TLP:GREEN  ·  Iran / Israel Conflict
Seven Months In:

Iran's Cyber War Goes Global as Threats Accelerate

HIGH. Maintained from prior cycle. A joint advisory from the UK's NCSC, FBI, and Dutch AIVD confirmed Iran's MOIS and IRGC cyber units are now actively targeting allied nations with a toolkit evolved from crude wipers to dual-use espionage-and-destruction platforms. Four critical vulnerabilities are being actively exploited - including a Cisco SD-WAN zero-day and a Zimbra root-level RCE - and Iran's most capable APT groups are targeting the CI/CD pipelines that build Western defense systems.

I am a
My sector

DevelopmentSignificance
BANISHED KITTEN was formally linked to ChosenBrick RAT in a three-nation joint...The Handala Hack Team hacktivist persona was confirmed as a BANISHED KITTEN front operation
PULSAR KITTEN (APT33) exploited CVE-2026-63077 in JetBrains TeamCity to deploy...Targeting aerospace and defense CI/CD infrastructure - the software supply chain that builds...
CVE-2026-76504 (CVSS 9.8), a Cisco Catalyst SD-WAN Manager auth bypass, added to...SD-WAN is no longer just a vulnerability - it is a persistent campaign surface
CVE-2026-73570, a root-level Zimbra command injection, documented by Microsoft...Custom Go-based exfiltration tooling and Azure Blob Storage used for data theft
Citrix NetScaler's 8 disclosed CVEs include two CVSS 10.0 flaws exploited as...The highest-severity Citrix vulnerabilities disclosed in the current conflict period
UNC6446/GRITCASPIAN updated its aerospace phishing campaign, converging with...Signals a coordinated collection priority against Western defense supply chains
Coordinated operational silence from five major Iranian APT groups has now...A historically reliable pre-campaign indicator

PhaseTimeframeCyber Activity
Conflict begins, pre-disclosure exploitation startsFeb 28 - Aug 7, 2026US-Israeli conflict with Iran begins; attackers begin scanning the vulnerable Zimbra SNMP path 8...
UK energy attack, Zimbra disclosedAug 13-24, 2026Zimbra CVE-2026-73570 publicly disclosed; Reuters reports a UK energy facility shutdown attributed...
Houthi chokepoint seizure, dissident espionage uncoveredSep 10-16, 2026Houthi forces seize Mokha port and Mayun Island with coordinated hacktivist DDoS; GCHQ uncovers an...
Citrix mega-disclosure, RAF Fairford plot, aerospace targetingSep 27-29, 2026Citrix discloses 8 NetScaler CVEs (3x CVSS 10.0) exploited as zero-days deploying...
Current (Day ~215) - KEV addition, dual APT profile updatesSep 30 - Oct 1, 2026CISA adds Cisco SD-WAN CVE-2026-76504 to KEV (8th this year); CrowdStrike confirms BANISHED...

Previously known for destructive wipers (BiBiWiper, ZeroShred, GoneXML, MisleadingAxe) against Israeli targets, the joint advisory reveals BANISHED KITTEN now operates a full espionage toolkit (ChosenBrick RAT, WovenMist, PhantomBlade, AllinOneNeo) alongside destructive capabilities - using legitimate NetBird/ZeroTier for C2. An actor that...

T1566.002T1105T1041

APT33/Peach Sandstorm exploited TeamCity CVE-2026-63077 for initial access, then deployed SlumberRAT via DLL sideloading through AppVShNotify.exe, hosting malware in open directories on the same infrastructure. Compromising CI/CD infrastructure means an attacker inside a defense contractor's build pipeline can inject backdoors into software...

T1190T1574.002T1105

Cisco SD-WAN (CVE-2026-76504, 9.8): no-auth admin API access via URI-encoding bypass on /j_security_check - the 8th SD-WAN KEV in 2026, providing god-mode network access.

