| Development | Significance |
|---|---|
| CyberAv3ngers campaign expands to 7 U.S. states | Largest Iranian ICS/OT destructive campaign of the conflict — PLC-level manipulation causing service outages at 36+ Minnesota water utilities |
| SPECTRAL KITTEN pivots from destruction to espionage | MOIS-affiliated actor compromised Israeli electrical utility via IIS/MSSQL web shells — covert reconnaissance without destructive payload suggests pre-positioning or battle damage assessment collection |
| Mythic C2 framework adopted by Iranian operators | First confirmed Mythic server on Iranian ASN — deliberate evasion of Cobalt Strike-focused detection signatures |
| SonicWall SMA1000 CVE-2026-15409 (CVSS 10.0) actively exploited | Unauthenticated SSRF chained with code injection for ransomware deployment by INC Ransomware; aligns with Iranian edge-device targeting pattern |
| Iran-nexus GitHub-resilient implants campaign updated | Living-off-trusted-services C2 targeting government and telecom — updated August 11, indicating fresh operational activity |
| Ubiquiti EdgeSwitch pre-auth RCE 0-day for sale ($50K) | ~560 vulnerable hosts in small utility/municipal networks — exactly the infrastructure CyberAv3ngers targets |
| Additional critical CVEs under active exploitation | Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) and JetBrains TeamCity (CVE-2026-63077, CVSS 9.8) added to CISA KEV or actively exploited — broadening the attack surface across energy, healthcare, and CI/CD pipelines |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict initiation | Feb 28, 2026 | U.S.-Iran kinetic conflict begins. |
| Stryker wiper operation | Mar 11, 2026 | Void Manticore/Handala (MOIS) executes the Stryker wiper operation. |
| Covert espionage pivot | Mid-June 2026 | SPECTRAL KITTEN (Agrius/MOIS) compromises an Israeli electrical utility via IIS/MSSQL web shells — reconnaissance without a destructive payload. |
| Multi-state water utility campaign | Jul 26 – Aug 6, 2026 | CyberAv3ngers (IRGC) launches multi-state water utility cyberattacks; 36 Minnesota utilities confirmed compromised by Aug 4; CVE-2026-63077 (TeamCity) added to CISA KEV Aug 5; CSIS publishes analysis of Tehran's evolved cyber operations Aug 6. |
| C2 diversification & fresh activity | Aug 10–11, 2026 | Mythic C2 server confirmed active on Iranian ASN 60631 (Aug 10); SPECTRAL KITTEN profile updated with Israeli utility intrusion details (Aug 10); Iran-nexus GitHub-resilient implants campaign updated (Aug 11). |
| Current (Day 164) | Aug 11, 2026 | Intelligence collection cutoff. Iranian cyber operations have transitioned from pre-positioning to sustained execution. |
Actor: CyberAv3ngers (IRGC-affiliated). Targets: U.S. water treatment facilities across 7+ states. Impact: PLC-level manipulation causing service outages.
The CyberAv3ngers campaign represents a deliberate escalation from their 2023–2024 operations against individual Unitronics PLCs to a coordinated, multi-state disruption campaign. The FBI and EPA have issued a joint alert. The intelligence community assesses Iran as responsible with high confidence, despite political contestation of attribution.
Key characteristics: exploitation of public-facing HMI/PLC interfaces; likely use of default credentials on Unitronics PLCs; PLC process manipulation causing physical service disruption; targeting of small municipal utilities with limited cybersecurity resources.
Critical gap: specific IOCs from the FBI/EPA joint alert have not been publicly released. Organizations should contact WaterISAC or CISA directly for indicator sharing.
Actor: SPECTRAL KITTEN (also tracked as Agrius, Black Shadow, Pink Sandstorm, AMERICIUM, UNC2428) — MOIS-affiliated. Target: Israeli electrical utility. Significance: Behavioral pivot with strategic implications.
SPECTRAL KITTEN historically conducted "lock-and-leak" operations using Apostle ransomware and data leaks via the Black Shadow persona. Their mid-June 2026 intrusion into an Israeli electrical utility shows a fundamentally different approach: web shell deployment, lateral movement, and reconnaissance without destructive payload execution.
