| Development | Significance |
|---|---|
| FBI/EPA joint advisory confirms Iranian-linked cyberattacks on water systems in 7 U.S. states | Largest confirmed Iranian ICS operation on U.S. soil; utilities forced to manual operations |
New Iranian C2 node (77.90.185[.]248) provisioned on ASN213790 (Tehran) | Active infrastructure expansion — 3 high-confidence APT IPs on this ASN in 7 days |
| CVE-2026-9198 (IBM Langflow, CVSS 9.8) added to CISA KEV | Unauthenticated RCE on AI/LLM orchestration platforms — no exploit complexity required |
| CVE-2026-18577 (N-able N-central, CVSS 8.1) — second KEV in 3 days | RMM platform auth bypass enables MSP supply chain compromise; patch was incomplete |
| CISA ICS advisories for Schneider IGSS, Toptech petroleum systems, libiec61850 | Expanded OT attack surface directly aligned with Iranian targeting patterns |
| APT42 (IRGC-IO) updates BELLACIAO/SHELLAFEL espionage campaigns | Active collection operations against energy, government, and healthcare sectors confirmed Aug 1–3 |
| MuddyWater (MOIS) operational silence enters Day 5+ | Historically precedes retooling and new campaign launch within 14 days |
| No wiper deployment despite ICS escalation | Breaks historical Iranian doctrine — signals either restraint or preparation for larger strike |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | 2026-02-28 | Day 0 — Iran-related cyber conflict escalation begins |
| Initial ICS disruption | 2026-07-26 – 2026-07-28 | CyberAv3ngers attacks 30+ Minnesota water systems; Cavern Manticore (MOIS) updates destructive posture with no announced operations |
| Infrastructure build-out & scale confirmation | 2026-07-30 – 2026-07-31 | ASN213790 C2 node goes active (confidence 97%); MuddyWater (MOIS) last confirmed operational activity; FBI/EPA confirm water attacks expanded to 7 states |
| Silent reload & espionage tempo | 2026-08-01 – 2026-08-03 | Pioneer Kitten refreshes infrastructure; APT42 updates BELLACIAO/SHELLAFEL; new C2 node provisioned on ASN213790; Remcos RAT and Cobalt Strike DNS tunneling active; CVE-2026-18577 added to CISA KEV; MuddyWater silence formally noted (Day 4) |
| Current (Day 158) | 2026-08-04 – 2026-08-05 | CVE-2026-9198 (Langflow) added to CISA KEV; UNC815 (Iranian, fintech/telecom-focused) profile updated — possible new campaign activation |
Actor: CyberAv3ngers (IRGC-affiliated proxy). Targets: Municipal water and wastewater systems across Michigan, Minnesota, and at least 5 additional states. TTPs: Exploitation of internet-exposed Unitronics PLCs using default credentials (T1078), PLC logic modification (T1565.001), forcing utilities to manual operations (T1489).
This campaign represents a qualitative escalation. CyberAv3ngers has moved from opportunistic single-utility attacks (2023 Aliquippa, PA) to coordinated multi-state operations. The FBI/EPA joint advisory confirms this is not isolated criminal activity — it is a state-directed campaign against U.S. critical infrastructure.
The wiper question: Iranian operational doctrine since October 2023 has paired ICS disruption with destructive wiper deployment (BiBiWiper, ZeroShred) against allied targets within 48–72 hours. We are now 9+ days into this campaign with no wiper observed. Two interpretations exist: a restraint hypothesis (Iran is deliberately staying below the destructive threshold to maintain plausible deniability through its proxy structure) or an escalation hypothesis (destructive capability is being held in reserve for a larger trigger event, and the water campaign is pre-positioning). Both interpretations demand heightened defensive posture.
Actor: Pioneer Kitten (UNC757, Fox Kitten, IRGC-linked). Infrastructure: ASN213790 ("Limited Network", Tehran) — now hosting 3 confirmed high-confidence APT IPs.
