TLP:GREEN  ·  Iran / Israel Conflict
Iran's Cyber War on U.S. Water Systems Has Entered a New Phase:

What CISOs Must Do Now

HIGH. We are now 158 days into an escalating Iranian cyber conflict, and the threat landscape has shifted decisively. What began as isolated intrusions against individual water utilities in late July has been confirmed by the FBI and EPA as a coordinated campaign spanning at least seven U.S. states — the largest confirmed Iranian ICS/OT operation against American soil to date. Iranian C2 infrastructure is expanding at a pace of one new node every 48–72 hours, critical vulnerabilities in AI platforms and RMM tools are under active exploitation, and the conspicuous absence of destructive wiper malware during this escalation may be the most dangerous signal of all.

I am a
My sector

DevelopmentSignificance
FBI/EPA joint advisory confirms Iranian-linked cyberattacks on water systems in 7 U.S. statesLargest confirmed Iranian ICS operation on U.S. soil; utilities forced to manual operations
New Iranian C2 node (77.90.185[.]248) provisioned on ASN213790 (Tehran)Active infrastructure expansion — 3 high-confidence APT IPs on this ASN in 7 days
CVE-2026-9198 (IBM Langflow, CVSS 9.8) added to CISA KEVUnauthenticated RCE on AI/LLM orchestration platforms — no exploit complexity required
CVE-2026-18577 (N-able N-central, CVSS 8.1) — second KEV in 3 daysRMM platform auth bypass enables MSP supply chain compromise; patch was incomplete
CISA ICS advisories for Schneider IGSS, Toptech petroleum systems, libiec61850Expanded OT attack surface directly aligned with Iranian targeting patterns
APT42 (IRGC-IO) updates BELLACIAO/SHELLAFEL espionage campaignsActive collection operations against energy, government, and healthcare sectors confirmed Aug 1–3
MuddyWater (MOIS) operational silence enters Day 5+Historically precedes retooling and new campaign launch within 14 days
No wiper deployment despite ICS escalationBreaks historical Iranian doctrine — signals either restraint or preparation for larger strike

PhaseTimeframeCyber Activity
Conflict begins2026-02-28Day 0 — Iran-related cyber conflict escalation begins
Initial ICS disruption2026-07-26 – 2026-07-28CyberAv3ngers attacks 30+ Minnesota water systems; Cavern Manticore (MOIS) updates destructive posture with no announced operations
Infrastructure build-out & scale confirmation2026-07-30 – 2026-07-31ASN213790 C2 node goes active (confidence 97%); MuddyWater (MOIS) last confirmed operational activity; FBI/EPA confirm water attacks expanded to 7 states
Silent reload & espionage tempo2026-08-01 – 2026-08-03Pioneer Kitten refreshes infrastructure; APT42 updates BELLACIAO/SHELLAFEL; new C2 node provisioned on ASN213790; Remcos RAT and Cobalt Strike DNS tunneling active; CVE-2026-18577 added to CISA KEV; MuddyWater silence formally noted (Day 4)
Current (Day 158)2026-08-04 – 2026-08-05CVE-2026-9198 (Langflow) added to CISA KEV; UNC815 (Iranian, fintech/telecom-focused) profile updated — possible new campaign activation

Actor: CyberAv3ngers (IRGC-affiliated proxy). Targets: Municipal water and wastewater systems across Michigan, Minnesota, and at least 5 additional states. TTPs: Exploitation of internet-exposed Unitronics PLCs using default credentials (T1078), PLC logic modification (T1565.001), forcing utilities to manual operations (T1489).

This campaign represents a qualitative escalation. CyberAv3ngers has moved from opportunistic single-utility attacks (2023 Aliquippa, PA) to coordinated multi-state operations. The FBI/EPA joint advisory confirms this is not isolated criminal activity — it is a state-directed campaign against U.S. critical infrastructure.

The wiper question: Iranian operational doctrine since October 2023 has paired ICS disruption with destructive wiper deployment (BiBiWiper, ZeroShred) against allied targets within 48–72 hours. We are now 9+ days into this campaign with no wiper observed. Two interpretations exist: a restraint hypothesis (Iran is deliberately staying below the destructive threshold to maintain plausible deniability through its proxy structure) or an escalation hypothesis (destructive capability is being held in reserve for a larger trigger event, and the water campaign is pre-positioning). Both interpretations demand heightened defensive posture.