This behavioral shift likely indicates one of three scenarios: pre-positioning for a future destructive attack timed to kinetic escalation; battle damage assessment collection providing targeting intelligence to IRGC for kinetic strikes; or a tasking shift from MOIS information operations to IRGC military intelligence support.
Known tooling: IPSecHelper, Apostle, FusionStub, SQLShred, ASPXSpy, Orcus RAT, HellLoader, PetitPotato, Datascout, FlowTunnel.
Vulnerabilities: CVE-2026-15409 — Server-Side Request Forgery (SSRF), CVSS 10.0, unauthenticated; CVE-2026-15410 — code injection, CVSS 7.2, post-authentication (admin).
Exploitation: actively chained by INC Ransomware operators and UTA0533. Affects SMA 6210, 7210, 8200v running platform-hotfix 12.4.3 or 12.5.0.
Iranian nexus: edge device exploitation (SonicWall, Fortinet, Ivanti, Citrix) is the primary initial access vector across all Iranian actor clusters. Pioneer Kitten / Fox Kitten (IRGC contractor) has historically enabled ransomware operations including INC Ransomware affiliates.
Detection indicators: unexpected requests to /api/login, /api/logout, /wsproxy in extraweb_access.log; suspicious hotfix rollback entries in ctrl-service.log; non-legitimate API routes in /var/lib/unit/conf.json.
IOC: 185.7.212[.]83 (ASN 60631, Vandad Vira Hooman, Tehran) — confirmed active Mythic C2 server.
Iranian operators are deliberately diversifying away from Cobalt Strike toward open-source alternatives. Mythic's modular agent architecture (Apollo, Medusa, Poseidon agents) complicates signature-based detection and renders Cobalt Strike-focused hunting rules insufficient.
This mirrors a broader adversary trend but carries specific implications: organizations that invested heavily in Cobalt Strike detection over the past three years now face a detection gap against the same Iranian operators using different tooling.
Four vulnerabilities beyond the SonicWall chain are under active exploitation or newly added to CISA KEV, broadening the attack surface across energy, healthcare, and CI/CD pipelines:
| CVE | CVSS | Product | Status |
|---|---|---|---|
| CVE-2026-15409 | 10.0 | SonicWall SMA1000 | Active exploitation — INC Ransomware |
| CVE-2026-9198 | 9.8 | SonicWall (additional) | Active exploitation |
| CVE-2026-8037 | 9.6 | Progress Kemp LoadMaster | Active exploitation — pre-auth RCE |
| CVE-2026-63077 | 9.8 | JetBrains TeamCity | CISA KEV (added Aug 5) — unauthenticated RCE |
| Prediction | Probability | Timeframe | Rationale |
|---|---|---|---|
| Additional U.S. water utilities report compromises as forensic investigations complete; state count rises from 7 to 10+ | 80% | 1–2 weeks | Forensic lag typical in municipal environments; campaign scope likely larger than currently reported |
| SPECTRAL KITTEN Israeli utility access leveraged for destructive attack or handed to IRGC for kinetic targeting | 60% | 2–6 weeks | Behavioral pivot to espionage on energy infrastructure during active war strongly suggests pre-positioning |
| Ubiquiti EdgeSwitch 0-day purchased and weaponized; buyer profile includes Iranian proxy operators | 55% | 2–4 weeks | $50K price point accessible to state actors; target overlap with CyberAv3ngers victim profile (small utilities) |
| APT42 silence breaks with credential harvesting campaign targeting U.S. government/military personnel | 40% | 1–3 weeks | Operational silence during active war is anomalous for this actor; likely rebuilding infrastructure |
| Void Manticore / Handala resurfaces with destructive wiper operation after 153+ days of silence | 35% | 2–8 weeks | Extended silence assessed as access stockpiling; coordinated destructive strike likely timed to conflict escalation |
| Iranian operators purchase or exploit Ubiquiti 0-day to expand water/utility targeting | 45% | 3–6 weeks | Natural extension of CyberAv3ngers targeting pattern against under-resourced municipal infrastructure |
Iranian operators are shifting from Cobalt Strike to Mythic. Deploy detection for: default Mythic HTTP callback paths (/api/v1.0/agent_message and custom profiles), Apollo/Medusa/Poseidon agent PE characteristics, Mythic teamserver default TLS certificate fingerprints, and outbound HTTPS to ASN 60631 (Vandad Vira Hooman), ASN 213790 (Limited Network), ASN 51396 (Pfcloud).
