[.]39173.249.252[.]20087.249.138[.]3437.19.210[.]3268.235.46[.]214

Block the above at perimeter firewalls, proxies, and DNS. Hashes: 5bb1dcbaab8e3231889700c38a21e8ea. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1133
Pioneer Kitten pre-positioned access exists in our environment
Hunt for: unauthorized VPN tunnel configurations on Fortinet/Cisco/Ivanti devices; SSH keys added outside change windows; scheduled tasks calling back to Iranian ASN ranges. Technique: T1133 (External Remote Services), T1078.001 (Default Accounts).
HUNT 02 · T1036.005
N-able N-central has been compromised via CVE-2026-18577
Hunt for: svchost.exe in user Documents folders (masquerading); Cloudflared service registrations; Take Control sessions initiated from non-standard IPs; admin account creation timestamps that don't correlate with legitimate provisioning. Technique: T1036.005 (Masquerading: Match Legitimate Name), T1543.003 (Create or Modify System Process: Windows Service).
HUNT 03 · T1071.004
DNS-based C2 is active in our network
Hunt for: unusually long DNS queries (>50 characters); high volume of TXT record requests to single domains; DNS traffic to non-corporate resolvers; beaconing patterns in DNS query timing. Technique: T1071.004 (DNS), T1568.002 (Dynamic Resolution: Domain Generation Algorithms).
HUNT 04 · T1190
OT/ICS systems have unauthorized internet exposure
Hunt for: Rockwell Allen-Bradley, Siemens S7-1200, or Schneider Electric devices with routes to public internet; PLC firmware versions with known default credentials; engineering workstation connections from non-allowlisted IPs. Technique: T1190, T1078 (Default Accounts).

Financial Services
MSP-Managed Financial Institutions
Primary threat
Pioneer Kitten selling access to ransomware operators; N-able N-central compromise of MSPs serving financial institutions
Actions
  • Audit all third-party RMM tools (N-able, ConnectWise, SimpleHelp) for CVE-2026-18577 exposure; verify MSP access is MFA-enforced and session-limited
  • Review Check Point Security Management configurations for CVE-2026-18574; restrict SmartConsole access to hardened jump servers only
  • Demand attestation from MSP providers that N-central instances are patched to version 2026.3 HF1
Energy
SCADA/DCS, Fuel Terminal Automation
Primary threat
CyberAv3ngers ICS disruption expanding from water to energy; BINDCLOAK espionage targeting ME energy entities; Schneider Electric IGSS and Toptech fuel terminal vulnerabilities
Actions
  • Verify air-gap integrity of all SCADA/DCS systems; audit Schneider Electric IGSS deployments for CISA advisory compliance; confirm Toptech fuel terminal automation systems are segmented
  • Deploy OT-specific network monitoring (Claroty, Dragos, Nozomi) if not already present; establish baseline PLC communication patterns for anomaly detection
  • Brief board on Iranian ICS targeting escalation; ensure OT incident response retainer is current and tested
Healthcare
Clinical Systems, Biomedical Devices
Primary threat
APT42 (IRGC-IO) BELLACIAO/SHELLAFEL campaigns actively targeting healthcare; ransomware via Pioneer Kitten access brokering
Actions
  • Verify all internet-facing clinical systems (patient portals, telehealth platforms) are patched for known VPN/auth bypass vulnerabilities; audit for default credentials on medical device network interfaces
  • Segment biomedical device networks from corporate IT; ensure backup systems for EHR are tested and isolated from network-accessible ransomware paths
  • Validate cyber insurance coverage explicitly includes nation-state attacks; pre-position patient diversion protocols
Government
Full-Spectrum Targeting
Primary threats
Full spectrum — APT42 (IRGC-IO) espionage, CyberAv3ngers ICS disruption, Pioneer Kitten perimeter exploitation, Check Point management plane compromise, Cavern Manticore (MOIS) destructive capability on standby
Actions
  • Emergency audit of all Check Point Security Management Servers for CVE-2026-18574 exposure; verify no management interfaces are reachable from untrusted networks; patch N-able N-central instances serving government endpoints
  • Conduct threat hunt for Pioneer Kitten persistence artifacts (unauthorized SSH keys, VPN tunnel configurations, scheduled tasks to Iranian IP ranges); review DNS logs for tunneling indicators
  • Activate CISA Shields Up protocols; ensure continuity of operations plans account for simultaneous IT and OT compromise; coordinate with sector ISACs on water system attack indicators
Aviation / Logistics
Fleet Management, Logistics Chain
Primary threat
Supply chain compromise via RMM tools; Pioneer Kitten access brokering to ransomware operators targeting logistics disruption
Actions
  • Inventory all remote management tools across the fleet management and logistics chain; verify MFA on all administrative access to scheduling, cargo, and flight operations systems
  • Assess exposure to N-able N-central (CVE-2026-18577) across third-party maintenance providers; review Fortinet/Ivanti VPN configurations for Pioneer Kitten exploitation indicators
  • Engage third-party logistics and maintenance providers for security attestation; ensure operational resilience plans account for IT system unavailability during peak operations

