TLP:GREEN  ·  Iran / Israel Conflict
Seven Months In:

Three Zero-Days, Validated Wipers, and a Shrinking Window to Act

ELEVATED. Maintained from prior cycle. CrowdStrike has validated that BANISHED KITTEN's destructive wiper attacks against UAE, Saudi Arabia, and Bahrain are likely valid - not just bluster. Three critical edge device vulnerabilities (CVSS 9.8-10.0) are under active exploitation in product families Iranian APTs have historically weaponized within days. Sixteen ICS/SCADA advisories have been published in 48 hours. The historical pattern is clear: Iranian APTs weaponize KEV additions within 3-7 days, and that window closes by the end of this week.

I am a
My sector

DevelopmentWhy It Matters
BANISHED KITTEN wiper campaign validated by...Handala Hack Team's claims of data destruction against...
Arista VeloCloud Orchestrator CVE-2026-93952 (CVSS...Active zero-day exploitation of SD-WAN orchestrators. Compromise of a...
F5 BIG-IP APM OAuth RCE CVE-2026-94127 (CVSS 9.8)First confirmed wild exploitation of an OAuth-specific vulnerability...
Check Point Quantum Gateway CVE-2026-85102 (CVSS 9.8)Unauthenticated RCE via VPN certificate trust validation bypass...
16 ICS advisories in 48 hoursSiemens-heavy batch includes Industrial Edge Management auth bypass...
Tehran-hosted C2 infrastructure activeAgentemis/CobaltStrike beacons on ports 443 and 53, plus...
Plugin4Shell and AI-accelerated exploitationZero-click RCE class affecting major AI coding agents (Claude Code...
U.S.-Iran rhetoric escalation"Annihilate" vs. "crushing" language detected in diplomatic channels...

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran-US conflict begins; Iranian cyber operations activate across...
PAYLOAD and BANISHED KITTEN claims, water systems compromisedApr - Aug 2026PAYLOAD ransomware breaches a manufacturer via FortiGate VPN...
Edge device CVEs emergeSep 9-19, 2026Check Point Quantum Gateway CVE published; Brevo supply chain attack...
KEV surge, wiper validationSep 22, 2026CISA adds 4 vulnerabilities to KEV; 9 ICS advisories published...
Current (Day ~208) - active C2, five concurrent campaignsSep 23, 2026UNC6446 aerospace phishing updated; Tehran-hosted...

CrowdStrike now assesses BANISHED KITTEN's (Handala Hack Team) April 2026 claims of data deletion against UAE, Saudi Arabia, and Bahrain government/manufacturing targets as "likely valid" based on screenshot analysis and correlated wiper samples. Confirmed arsenal: GoneXML ransomware, ZeroShred wiper, AllinOneNeo implant, BiBiWiper, plus...

T1485T1486T1489T1572

Iranian APTs weaponize KEV additions within 3-7 days. Three new critical CVEs join the active exploitation landscape: Arista VeloCloud Orchestrator (CVSS 10.0, active zero-day, controls SD-WAN routing enterprise-wide), F5 BIG-IP APM OAuth RCE (CVSS 9.8, combines initial access with OAuth token theft), and...

T1190T1133T1078

Sixteen ICS/SCADA advisories in 48 hours is the highest two-day volume of this conflict, seven from Siemens. Most critical: Siemens Industrial Edge Management auth bypass (the exact IT-to-OT bridge Cyber Av3ngers and SPECTRAL KITTEN have been developing), lwIP TCP/IP stack full code execution on embedded...

T1190T0890T0816

Four IPs geolocated to Tehran hosting active C2: two Agentemis/CobaltStrike BEACON servers (ports 443/53), a Tofsee server, and a Chaos/FakeRyuk/Yashma server on Iranian academic infrastructure (IPM). Port 53 CobaltStrike traffic indicates DNS tunneling - standard Iranian APT tradecraft.

T1071.001T1071.004T1059.001

Plugin4Shell: zero-click RCE affecting AI coding agents (Claude Code, OpenAI Codex, GitHub Copilot) via plugin SHA-pinning bypass - no user interaction required since agents auto-update plugins. A new attack surface category Iranian actors could weaponize against developer environments at scale.

AI-accelerated...

ScenarioProbabilityBasis
Iranian actors attempt exploitation of at least one of today's three...75% (HIGH)Historical pattern: Iranian groups weaponize KEV additions within 3–7...
BANISHED KITTEN escalates information operations with new breach...50% (MODERATE)U.S.-Iran rhetoric escalation ("annihilate" vs. "crushing") detected...
SPECTRAL KITTEN breaks operational silence with exploitation of...35% (LOW-MODERATE)SPECTRAL KITTEN typically exploits ICS advisories within days...
Iranian actors weaponize F5 BIG-IP APM OAuth RCE (CVE-2026-94127) for...40% (MODERATE)The OAuth profile requirement makes this a high-value target for...
Ransomware affiliate (ISRL) deploys FortiGate VPN credential...30% (LOW-MODERATE)Stockpile existence confirmed in prior cycles. Deployment timing...

1. Edge Device Exploitation Monitoring:

Hunt hypothesis: Adversaries are scanning for and...

3. BANISHED KITTEN Wiper Pre-Positioning:

Hunt hypothesis: BANISHED KITTEN has pre-positioned...

4. ICS/OT Network Monitoring:

Hunt hypothesis: Iranian proxy groups are probing...

5. OAuth and Identity Abuse:

Hunt hypothesis: Adversaries are exploiting F5...