Monitor for: anomalous requests to /api/login, /api/logout, /wsproxy in extraweb_access.log; hotfix rollback events in ctrl-service.log (attackers rolling back patches); non-standard API routes appearing in /var/lib/unit/conf.json; and post-exploitation credential dumping (T1003) following SMA compromise.
Hunt on IIS and MSSQL servers, particularly in energy sector: ASPXSpy web shells on IIS servers, IPSecHelper and FlowTunnel persistence mechanisms, co-located IIS + MSSQL servers with unexpected outbound connections, and reconnaissance commands (T1083) from web shell processes.
For organizations with OT environments: monitor for default credential usage on Unitronics PLCs; alert on any external access to PLC programming ports (historically port 20256); monitor HMI/SCADA web interfaces for authentication anomalies; and detect PLC logic changes outside maintenance windows.
Iranian actors are using GitHub and M365 calendar for C2 resilience: monitor for unusual GitHub API calls from non-developer endpoints; alert on M365 calendar items with encoded data in body/subject fields; and baseline legitimate GitHub/cloud service usage to detect anomalous patterns.
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Audit all SonicWall SMA appliances immediately; patch CVE-2026-15409/15410
- Review VPN access logs for anomalous admin-level API calls
- Ensure ransomware playbooks account for Iranian-nexus actors who sell access to ransomware affiliates
- Validate backup integrity and test restoration procedures for core banking systems
- Hunt for ASPXSpy, IPSecHelper, and FlowTunnel on all IIS/MSSQL servers in OT-adjacent networks
- Audit Unitronics, ABB Zenon, Schneider, and Siemens PLC access controls — eliminate default credentials
- Segment IT/OT boundaries; verify no direct internet exposure of SCADA/HMI interfaces
- Coordinate with E-ISAC for sector-specific threat sharing
- Emergency patch all SonicWall SMA1000 appliances; verify no compromise indicators in logs
- Audit TeamCity instances (CVE-2026-63077) — CI/CD compromise enables supply chain attacks on medical device software
- Review Progress Kemp LoadMaster deployments (CVE-2026-8037) — common in healthcare load balancing
- Activate crisis communication plans for ransomware scenarios
- Enforce phishing-resistant MFA (FIDO2/hardware keys) for all personnel with access to classified or sensitive systems
- Hunt for GitHub-based C2 channels — unusual GitHub API traffic from non-development systems
- Review and harden M365 tenant configurations against OAuth abuse
- Prepare for wiper scenario: validate offline backup integrity, test bare-metal recovery
- Review CISA ICS advisories for CPDLC systems; assess exposure and implement mitigations
- Audit all TeamCity and CI/CD pipeline configurations; pin dependencies to commit SHAs
- Verify SonicWall and LoadMaster appliances in logistics network segments are patched
- Coordinate with A-ISAC for aviation-specific threat intelligence
185.7.212[.]83 (Mythic) and 217.60.241[.]17 (Cobalt Strike) at all perimeter firewalls and proxy systems.extraweb_access.log and ctrl-service.log for compromise indicators.The U.S.-Iran conflict has been active for 164 days. Iranian cyber operations have transitioned from pre-positioning to sustained execution. The CyberAv3ngers water campaign, SPECTRAL KITTEN's espionage pivot, and the active exploitation of CVSS 10.0 edge device vulnerabilities are not isolated events — they are components of a coordinated national cyber campaign operating under wartime authorities. The traditional assumption that "they won't hit us" no longer holds. Iranian operators are targeting small municipal utilities, not just Fortune 500 companies. They are exploiting the same SonicWall and LoadMaster appliances that sit in your DMZ. They are shifting to open-source C2 frameworks specifically to evade the detection rules you deployed last year.