Disconnect all internet-exposed PLCs (Rockwell Allen-Bradley, Siemens S7-1200, Schneider Electric) — verify via Shodan/Censys scan of your public IP ranges.
ICS / OT
Patch N-able N-central to version 2026.3 HF1 — search for svchost.exe in user Documents folders and Cloudflared service registrations as compromise indicators.
Incident Responder
Block confirmed C2 infrastructure at perimeter firewalls: 77.90.185[.]248, 77.90.185[.]28, 172.94.9[.]74, 62.60.226[.]42, 217.60.241[.]17, 87.107.191[.]39, 173.249.252[.]200, 68.235.46[.]214.
SOC Analyst
Restrict Check Point SmartConsole access to named admin IPs only — remove any "Any" entries from Trusted Clients configuration pending CVE-2026-18574 patch.
SOC Analyst
Activate enhanced monitoring for DNS tunneling — alert on DNS traffic to ASNs 44436, 51396, 213790; flag high-entropy TXT queries.
SOC Analyst
Pre-position external IR retainer activation — ensure OT-capable responders are on standby.
Incident ResponderCISO / Exec
No immediate actions for the selected roles.
Deploy Check Point hotfix for CVE-2026-18574 (Jumbo Hotfix Accumulator per version).
Incident Responder
Conduct Pioneer Kitten threat hunt — search for unauthorized SSH keys, VPN tunnel configs, and scheduled tasks calling Iranian IP ranges across all Fortinet/Cisco/Ivanti devices.
Threat Hunter
Audit MSP access controls — demand CVE-2026-18577 patch attestation from all managed service providers; enforce session time limits and MFA on all RMM connections.
CISO / Exec
Establish OT network baselines — deploy passive monitoring on ICS networks to detect PLC communication anomalies and unauthorized engineering workstation connections.
ICS / OT
Review DNS security architecture — ensure all endpoints use corporate DNS resolvers; deploy DNS logging at the resolver level to enable tunneling detection.
SOC Analyst
Brief the board on Iranian ICS escalation — this is the most significant nation-state OT campaign against U.S. infrastructure since Colonial Pipeline.
CISO / Exec
Coordinate with sector ISAC on water system attack indicators and defensive measures.
Threat HunterCISO / Exec
Prepare public communications template for potential ICS incident disclosure.
CISO / Exec
No 7-day actions for the selected roles.
Commission AI-augmented offensive assessment — model how autonomous scanning agents could discover your exposed VPN/RMM instances faster than current patch cycles.
CISO / Exec
Develop BINDCLOAK-style token manipulation detection — deploy monitoring for CreateProcessWithToken/ImpersonateLoggedOnUser API calls from non-standard processes.
Threat Hunter
Tabletop exercise: simultaneous IT + OT compromise — scenario: Pioneer Kitten sells VPN access while CyberAv3ngers hits water/energy OT in parallel.
CISO / ExecIncident Responder
Evaluate OT-specific NDR deployment (Claroty, Dragos, Nozomi) for ICS environments lacking visibility.
ICS / OT
Reassess cyber insurance — confirm policy explicitly covers nation-state attacks and ICS/OT disruption scenarios.
CISO / Exec
Validate continuity of operations plans for scenarios where both IT and OT are simultaneously compromised.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

We are 157 days into the Iran conflict, and the cyber dimension has moved from espionage and pre-positioning into active disruption of American critical infrastructure. The seven-state water system campaign is not an isolated incident — it is a strategic signal from the IRGC that U.S. civilian infrastructure is within reach. What makes the current moment particularly dangerous is the convergence of three factors: active operations (CyberAv3ngers is hitting water systems right now), silent reloading (Pioneer Kitten and Cavern Manticore are refreshing infrastructure without visible campaigns, the hallmark of preparation for the next wave), and fresh ammunition (CVE-2026-18577 and CVE-2026-18574 give Iranian operators new paths into networks that may have hardened against their previous techniques). The window between Pioneer Kitten's silent infrastructure update (August 1) and their historical pattern of launching new campaigns (7–14 days) puts us in a critical decision period.

1
Have you disconnected every internet-exposed PLC? Shodan/Censys scans of your own public IP ranges will tell you if you're already exposed.
2
Is your N-able N-central instance patched to 2026.3 HF1? A single compromised console provides access to hundreds of managed endpoints.
3
Have you restricted Check Point SmartConsole access? CVE-2026-18574 gives attackers the ability to rewrite every firewall policy you have — no exploitation confirmed yet, but the impact is catastrophic.
No items found.