TLP:GREEN  ·  Iran / Israel Conflict
The Calm Before the Storm:

Iran's Cyber Operators Go Silent While Critical Vulnerabilities Multiply

HIGH. Maintained from prior cycle. Pioneer Kitten and Fox Kitten have been silent for 31 consecutive days - the longest observed dormancy in the conflict - while public exploit code now exists for four Linux kernel privilege escalation flaws, a novel encryptionless ransomware technique achieved full operational disruption without deploying malware, and an autonomous AI-driven ransomware strain now targets machine learning models directly. The operational silence from destructive actors is not reassurance - it is a warning.

I am a
My sector

DevelopmentSignificance
Pioneer Kitten / Fox Kitten silent for 31...The pattern that precedes coordinated activation...
Public exploit code released for four...10-21-year-old bugs affecting virtually every...
A novel "encryptionless" ransomware...No ransomware binary ever touched a Windows...
Eight new CISA ICS advisories...Widely deployed in energy, manufacturing, and...
JADEPUFFER agentic ransomware...Recovery requires retraining, not restoring...
UNC6779 (IRGC-linked) actively exploiting...A live, ongoing intrusion campaign
New Iran-themed C2 infrastructure...This pattern historically precedes new activity...

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran conflict begins, initiating sustained cyber...
PAYLOAD incident, Gulf wipers, silence beginsApr - Aug 2026PAYLOAD ransomware disrupts a Middle East...
BANISHED KITTEN pauses, ICS advisories surgeSep 15-17, 2026BANISHED KITTEN wiper campaign pauses; CISA...
Exploit code, tankers, AI ransomwareSep 18, 2026Linux quad-LPE exploits published; FBI...
Current (Day ~206) - active exploitation, new C2Sep 19-21, 2026UNC6779 actively exploiting Palo Alto...

In a confirmed Middle East manufacturing incident, the attacker gained access via a compromised FortiGate SSL VPN credential, escalated to domain admin, created a malicious GPO linked at the domain root, and used it to hijack wallpapers with ransom notes, disable local admin accounts, and disable Windows Firewall - exfiltrating data, but never...

T1078T1133T1484.001T1491.001T1531

These IRGC-affiliated groups maintain persistent access inside DIB and critical infrastructure networks, often through compromised VPN appliances. Thirty-one days is the longest observed dormancy for these actors during the conflict - not reassuring, but the pattern that precedes coordinated activation. A ceasefire collapse, a Hormuz incident...

T1078T1133

Public exploit code exists for four Linux kernel privilege escalation flaws, several hiding for over a decade: DirtyAH6 (IPsec AH6), TUNderflow (TUN/TAP), PPPoEject (PPPoE) - all requiring unprivileged user namespaces - and DiagSpill (SCTP), requiring no special privileges whatsoever. Any user on an unpatched system can...

T1068

JADEPUFFER exploits Langflow CVE-2025-3248 for initial access; its ENCFORGE payload targets ~180 file extensions tied to AI model checkpoints, vector databases, and training datasets. The ransomware operates autonomously - planning, executing, and self-correcting in ~31 seconds - following a destruction-first model that deletes originals before...

T1190T1485T1486

UNC6779 (IRGC-linked) is actively exploiting Palo Alto GlobalProtect (CVE-2026-0257, CVSS 9.1) against energy and utility networks as of Sep 19 - a live, ongoing intrusion campaign, not a theoretical risk. Combined with the Schneider Modicon M340 ICS advisory and known Iranian ICS targeting interest (Cyber Av3ngers, SPECTRAL KITTEN), energy...

T1190

ScenarioProbabilityTimeframeBasis
Linux kernel exploitation attempts surge as...70%48 hoursPublic exploit availability + zero-privilege...
BANISHED KITTEN wiper campaign resumes with...60%7 days6-day pause after sustained campaign; historical...
MuddyWater new campaign publicly reported...50%5–7 daysThreatStream profile updates without campaign...
Pioneer Kitten / Fox Kitten dormant access...40%30 days31-day silence; historical precedent of...
GPO-based encryptionless ransomware technique...35%30 daysTTP fits Iranian below-threshold disruption...
JADEPUFFER or copycat targets enterprise AI/ML...30%30 daysENCFORGE capability demonstrated; AI/ML assets...

1. Group Policy Object Abuse (T1484.001 — Domain Policy Modification: Group Policy Modification):

Hunting Hypothesis: An adversary with...

2. FortiGate VPN Credential Abuse (T1078 — Valid Accounts + T1133 — External Remote Services):

Hunting Hypothesis: Iranian actors use...

3. Linux Kernel Privilege Escalation (T1068 — Exploitation for Privilege Escalation):

Hunting Hypothesis: Attackers exploit...

4. JADEPUFFER / ENCFORGE AI Asset Targeting (T1190, T1486, T1485):

Hunting Hypothesis: Attacker exploits...

5. Iran-Themed C2 — Trojan-Spy.Win32.Noon (T1071.001, T1555):

Monitor: DNS queries and HTTP...

