| Development | Significance |
|---|---|
| BANISHED KITTEN was formally linked to ChosenBrick RAT in a three-nation joint... | The Handala Hack Team hacktivist persona was confirmed as a BANISHED KITTEN front operation |
| PULSAR KITTEN (APT33) exploited CVE-2026-63077 in JetBrains TeamCity to deploy... | Targeting aerospace and defense CI/CD infrastructure - the software supply chain that builds... |
| CVE-2026-76504 (CVSS 9.8), a Cisco Catalyst SD-WAN Manager auth bypass, added to... | SD-WAN is no longer just a vulnerability - it is a persistent campaign surface |
| CVE-2026-73570, a root-level Zimbra command injection, documented by Microsoft... | Custom Go-based exfiltration tooling and Azure Blob Storage used for data theft |
| Citrix NetScaler's 8 disclosed CVEs include two CVSS 10.0 flaws exploited as... | The highest-severity Citrix vulnerabilities disclosed in the current conflict period |
| UNC6446/GRITCASPIAN updated its aerospace phishing campaign, converging with... | Signals a coordinated collection priority against Western defense supply chains |
| Coordinated operational silence from five major Iranian APT groups has now... | A historically reliable pre-campaign indicator |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins, pre-disclosure exploitation starts | Feb 28 - Aug 7, 2026 | US-Israeli conflict with Iran begins; attackers begin scanning the vulnerable Zimbra SNMP path 8... |
| UK energy attack, Zimbra disclosed | Aug 13-24, 2026 | Zimbra CVE-2026-73570 publicly disclosed; Reuters reports a UK energy facility shutdown attributed... |
| Houthi chokepoint seizure, dissident espionage uncovered | Sep 10-16, 2026 | Houthi forces seize Mokha port and Mayun Island with coordinated hacktivist DDoS; GCHQ uncovers an... |
| Citrix mega-disclosure, RAF Fairford plot, aerospace targeting | Sep 27-29, 2026 | Citrix discloses 8 NetScaler CVEs (3x CVSS 10.0) exploited as zero-days deploying... |
| Current (Day ~215) - KEV addition, dual APT profile updates | Sep 30 - Oct 1, 2026 | CISA adds Cisco SD-WAN CVE-2026-76504 to KEV (8th this year); CrowdStrike confirms BANISHED... |
Previously known for destructive wipers (BiBiWiper, ZeroShred, GoneXML, MisleadingAxe) against Israeli targets, the joint advisory reveals BANISHED KITTEN now operates a full espionage toolkit (ChosenBrick RAT, WovenMist, PhantomBlade, AllinOneNeo) alongside destructive capabilities - using legitimate NetBird/ZeroTier for C2. An actor that...
APT33/Peach Sandstorm exploited TeamCity CVE-2026-63077 for initial access, then deployed SlumberRAT via DLL sideloading through AppVShNotify.exe, hosting malware in open directories on the same infrastructure. Compromising CI/CD infrastructure means an attacker inside a defense contractor's build pipeline can inject backdoors into software...
Cisco SD-WAN (CVE-2026-76504, 9.8): no-auth admin API access via URI-encoding bypass on /j_security_check - the 8th SD-WAN KEV in 2026, providing god-mode network access.
Zimbra (CVE-2026-73570): pre-disclosure exploitation with JSP webshells, stolen auth tokens, and Azure Blob exfiltration via custom Go...
MuddyWater, BANISHED KITTEN, HYDRO KITTEN, IMPERIAL KITTEN, and APT42 have maintained coordinated silence exceeding three weeks. In Iranian cyber operations, coordinated silence is historically a pre-campaign indicator - these groups do not go quiet simultaneously by accident. Combined with geographic expansion to allied nations and active...
Multiple reports confirm Iran's hybrid warfare has expanded to the UK and Europe: an alleged bomb plot against RAF Fairford, a cyberattack shutting down a UK energy facility, and a GCHQ-uncovered espionage campaign targeting Iranian dissidents worldwide. The three-nation joint advisory on BANISHED KITTEN independently corroborates this...
| Probability | Assessment |
|---|---|
| 75% (HIGH) | CVE-2026-76504 (Cisco SD-WAN) exploitation will be attributed to a specific state-sponsored actor... |
| 55% (MODERATE) | MuddyWater will resurface with new or retooled capabilities. Operational silence during conflict... |
| 50% (MODERATE) | Iranian ICS/OT proxy groups (Cyber Av3ngers, HYDRO KITTEN) will target newly disclosed ICS... |
| 45% (MODERATE) | A destructive cyber operation (wiper deployment or ICS disruption) will target a UK or European... |
| 35% (LOW-MODERATE) | The Zimbra CVE-2026-73570 campaign will be attributed to an Iranian actor. The pre-disclosure... |
Hunt hypothesis: Attackers are using URI-encoded variants of...
Hunt hypothesis: Attackers are exploiting Zimbra's SNMP notification processing to...
Hunt hypothesis: APT33 is exploiting TeamCity servers and deploying SlumberRAT...
Hunt hypothesis: BANISHED KITTEN is using spearphishing links to deliver...
Hunt hypothesis: Targeted individuals (executives, intelligence analysts...
| Threat | ATT&CK |
|---|---|
| 1. Cisco SD-WAN Manager CVE-2026-76504 (T1190, T1078) | T1190 T1078 T1548.002 |
| 2. Zimbra CVE-2026-73570 Full Attack Chain (T1190, T1505.003, T1003, T1537) | T1190 T1505.003 T1003 T1537... |
| 3. PULSAR KITTEN SlumberRAT via DLL Sideloading (T1574.002, T1190) | T1574.002 T1190 T1105 T1059 |
| 4. BANISHED KITTEN ChosenBrick / WovenMist (T1566.002, T1105, T1041) | T1566.002 T1105 T1041 T1204.002... |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali...
/j_security_check to bypass authentication on Cisco Catalyst SD-WAN Manager instances.AppVShNotify.exe.- Audit Cisco SD-WAN deployments; prepare for destructive attacks given BANISHED KITTEN's dual-use capability
- Segment OT/ICS from IT networks; audit ICS systems against Toptech/Lantronix/VIVOTEK advisories
- Audit Zimbra deployments for the full attack chain; review CI/CD pipelines for medical device software
- Implement Zimbra mitigations immediately; brief personnel with Iranian diaspora/human rights connections on ChosenBrick targeting
- Audit TeamCity for CVE-2026-63077; scan GitHub repos for exposed credentials (543,000+ exposed globally)
Seven months into this conflict, Iran's cyber operations have crossed a threshold. The geographic expansion from Israel and the Gulf to the UK and Europe is confirmed by a three-nation joint advisory. The toolkit has evolved from crude wipers to dual-use espionage-and-destruction platforms. The targeting has expanded to include the CI/CD pipelines that build Western defense systems. Four critical vulnerabilities are being actively exploited right now. Five major Iranian APT groups are...