ThreatATT&CK
1. Edge Device Exploitation MonitoringT1190 T1133 T1078...
3. BANISHED KITTEN Wiper Pre-PositioningT1485 T1486 T1489...
4. ICS/OT Network MonitoringT1190 T0890 T0816...
5. OAuth and Identity AbuseT1078 T1550.001
IOC Blocking Table:
217.60.241[.]1787.107.191[.]39217.60.241[.]3994.184.37[.]68customermgmt[.]netiranelectric[.]comiran-as.fartit[.]com

Block the above at perimeter firewalls, proxies, and DNS. Hashes...

Hunting Hypotheses:
HUNT 01 · T1071.001
2. Iranian C2 Infrastructure Blocking and Hunting
Hunt hypothesis: Compromised internal hosts are beaconing to Tehran-hosted Agentemis/CobaltStrike C2 infrastructure. Detection guidance: - Block and alert on connections to 217.60.241[.]17:443, 87.107.191[.]39:53, 217.60.241[.]39:431, 94.184.37[.]68:8080 - Hunt for DNS queries to unusual ports (port 53 traffic to non-DNS-server IPs is a strong C2 indicator) - Monitor for CobaltStrike BEACON behavioral signatures: regular interval callbacks, named pipe usage, reflective DLL injection - Alert on any traffic to AS51396 (Pfcloud UG) and AS44436 (Toosee Ertebatat Damavand) — these ASNs host confirmed Iranian C2
HUNT 02
1. Edge Device Exploitation Monitoring
Adversaries are scanning for and exploiting unpatched Arista VCO, F5 BIG-IP APM, and Check Point Quantum gateways. Look for anomalous authentication events, unexpected administrative sessions, and configuration changes on these platforms.
HUNT 03
3. BANISHED KITTEN Wiper Pre-Positioning
BANISHED KITTEN has pre-positioned wiper tooling (GoneXML, ZeroShred, BiBiWiper) in target environments and may activate on a geopolitical trigger.
HUNT 04
4. ICS/OT Network Monitoring
Iranian proxy groups are probing Siemens Industrial Edge Management interfaces for the authentication bypass (ICSA-26-265-06) and may pivot from IT to OT networks.
HUNT 05
5. OAuth and Identity Abuse
Adversaries are exploiting F5 BIG-IP APM OAuth configurations to obtain valid tokens for lateral movement and cloud resource access.

Financial Services
OAuth Authentication, CDN Dependencies
Primary threat
Dual supply chain threat from Brevo/Cloudflare Worker hijack; F5 BIG-IP APM OAuth RCE is a direct...
Actions
  • Audit third-party JS/CDN dependencies and implement SRI tags; patch or disable F5 OAuth Authorization Server profiles
Energy
SD-WAN, ICS/SCADA
Primary threat
Most acute threat sector. UNC6779 actively exploiting GlobalProtect; Arista VCO could reroute...
Actions
  • Verify IT/OT segmentation for Siemens Industrial Edge Management; patch VCO On-Prem within CISA's 3-day window
Healthcare
Linux Servers, Backup Infrastructure
Primary threat
Exposure through BANISHED KITTEN wiper threat (prior BiBiWiper targeting) and active Linux kernel...
Actions
  • Patch Linux kernel on medical imaging/EHR systems; patch Acronis Backup for CVE-2026-87886
Government
Federal Compliance, DIB
Primary threat
Broadest threat surface; BOD 26-04 mandates 3-day patching for Arista VCO; BANISHED KITTEN...
Actions
  • Prioritize Check Point and Arista VCO patching for compliance deadlines; request UNC6446 IOC packages
Aviation / Logistics
SD-WAN, Aerospace Phishing
Primary threat
Strategic risk from Arista VCO (traffic interception across branch offices) and targeted risk from...
Actions
  • Patch VCO On-Prem immediately; brief security teams on current UNC6446 phishing TTPs
No sector cards match the selected filters.

Block Iran-hosted C2 IPs at perimeter firewall (see IOC table...
SOC Analyst
Patch F5 BIG-IP APM against CVE-2026-94127; disable OAuth...
Incident Responder
Upgrade Arista VeloCloud Orchestrator to 5.2.3.16 or 6.4.2.8...
Incident Responder
Patch Check Point Quantum Gateways against CVE-2026-85102...
Incident Responder
No immediate actions for the selected roles.
Audit Siemens Industrial Edge Management for auth bypass...
ICS / OT
Patch Linux kernel against CVE-2025-39964 and CVE-2026-53266...
Incident Responder
Hunt for SPECTRAL KITTEN against Siemens Industrial Edge...
Threat Hunter
Audit F5 BIG-IP APM OAuth token logs; correlate with Entra ID...
SOC Analyst
No 7-day actions for the selected roles.
Investigate intelligence collection gaps - OSINT feed...
CISO / Exec
Conduct a focused threat hunt for UNC6446 aerospace phishing...
Threat Hunter
Commission a red team assessment of IT-to-OT segmentation for...
CISO / Exec
Review AI coding agent security posture - audit plugin...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Seven months into this conflict, Iranian cyber operations have matured from opportunistic exploitation to industrialized, multi-vector campaigns spanning edge devices, OT systems, cloud identity infrastructure, and destructive wiper deployments simultaneously. The validation of BANISHED KITTEN's destructive capability, combined with three CVSS 9.8-10.0 edge device vulnerabilities under active exploitation, means the question is not whether these vulnerabilities will be weaponized by Iranian...

1
Patch the edge devices today.
2
Block the C2 infrastructure now.
3
Deploy the wiper IOCs and test your incident response playbooks.
No items found.