6. ICS/OT Monitoring (T1190, T0890, T0826, T0831):

Monitor: Network traffic to/from...

ThreatATT&CK
1. Group Policy Object Abuse (T1484.001 — Domain...T1484.001
2. FortiGate VPN Credential Abuse (T1078 — Valid...T1078 T1133
3. Linux Kernel Privilege Escalation (T1068 —...T1068
4. JADEPUFFER / ENCFORGE AI Asset Targeting...T1190 T1486...
5. Iran-Themed C2 — Trojan-Spy.Win32.Noon...T1071.001 T1555
6. ICS/OT Monitoring (T1190, T0890, T0826, T0831)T1190 T0890...
IOC Blocking Table:
irancepat[.]xyzhxxp://irancepat[.]xyz/nqf0hxxp://iranelectric[.]com/what-the-key-two-bridges45.131.66[.]10664.20.53[.]230

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01 · T1484.001
1. Group Policy Object Abuse (T1484.001 — Domain Policy Modification: Group Policy Modification)
An adversary with domain admin privileges creates or modifies GPOs linked at the domain root to achieve disruption without deploying malware.
HUNT 02 · T1078
2. FortiGate VPN Credential Abuse (T1078 — Valid Accounts + T1133 — External Remote Services)
Iranian actors use compromised or brute-forced FortiGate SSL VPN credentials for initial access, potentially from infrastructure dormant for weeks.
HUNT 03 · T1068
3. Linux Kernel Privilege Escalation (T1068 — Exploitation for Privilege Escalation)
Attackers exploit DiagSpill (CVE-2026-74469) via SCTP to escalate from any user to root on unpatched Linux servers.
HUNT 04 · T1190
4. JADEPUFFER / ENCFORGE AI Asset Targeting (T1190, T1486, T1485)
Attacker exploits Langflow CVE-2025-3248 to gain access to AI/ML infrastructure, then deploys ENCFORGE to destroy model artifacts.

Financial Services
AD Environments, VPN Access
Primary threat
The PAYLOAD GPO technique is directly applicable to institutions with large AD environments...
Actions
  • Audit FortiGate VPN accounts and enforce MFA; implement GPO change monitoring
Energy
ICS/SCADA, VPN Gateways
Primary threat
Most acute threat sector. UNC6779 actively exploiting Palo Alto GlobalProtect; 8 ICS advisories...
Actions
  • Patch Schneider Modicon M340 and Hitachi FACTS; verify Palo Alto GlobalProtect patched against CVE-2026-0257
Healthcare
Linux Servers, AD Environments
Primary threat
Legacy Linux systems vulnerable to quad-LPE; PAYLOAD technique would be devastating in hospital AD...
Actions
  • Patch Linux servers immediately; audit VPN access controls given PAYLOAD's entry vector
Government
DIB, Coalition Networks
Primary threats
Primary Iranian targeting priority, particularly coalition military operations and Five Eyes...
Actions
  • Commission a threat hunt for Pioneer Kitten/Fox Kitten dormant access - FortiGate logs, Rclone/Wasabi exfiltration indicators
Aviation / Logistics
DIB Contractors, Maritime
Primary threat
UNC6446 aerospace phishing campaigns active; maritime logistics under threat following tanker...
Actions
  • Review email security for aerospace phishing lures; audit DIB contractor FortiGate VPN access
No sector cards match the selected filters.

Block C2 domain irancepat[.]xyz and JADEPUFFER...
SOC Analyst
Patch all Linux kernel servers to remediate the quad-LPE...
Incident Responder
Implement GPO creation/modification monitoring - alert on new...
SOC Analyst
Audit all FortiGate SSL VPN accounts for compromised...
Incident Responder
No immediate actions for the selected roles.
Apply vendor patches for Schneider Modicon M340, Mitsubishi GX...
ICS / OT
Inventory Langflow/AI orchestration platforms; patch Langflow...
Incident Responder
Patch cPanel/WHM instances against CVE-2026-41940; disable...
Incident Responder
Monitor for JADEPUFFER cron beacons on port 4444; add...
SOC Analyst
No 7-day actions for the selected roles.
Commission a dedicated threat hunt for Pioneer Kitten/Fox...
Threat Hunter
Deploy a GPO integrity monitoring solution - AD integrity...
CISO / Exec
Update IR playbooks for GPO-based attack scenarios; tabletop...
CISO / ExecIncident Responder
Review cyber insurance coverage for AI asset destruction...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Seven months into this conflict, the Iranian cyber threat is not diminishing - it is maturing. The actors are more patient (31 days of silence from DIB access operators). The techniques are more sophisticated (GPO-based disruption that leaves no malware on disk). The targets are expanding (AI/ML infrastructure, maritime vessels, ICS across multiple vendors). And the vulnerability surface keeps growing. The single most important action you can take today is to stop treating silence as safety...

1
Commission a threat hunt for dormant access today.
2
Audit VPN logs and monitor GPOs this week.
3
Back up your AI models. The adversary is already inside.
No items found.