T1078T1565.001T1489

Actor: Pioneer Kitten (UNC757, Fox Kitten, IRGC-linked). Infrastructure: ASN213790 ("Limited Network", Tehran) — now hosting 3 confirmed high-confidence APT IPs.

Pioneer Kitten's infrastructure refresh on August 1 — without corresponding campaign activity — matches a historical pattern: silent infrastructure provisioning precedes new exploitation waves within 14 days. This actor has a documented history of operating as an initial access broker, selling footholds to ransomware affiliates (previously ALPHV/BlackCat, now assessed Qilin).

The convergence of Pioneer Kitten infrastructure expansion with the CyberAv3ngers water campaign on overlapping ASN infrastructure suggests possible operational coordination between IRGC units.

T1071T1571T1572

Vulnerability: IBM Langflow versions 1.0.0–1.10.0. CVSS: 9.8 (Critical). Exploit chain: /api/v1/auto_login mints SUPERUSER tokens to any network caller → /api/v1/validate/code executes arbitrary Python via exec(). Status: CISA KEV (active exploitation confirmed).

This is a trivial-to-exploit, unauthenticated RCE on AI/LLM orchestration platforms increasingly deployed in enterprise environments. The attack chain requires zero authentication and zero user interaction. Any Langflow instance exposed to an untrusted network is fully compromised.

This vulnerability is particularly concerning in the Iranian context: APT42 (IRGC-IO) and MuddyWater (MOIS) have demonstrated increasing interest in cloud and AI infrastructure as collection targets, and the OAuth-like token-minting mechanism aligns with documented Iranian exploitation patterns.

T1190T1059.006

Vulnerability: N-able N-central ≤ 2026.3.1 (authentication bypass → account takeover). CVSS: 8.1 (High). Context: This is an incomplete patch for CVE-2026-18556 (CVSS 7.4) — meaning organizations that patched the first vulnerability remain exposed.

N-able N-central is widely deployed by Managed Service Providers (MSPs). Compromise of an RMM platform provides attackers with trusted access to every downstream client (T1199 — Trusted Relationship). Pioneer Kitten has historically exploited VPN and remote access tools as initial access vectors; RMM platforms represent the same attack pattern at MSP scale.

T1199T1190T1078T1219

Actor: MuddyWater (affiliated with MOIS — Ministry of Intelligence and Security). Status: Operational silence since approximately July 30–31; intel profile updated August 3 to formally note the absence of activity.

MuddyWater typically operates at a weekly cadence of phishing, credential harvesting, and PowerShell/DotNET loader deployment. A silence of 5+ days — confirmed as of this writing — has historically preceded retooling events followed by new campaign launches within 14 days. The August 3 profile update reflects the intelligence community's assessment of this silence, not new MuddyWater activity. Defenders should treat this as a warning indicator, not a stand-down signal.

UNC815 — an Iranian-origin actor targeting financial services, technology, telecommunications, and entertainment — received a profile update on August 5. This targeting profile is atypical for Iranian groups (which traditionally focus on government, energy, and defense). This may represent a new MOIS collection priority or a financial-crime crossover unit. Monitoring is warranted.

ScenarioProbabilityTimeframeBasis
Water ICS campaign expands to additional states; FBI/CISA releases technical IOCs with direct CyberAv3ngers attribution70%72 hoursCampaign trajectory, FBI/EPA advisory language, media reporting cadence
Wiper deployment (BiBiWiper/ZeroShred) against Israeli or allied targets40%72 hoursHistorical 48–72hr lag between ICS disruption and destructive ops; currently overdue
MuddyWater (MOIS) resurfaces with new tooling variant after operational silence25%14 days5+ days of silence historically precedes retooling; operational silence began ~Jul 30–31
Pioneer Kitten launches new exploitation wave leveraging refreshed infrastructure60%14 daysHistorical pattern: infrastructure refresh → campaign within 14 days
CVE-2026-9198 (Langflow) exploited by Iranian actors against enterprise AI deployments35%30 daysAligns with PIR-006 trend; trivial exploit complexity; Iranian interest in cloud/AI
N-central CVE-2026-18577 used for MSP supply chain compromise50%14 daysKEV listing confirms active exploitation; RMM = high-value initial access

1. Iranian C2 Infrastructure Monitoring:

Hunt for any network connections to ASN213790 ("Limited Network") and ASN214192 ("Milad Ahadpour"), both Tehran-based and hosting confirmed APT infrastructure. Hunting hypothesis: "Are any internal hosts communicating with Iranian ASNs 213790, 214192, or 42337 on any port?" Detection: Aggregate alerting on any connection to/from these ASNs — treat as high-priority. DNS tunneling detection (unusually long subdomain queries, high query volume to single domains) is critical given confirmed Cobalt Strike DNS tunneling on these networks.