Pioneer Kitten's infrastructure refresh on August 1 — without corresponding campaign activity — matches a historical pattern: silent infrastructure provisioning precedes new exploitation waves within 14 days. This actor has a documented history of operating as an initial access broker, selling footholds to ransomware affiliates (previously ALPHV/BlackCat, now assessed Qilin).
The convergence of Pioneer Kitten infrastructure expansion with the CyberAv3ngers water campaign on overlapping ASN infrastructure suggests possible operational coordination between IRGC units.
Vulnerability: IBM Langflow versions 1.0.0–1.10.0. CVSS: 9.8 (Critical). Exploit chain: /api/v1/auto_login mints SUPERUSER tokens to any network caller → /api/v1/validate/code executes arbitrary Python via exec(). Status: CISA KEV (active exploitation confirmed).
This is a trivial-to-exploit, unauthenticated RCE on AI/LLM orchestration platforms increasingly deployed in enterprise environments. The attack chain requires zero authentication and zero user interaction. Any Langflow instance exposed to an untrusted network is fully compromised.
This vulnerability is particularly concerning in the Iranian context: APT42 (IRGC-IO) and MuddyWater (MOIS) have demonstrated increasing interest in cloud and AI infrastructure as collection targets, and the OAuth-like token-minting mechanism aligns with documented Iranian exploitation patterns.
Vulnerability: N-able N-central ≤ 2026.3.1 (authentication bypass → account takeover). CVSS: 8.1 (High). Context: This is an incomplete patch for CVE-2026-18556 (CVSS 7.4) — meaning organizations that patched the first vulnerability remain exposed.
N-able N-central is widely deployed by Managed Service Providers (MSPs). Compromise of an RMM platform provides attackers with trusted access to every downstream client (T1199 — Trusted Relationship). Pioneer Kitten has historically exploited VPN and remote access tools as initial access vectors; RMM platforms represent the same attack pattern at MSP scale.
Actor: MuddyWater (affiliated with MOIS — Ministry of Intelligence and Security). Status: Operational silence since approximately July 30–31; intel profile updated August 3 to formally note the absence of activity.
MuddyWater typically operates at a weekly cadence of phishing, credential harvesting, and PowerShell/DotNET loader deployment. A silence of 5+ days — confirmed as of this writing — has historically preceded retooling events followed by new campaign launches within 14 days. The August 3 profile update reflects the intelligence community's assessment of this silence, not new MuddyWater activity. Defenders should treat this as a warning indicator, not a stand-down signal.
UNC815 — an Iranian-origin actor targeting financial services, technology, telecommunications, and entertainment — received a profile update on August 5. This targeting profile is atypical for Iranian groups (which traditionally focus on government, energy, and defense). This may represent a new MOIS collection priority or a financial-crime crossover unit. Monitoring is warranted.
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Water ICS campaign expands to additional states; FBI/CISA releases technical IOCs with direct CyberAv3ngers attribution | 70% | 72 hours | Campaign trajectory, FBI/EPA advisory language, media reporting cadence |
| Wiper deployment (BiBiWiper/ZeroShred) against Israeli or allied targets | 40% | 72 hours | Historical 48–72hr lag between ICS disruption and destructive ops; currently overdue |
| MuddyWater (MOIS) resurfaces with new tooling variant after operational silence | 25% | 14 days | 5+ days of silence historically precedes retooling; operational silence began ~Jul 30–31 |
| Pioneer Kitten launches new exploitation wave leveraging refreshed infrastructure | 60% | 14 days | Historical pattern: infrastructure refresh → campaign within 14 days |
| CVE-2026-9198 (Langflow) exploited by Iranian actors against enterprise AI deployments | 35% | 30 days | Aligns with PIR-006 trend; trivial exploit complexity; Iranian interest in cloud/AI |
| N-central CVE-2026-18577 used for MSP supply chain compromise | 50% | 14 days | KEV listing confirms active exploitation; RMM = high-value initial access |
Hunt for any network connections to ASN213790 ("Limited Network") and ASN214192 ("Milad Ahadpour"), both Tehran-based and hosting confirmed APT infrastructure. Hunting hypothesis: "Are any internal hosts communicating with Iranian ASNs 213790, 214192, or 42337 on any port?" Detection: Aggregate alerting on any connection to/from these ASNs — treat as high-priority. DNS tunneling detection (unusually long subdomain queries, high query volume to single domains) is critical given confirmed Cobalt Strike DNS tunneling on these networks.
