| Development | Significance |
|---|---|
| Pioneer Kitten / Fox Kitten silent for 31... | The pattern that precedes coordinated activation... |
| Public exploit code released for four... | 10-21-year-old bugs affecting virtually every... |
| A novel "encryptionless" ransomware... | No ransomware binary ever touched a Windows... |
| Eight new CISA ICS advisories... | Widely deployed in energy, manufacturing, and... |
| JADEPUFFER agentic ransomware... | Recovery requires retraining, not restoring... |
| UNC6779 (IRGC-linked) actively exploiting... | A live, ongoing intrusion campaign |
| New Iran-themed C2 infrastructure... | This pattern historically precedes new activity... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | Iran conflict begins, initiating sustained cyber... |
| PAYLOAD incident, Gulf wipers, silence begins | Apr - Aug 2026 | PAYLOAD ransomware disrupts a Middle East... |
| BANISHED KITTEN pauses, ICS advisories surge | Sep 15-17, 2026 | BANISHED KITTEN wiper campaign pauses; CISA... |
| Exploit code, tankers, AI ransomware | Sep 18, 2026 | Linux quad-LPE exploits published; FBI... |
| Current (Day ~206) - active exploitation, new C2 | Sep 19-21, 2026 | UNC6779 actively exploiting Palo Alto... |
In a confirmed Middle East manufacturing incident, the attacker gained access via a compromised FortiGate SSL VPN credential, escalated to domain admin, created a malicious GPO linked at the domain root, and used it to hijack wallpapers with ransom notes, disable local admin accounts, and disable Windows Firewall - exfiltrating data, but never...
These IRGC-affiliated groups maintain persistent access inside DIB and critical infrastructure networks, often through compromised VPN appliances. Thirty-one days is the longest observed dormancy for these actors during the conflict - not reassuring, but the pattern that precedes coordinated activation. A ceasefire collapse, a Hormuz incident...
Public exploit code exists for four Linux kernel privilege escalation flaws, several hiding for over a decade: DirtyAH6 (IPsec AH6), TUNderflow (TUN/TAP), PPPoEject (PPPoE) - all requiring unprivileged user namespaces - and DiagSpill (SCTP), requiring no special privileges whatsoever. Any user on an unpatched system can...
JADEPUFFER exploits Langflow CVE-2025-3248 for initial access; its ENCFORGE payload targets ~180 file extensions tied to AI model checkpoints, vector databases, and training datasets. The ransomware operates autonomously - planning, executing, and self-correcting in ~31 seconds - following a destruction-first model that deletes originals before...
UNC6779 (IRGC-linked) is actively exploiting Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.1) against energy and utility networks as of Sep 19 - a live, ongoing intrusion campaign, not a theoretical risk. Combined with the Schneider Modicon M340 ICS advisory and known Iranian ICS targeting interest (Cyber Av3ngers, SPECTRAL KITTEN), energy...
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Linux kernel exploitation attempts surge as... | 70% | 48 hours | Public exploit availability + zero-privilege... |
| BANISHED KITTEN wiper campaign resumes with... | 60% | 7 days | 6-day pause after sustained campaign; historical... |
| MuddyWater new campaign publicly reported... | 50% | 5–7 days | ThreatStream profile updates without campaign... |
| Pioneer Kitten / Fox Kitten dormant access... | 40% | 30 days | 31-day silence; historical precedent of... |
| GPO-based encryptionless ransomware technique... | 35% | 30 days | TTP fits Iranian below-threshold disruption... |
| JADEPUFFER or copycat targets enterprise AI/ML... | 30% | 30 days | ENCFORGE capability demonstrated; AI/ML assets... |
Hunting Hypothesis: An adversary with...
Hunting Hypothesis: Iranian actors use...
Hunting Hypothesis: Attackers exploit...
Hunting Hypothesis: Attacker exploits...
Monitor: DNS queries and HTTP...
Monitor: Network traffic to/from...
| Threat | ATT&CK |
|---|---|
| 1. Group Policy Object Abuse (T1484.001 — Domain... | T1484.001 |
| 2. FortiGate VPN Credential Abuse (T1078 — Valid... | T1078 T1133 |
| 3. Linux Kernel Privilege Escalation (T1068 —... | T1068 |
| 4. JADEPUFFER / ENCFORGE AI Asset Targeting... | T1190 T1486... |
| 5. Iran-Themed C2 — Trojan-Spy.Win32.Noon... | T1071.001 T1555 |
| 6. ICS/OT Monitoring (T1190, T0890, T0826, T0831) | T1190 T0890... |
Block the above at perimeter firewalls, proxies...
- Audit FortiGate VPN accounts and enforce MFA; implement GPO change monitoring
- Patch Schneider Modicon M340 and Hitachi FACTS; verify Palo Alto GlobalProtect patched against CVE-2026-0257
- Patch Linux servers immediately; audit VPN access controls given PAYLOAD's entry vector
- Commission a threat hunt for Pioneer Kitten/Fox Kitten dormant access - FortiGate logs, Rclone/Wasabi exfiltration indicators
- Review email security for aerospace phishing lures; audit DIB contractor FortiGate VPN access
irancepat[.]xyz and JADEPUFFER...Seven months into this conflict, the Iranian cyber threat is not diminishing - it is maturing. The actors are more patient (31 days of silence from DIB access operators). The techniques are more sophisticated (GPO-based disruption that leaves no malware on disk). The targets are expanding (AI/ML infrastructure, maritime vessels, ICS across multiple vendors). And the vulnerability surface keeps growing. The single most important action you can take today is to stop treating silence as safety...