Zimbra (CVE-2026-73570): pre-disclosure exploitation with JSP webshells, stolen auth tokens, and Azure Blob exfiltration via custom Go...

T1190T1078T1003

MuddyWater, BANISHED KITTEN, HYDRO KITTEN, IMPERIAL KITTEN, and APT42 have maintained coordinated silence exceeding three weeks. In Iranian cyber operations, coordinated silence is historically a pre-campaign indicator - these groups do not go quiet simultaneously by accident. Combined with geographic expansion to allied nations and active...

Multiple reports confirm Iran's hybrid warfare has expanded to the UK and Europe: an alleged bomb plot against RAF Fairford, a cyberattack shutting down a UK energy facility, and a GCHQ-uncovered espionage campaign targeting Iranian dissidents worldwide. The three-nation joint advisory on BANISHED KITTEN independently corroborates this...

ProbabilityAssessment
75% (HIGH)CVE-2026-76504 (Cisco SD-WAN) exploitation will be attributed to a specific state-sponsored actor...
55% (MODERATE)MuddyWater will resurface with new or retooled capabilities. Operational silence during conflict...
50% (MODERATE)Iranian ICS/OT proxy groups (Cyber Av3ngers, HYDRO KITTEN) will target newly disclosed ICS...
45% (MODERATE)A destructive cyber operation (wiper deployment or ICS disruption) will target a UK or European...
35% (LOW-MODERATE)The Zimbra CVE-2026-73570 campaign will be attributed to an Iranian actor. The pre-disclosure...

1. Cisco SD-WAN Manager CVE-2026-76504 (T1190, T1078):

Hunt hypothesis: Attackers are using URI-encoded variants of...

2. Zimbra CVE-2026-73570 Full Attack Chain (T1190, T1505.003, T1003, T1537):

Hunt hypothesis: Attackers are exploiting Zimbra's SNMP notification processing to...

3. PULSAR KITTEN SlumberRAT via DLL Sideloading (T1574.002, T1190):

Hunt hypothesis: APT33 is exploiting TeamCity servers and deploying SlumberRAT...

4. BANISHED KITTEN ChosenBrick / WovenMist (T1566.002, T1105, T1041):

Hunt hypothesis: BANISHED KITTEN is using spearphishing links to deliver...

5. Apple iOS/macOS Spyware — CVE-2026-86950:

Hunt hypothesis: Targeted individuals (executives, intelligence analysts...

ThreatATT&CK
1. Cisco SD-WAN Manager CVE-2026-76504 (T1190, T1078)T1190 T1078 T1548.002
2. Zimbra CVE-2026-73570 Full Attack Chain (T1190, T1505.003, T1003, T1537)T1190 T1505.003 T1003 T1537...
3. PULSAR KITTEN SlumberRAT via DLL Sideloading (T1574.002, T1190)T1574.002 T1190 T1105 T1059
4. BANISHED KITTEN ChosenBrick / WovenMist (T1566.002, T1105, T1041)T1566.002 T1105 T1041 T1204.002...
IOC Blocking Table:
117.107.25[.]243192.255.193[.]111transzimbra[.]linkpc[.]netpsk1zim[.]abrdns[.]comoast[.]funoast[.]onlinednslog[.]pp[.]uarequestrepo[.]com

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali...