Hunting hypothesis: "Are there any HTTP requests to /api/v1/auto_login or /api/v1/validate/code endpoints from external sources?" Detection: WAF rules blocking unauthenticated access to these endpoints; monitor for exec() patterns in application logs; alert on SUPERUSER token creation events outside normal admin activity.
Hunting hypothesis: "Are there authentication events in N-central that bypass normal login flow, or new admin accounts created without corresponding helpdesk tickets?" Detection: Monitor N-central audit logs for account creation/modification anomalies; alert on RMM agent deployment to hosts not in approved inventory.
Hunting hypothesis: "Are there PLC logic changes, setpoint modifications, or HMI access events outside maintenance windows?" Detection: Monitor Unitronics, Schneider Electric IGSS, and Toptech systems for unauthorized configuration changes; alert on any internet-facing SCADA/HMI access.
Hunting hypothesis: "Are there any processes attempting to overwrite MBR/VBR, delete shadow copies, or disable recovery services?" Detection: Monitor for vssadmin delete shadows, bcdedit /set {default} recoveryenabled No, and raw disk write operations from non-system processes. Alert on any BiBiWiper, ZeroShred, or GoneXML hash submissions to sandbox platforms.
| Threat | ATT&CK |
|---|---|
| 1. Iranian C2 Infrastructure Monitoring | T1071 T1571 T1572 |
| 2. Langflow Exploitation Attempts | T1190 T1059.006 |
| 3. N-central Authentication Bypass | T1190 T1078 T1219 |
| 4. ICS/SCADA Anomaly Detection | T1565.001 T1489 |
| 5. Wiper Pre-Indicators | T1485 T1561 T1490 |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Monitor for credential stuffing from Iranian IP ranges
- Review all RMM tool access (N-central exposure is critical for MSP-served financial institutions)
- Watch for unusual OAuth token generation, lateral movement from MSP-connected segments, and anomalous transaction system access
- Immediate audit of Toptech RCU II+/Multiload II+ and Schneider IGSS deployments
- Verify network segmentation between IT and OT
- Patch libiec61850 in substation environments
- Watch for unauthorized PLC/RTU configuration changes and anomalous IEC 61850 protocol traffic
- Verify MSP RMM tool versions; ensure N-central is patched to 2026.3 HF1
- Segment MSP access from clinical systems
- Watch for RMM agent deployment anomalies and lateral movement from administrative segments to clinical networks
- Heightened monitoring of all internet-facing applications
- Verify no Langflow/AI platform exposure
- Review MFA enforcement on all administrative accounts
- Audit fuel management system connectivity
- Verify Toptech system isolation from corporate networks
- Coordinate with fuel suppliers on their patch status
- Watch for MikroTik router compromise indicators (WireGuard key extraction)
77.90.185[.]248, 77.90.185[.]28, 185.93.89[.]75, 94.183.240[.]65, 2.188.214[.]142 at perimeter and add to threat intel blocklist./api/v1/auto_login and /api/v1/validate/code — CVE-2026-9198 enables trivial unauthenticated RCE.auto_login functionality if not operationally required.The Iranian cyber apparatus is operating at its highest sustained tempo against U.S. infrastructure since the conflict began 158 days ago. The seven-state water campaign is not an endpoint — it is a proof of concept being executed at scale. The simultaneous expansion of C2 infrastructure, the emergence of new actor profiles (UNC815), and the availability of trivially exploitable vulnerabilities in AI platforms and RMM tools create a threat environment where the next escalation could come from multiple vectors simultaneously. The most important signal right now is what we are not seeing: no wiper deployment despite the largest Iranian ICS operation in years, and no MuddyWater (MOIS) activity since approximately July 30–31 despite their historical weekly tempo. Silence from capable adversaries during active operations is not reassurance — it is preparation. The adversary is building capability faster than most organizations are building defenses. Close that gap today.