2. Langflow Exploitation Attempts:

Hunting hypothesis: "Are there any HTTP requests to /api/v1/auto_login or /api/v1/validate/code endpoints from external sources?" Detection: WAF rules blocking unauthenticated access to these endpoints; monitor for exec() patterns in application logs; alert on SUPERUSER token creation events outside normal admin activity.

3. N-central Authentication Bypass:

Hunting hypothesis: "Are there authentication events in N-central that bypass normal login flow, or new admin accounts created without corresponding helpdesk tickets?" Detection: Monitor N-central audit logs for account creation/modification anomalies; alert on RMM agent deployment to hosts not in approved inventory.

4. ICS/SCADA Anomaly Detection:

Hunting hypothesis: "Are there PLC logic changes, setpoint modifications, or HMI access events outside maintenance windows?" Detection: Monitor Unitronics, Schneider Electric IGSS, and Toptech systems for unauthorized configuration changes; alert on any internet-facing SCADA/HMI access.

5. Wiper Pre-Indicators:

Hunting hypothesis: "Are there any processes attempting to overwrite MBR/VBR, delete shadow copies, or disable recovery services?" Detection: Monitor for vssadmin delete shadows, bcdedit /set {default} recoveryenabled No, and raw disk write operations from non-system processes. Alert on any BiBiWiper, ZeroShred, or GoneXML hash submissions to sandbox platforms.

ThreatATT&CK
1. Iranian C2 Infrastructure MonitoringT1071 T1571 T1572
2. Langflow Exploitation AttemptsT1190 T1059.006
3. N-central Authentication BypassT1190 T1078 T1219
4. ICS/SCADA Anomaly DetectionT1565.001 T1489
5. Wiper Pre-IndicatorsT1485 T1561 T1490
IOC Blocking Table:
77.90.185[.]24877.90.185[.]28185.93.89[.]7594.183.240[.]652.188.214[.]142

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Financial Services
New Iranian Targeting Vector
Primary threat
UNC815's emergence with financial services targeting represents a new Iranian threat vector for this sector. Pioneer Kitten's history as an initial access broker means compromised credentials from any sector may be sold to ransomware operators targeting financial institutions
Actions
  • Monitor for credential stuffing from Iranian IP ranges
  • Review all RMM tool access (N-central exposure is critical for MSP-served financial institutions)
  • Watch for unusual OAuth token generation, lateral movement from MSP-connected segments, and anomalous transaction system access
Energy
OT/SCADA Exposure
Primary threat
The Toptech petroleum loading system advisories and Schneider Electric IGSS vulnerabilities directly threaten energy sector OT environments. Iranian actors have demonstrated sustained interest in energy infrastructure (APT42 BELLACIAO/SHELLAFEL campaigns updated August 1–3)
Actions
  • Immediate audit of Toptech RCU II+/Multiload II+ and Schneider IGSS deployments
  • Verify network segmentation between IT and OT
  • Patch libiec61850 in substation environments
  • Watch for unauthorized PLC/RTU configuration changes and anomalous IEC 61850 protocol traffic
Healthcare
MSP-Managed Clinical Systems
Primary threat
APT42's (IRGC-IO) SHELLAFEL campaign explicitly targets healthcare. The sector's reliance on managed service providers makes the N-central vulnerability (CVE-2026-18577) particularly dangerous — a compromised MSP provides access to hospital networks
Actions
  • Verify MSP RMM tool versions; ensure N-central is patched to 2026.3 HF1
  • Segment MSP access from clinical systems
  • Watch for RMM agent deployment anomalies and lateral movement from administrative segments to clinical networks
Government
Primary Espionage & Retaliation Target
Primary threat
Government networks remain primary targets for Iranian espionage (APT42 BELLACIAO) and are the most likely targets for retaliatory destructive operations if the conflict escalates. The water utility campaign demonstrates willingness to target government-operated infrastructure
Actions
  • Heightened monitoring of all internet-facing applications
  • Verify no Langflow/AI platform exposure
  • Review MFA enforcement on all administrative accounts
Aviation / Logistics
Fuel Distribution, Terminal Automation
Primary threat
Toptech petroleum loading systems are deployed at fuel distribution terminals serving aviation. Supply chain disruption through petroleum loading manipulation could ground aircraft without directly attacking aviation systems
Actions
  • Audit fuel management system connectivity
  • Verify Toptech system isolation from corporate networks
  • Coordinate with fuel suppliers on their patch status
  • Watch for MikroTik router compromise indicators (WireGuard key extraction)