Hunting Hypotheses:
HUNT 01 · T1190
1. Cisco SD-WAN Manager CVE-2026-76504 (T1190, T1078)
Attackers are using URI-encoded variants of /j_security_check to bypass authentication on Cisco Catalyst SD-WAN Manager instances.
HUNT 02 · T1190
2. Zimbra CVE-2026-73570 Full Attack Chain (T1190, T1505.003, T1003, T1537)
Attackers are exploiting Zimbra's SNMP notification processing to achieve root access, deploy webshells, steal authentication secrets, and exfiltrate mailbox data to cloud storage.
HUNT 03 · T1574.002
3. PULSAR KITTEN SlumberRAT via DLL Sideloading (T1574.002, T1190)
APT33 is exploiting TeamCity servers and deploying SlumberRAT through DLL sideloading using the legitimate Microsoft binary AppVShNotify.exe.
HUNT 04 · T1566.002
4. BANISHED KITTEN ChosenBrick / WovenMist (T1566.002, T1105, T1041)
BANISHED KITTEN is using spearphishing links to deliver ChosenBrick RAT and WovenMist malware, with the Handala Hack Team persona as cover.
HUNT 05
5. Apple iOS/macOS Spyware — CVE-2026-86950
Targeted individuals (executives, intelligence analysts, journalists) are being compromised via iOS/macOS spyware exploiting CVE-2026-86950.

Financial Services
SD-WAN, Zimbra Deployments
Primary threat
Heavy SD-WAN users via distributed branch networks; acquired subsidiaries/international branches...
Actions
  • Audit Cisco SD-WAN deployments; prepare for destructive attacks given BANISHED KITTEN's dual-use capability
Energy
OT/ICS, MikroTik Boundaries
Primary threat
Confirmed Iranian targeting via the UK energy facility shutdown; MikroTik routers commonly deployed...
Actions
  • Segment OT/ICS from IT networks; audit ICS systems against Toptech/Lantronix/VIVOTEK advisories
Healthcare
Zimbra, CI/CD Pipelines
Primary threat
Academic medical centers are common Zimbra users; medical device software supply chains...
Actions
  • Audit Zimbra deployments for the full attack chain; review CI/CD pipelines for medical device software
Government
Email Infrastructure, Diaspora Ties
Primary threat
Primary target of Iranian state operations; the ChosenBrick joint advisory specifically addresses...
Actions
  • Implement Zimbra mitigations immediately; brief personnel with Iranian diaspora/human rights connections on ChosenBrick targeting
Aviation / Logistics
CI/CD, GitHub Exposure
Primary threat
Most actively targeted sector right now - PULSAR KITTEN and UNC6446 converge on aerospace/defense...
Actions
  • Audit TeamCity for CVE-2026-63077; scan GitHub repos for exposed credentials (543,000+ exposed globally)
No sector cards match the selected filters.

Hunt for Cisco SD-WAN compromise: URI-encoded...
SOC AnalystIncident Responder
Deploy Zimbra CVE-2026-73570 detection: block listed C2...
SOC Analyst
Patch all Apple devices to iOS 27.x/macOS Tahoe 26.7.1; enable...
Incident Responder
Activate heightened IR posture - four actively exploited CVEs...
CISO / Exec
No immediate actions for the selected roles.
Audit all MikroTik RouterOS devices; upgrade to 7.24+...
Incident Responder
Create detection rules for ChosenBrick RAT; monitor for...
SOC Analyst
Audit all TeamCity instances for CVE-2026-63077; verify no DLL...
Incident Responder
Scan GitHub repositories for exposed credentials using...
Incident Responder
No 7-day actions for the selected roles.
Commission a red team assessment of SD-WAN management...
CISO / Exec
Evaluate intelligence collection architecture - 12 consecutive...
CISO / Exec
Develop Iranian destructive attack playbooks given BANISHED...
CISO / ExecIncident Responder
Assess maritime cyber risk given active Hormuz conflict and...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Seven months into this conflict, Iran's cyber operations have crossed a threshold. The geographic expansion from Israel and the Gulf to the UK and Europe is confirmed by a three-nation joint advisory. The toolkit has evolved from crude wipers to dual-use espionage-and-destruction platforms. The targeting has expanded to include the CI/CD pipelines that build Western defense systems. Four critical vulnerabilities are being actively exploited right now. Five major Iranian APT groups are...

1
Patch Cisco SD-WAN and Zimbra now.
2
Audit TeamCity and hunt for ChosenBrick this week.
3
The joint advisory confirms escalation. Will you detect it when it arrives?
No items found.