Block IPs 77.90.185[.]248, 77.90.185[.]28, 185.93.89[.]75, 94.183.240[.]65, 2.188.214[.]142 at perimeter and add to threat intel blocklist.
SOC Analyst
Verify N-able N-central is patched to version 2026.3 HF1 — CVE-2026-18577 is in CISA KEV with active exploitation; the prior patch (for CVE-2026-18556) was incomplete.
Incident Responder
Deploy WAF/detection rules for Langflow endpoints /api/v1/auto_login and /api/v1/validate/code — CVE-2026-9198 enables trivial unauthenticated RCE.
SOC Analyst
Identify and isolate any internet-exposed Langflow instances; disable auto_login functionality if not operationally required.
Incident Responder
Enable aggregate alerting on all traffic to/from ASN213790 and ASN214192 (Iranian APT infrastructure).
SOC Analyst
No immediate actions for the selected roles.
Audit all ICS/SCADA deployments for Schneider Electric IGSS, Toptech RCU II+/Multiload II+, and MikroTik RouterOS — apply CISA ICS advisory patches.
ICS / OT
Complete inventory of all Langflow and AI/LLM orchestration platform deployments; ensure none expose administrative APIs to untrusted networks.
Threat Hunter
Implement DNS tunneling detection tuned for Cobalt Strike beacon patterns — high-entropy subdomain queries, periodic beaconing intervals, connections to Iranian ASNs.
SOC Analyst
Audit all RMM tool deployments across the enterprise; verify no unauthorized N-central, SimpleHelp, or similar agents are installed.
Incident Responder
Update incident response playbooks to include Iranian wiper scenarios (BiBiWiper, ZeroShred); verify backup integrity and offline backup availability.
Incident Responder
No 7-day actions for the selected roles.
Commission assessment of water utility / municipal SCADA exposure across any monitored or dependent infrastructure — the 7-state campaign demonstrates Iranian capability and intent at scale.
CISO / ExecICS / OT
Evaluate MSP supply chain risk — any MSP using N-able N-central represents a potential trusted-access compromise path into your environment.
CISO / Exec
Review network segmentation between IT, OT, and cloud/AI environments — ensure AI orchestration platforms cannot be used as pivot points into production systems.
ICS / OT
Brief board and legal counsel on Iranian cyber escalation trajectory; ensure cyber insurance coverage addresses nation-state destructive attacks.
CISO / Exec
Conduct tabletop exercise simulating simultaneous wiper deployment and ICS disruption — test communication plans, manual operations procedures, and recovery timelines.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

The Iranian cyber apparatus is operating at its highest sustained tempo against U.S. infrastructure since the conflict began 158 days ago. The seven-state water campaign is not an endpoint — it is a proof of concept being executed at scale. The simultaneous expansion of C2 infrastructure, the emergence of new actor profiles (UNC815), and the availability of trivially exploitable vulnerabilities in AI platforms and RMM tools create a threat environment where the next escalation could come from multiple vectors simultaneously. The most important signal right now is what we are not seeing: no wiper deployment despite the largest Iranian ICS operation in years, and no MuddyWater (MOIS) activity since approximately July 30–31 despite their historical weekly tempo. Silence from capable adversaries during active operations is not reassurance — it is preparation. The adversary is building capability faster than most organizations are building defenses. Close that gap today.

1
Block the Iranian C2 infrastructure identified in this report, and patch N-central and isolate Langflow — these are active exploitation targets.
2
Verify your ICS/SCADA systems are not internet-exposed, and ensure your wiper response playbook is current with offline backups.
3
Brief your executive team — this situation is escalating, and board-level awareness is overdue.
No items found.