TLP:GREEN  ·  Iran / Israel Conflict
The Silence Before the Storm:

Iranian Cyber Operations Enter a Dangerous Pre-Positioning Phase as Critical Zero-Days Emerge

HIGH. Escalated from ELEVATED. Day 212 of the US-Iran conflict. Two critical Citrix NetScaler zero-days entered active exploitation globally, Oracle PeopleSoft is under renewed mass attack, and Iranian-hosted Cobalt Strike C2 - including a node on Iran's state telecom backbone - remains persistently operational. Meanwhile MuddyWater, BANISHED KITTEN, Handala, and HYDRO KITTEN have all gone silent for 19+ days. History tells us what comes next.

I am a
My sector

DevelopmentSignificance
Citrix NetScaler dual zero-day...Iranian actors have weaponized past Citrix flaws...
Oracle PeopleSoft mass exploitation...The exploitation technique is trivially...
Microsoft SharePoint RCE...Additional perimeter attack surface
Kiteworks issued an unprecedented...Signals credible, specific threat intelligence...
JADEPUFFER/Storm-3168 Azure cloud...A template directly replicable by Iranian actors...
Iranian-hosted Cobalt Strike C2...Indicates persistent, state-aware pre-positioned...
Coordinated operational silence...Consistent with pre-campaign retooling across...
UNC6446/GRITCASPIAN updated its...Active IRGC-linked intelligence collection...

PhaseTimeframeCyber Activity
ICS integrator warningSep 23, 2026FBI/CISA publish joint fact sheet on third-party...
SharePoint and Kiteworks emergencySep 25, 2026SharePoint RCE added to KEV; Kiteworks issues...
PeopleSoft mass exploitation confirmedSep 25, 2026Mandiant/GTIG documents ShinyHunters/UNC6240...
Citrix dual zero-day, phishing campaign updatedSep 27, 2026CISA adds Citrix NetScaler dual zero-day to KEV...
Current (Day 212) - C2 confirmed persistentSep 28, 2026Iran-hosted Cobalt Strike C2 infrastructure...

CVE-2026-88771 (CVSS 9.5) enables unauthenticated arbitrary command execution; CVE-2026-88772 is a memory buffer flaw triggered by default DTLS configuration on VPN virtual servers. CISA, Rapid7, and TheHackerNews all confirmed active global exploitation the same day.

Pioneer Kitten (UNC757) weaponized CVE-2023-3519 within five days of...

T1190T1059T1133

ShinyHunters (UNC6240) exploits CVE-2026-35273 via a single-character WAF bypass (/%50SEMHUB/ instead of /PSEMHUB/). Post-exploitation includes dual JSP web shells, fileless execution, the SIDEEYE backdoor, MeshAgent, and a trojanized binary. Targets have expanded from education to healthcare, agriculture...

T1190T1505.003T1027

Storm-3168 conducted an 18-hour Azure destruction operation from two service principals whose credentials were exposed in a public GitHub issue: 300+ reconnaissance operations over 16 hours, then 150+ destructive operations in 35 minutes, deleting Storage Accounts, SQL databases, Key Vaults, and VMs. Azure resource locks blocked some deletions...

T1078.004T1485T1490

Four IPs confirmed active: two Agentemis/Cobalt Strike BEACON servers (ports 443/53 - port 53 is DNS-based evasion), a Chaos/FakeRyuk/Yashma server, and an unknown-malware server on Iran's state TIC telecom backbone. This infrastructure has been continuously active for months.

If this infrastructure suddenly goes dark, it may...

T1071.001T1071.004T1573

MuddyWater (19 days, vs. typical 7-14), BANISHED KITTEN (20+ days), Handala (20+ days), and HYDRO KITTEN (19 days) have all gone quiet simultaneously - across state espionage, hacktivist proxy, and ICS targeting tracks. This pattern is more consistent with coordinated restraint before action than coincidence.

The FBI/CISA ICS integrator...

ScenarioProbabilityBasis
Iranian actors attempt exploitation of...70%Pioneer Kitten weaponized CVE-2023-3519 within 5...
MuddyWater breaks operational silence with a new...50%19-day silence matches pre-campaign retooling...
Pro-Iran hacktivist groups (BANISHED KITTEN...40%20+ day quiet period is historically unusual and...
Iranian actors exploit supply-chain access...35%FBI/CISA fact sheet timing suggests active...
Kiteworks zero-day is disclosed and exploitation...25%Federal intelligence was credible enough to...

1. Citrix NetScaler Exploitation (CVE-2026-88771 / CVE-2026-88772):

Hunt hypothesis: Attackers are...

2. Oracle PeopleSoft WAF Bypass (CVE-2026-35273):

Hunt hypothesis: Attackers are...

3. Iranian C2 Infrastructure Monitoring:

Hunt hypothesis: Iranian-hosted...

5. Cloud Service Principal Security (JADEPUFFER Template):

Hunt hypothesis: Compromised...

ThreatATT&CK
1. Citrix NetScaler Exploitation (CVE-2026-88771...T1190 T1059...
2. Oracle PeopleSoft WAF Bypass (CVE-2026-35273)T1190 T1505.003...
3. Iranian C2 Infrastructure MonitoringT1071.001 T1071.004...
5. Cloud Service Principal Security (JADEPUFFER...T1078.004 T1580...
IOC Blocking Table:
217[.]60[.]241[.]1787[.]107[.]191[.]3994[.]184[.]37[.]6878[.]39[.]51[.]23yzs[.]fiigreenfaturas[.]toigreenfaturas[.]comwattiofaturas[.]comnuvfaturas[.]coma55scd[.]comx.jsp, u.jsp, u2.jsptunnel.jsp, tunnel.jspxPle64.exePSEMHUB.war directory

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01 · T1566.001
4. MuddyWater Proactive Hunt
Hunt hypothesis: MuddyWater's 19-day operational silence during an active retaliation window indicates retooling; the next campaign will likely leverage cloud/SaaS vectors. Detection actions: - Search for Power Automate abuse — unauthorized flow creation, especially flows that exfiltrate data or create persistence - Hunt for Teams device-code phishing attempts (unusual OAuth device authorization flows) - Monitor for DinDoor/Deno runtime C2 callbacks — look for deno or Node.js-like processes in unexpected locations - Alert on Agentemis BEACON traffic patterns across all monitored network segments
HUNT 02
1. Citrix NetScaler Exploitation (CVE-2026-88771 / CVE-2026-88772)
Attackers are exploiting unauthenticated command injection on internet-facing NetScaler appliances to establish persistent access.
HUNT 03
2. Oracle PeopleSoft WAF Bypass (CVE-2026-35273)
Attackers are bypassing WAF rules using URL-encoded paths to reach the PSEMHUB deserialization endpoint and deploy web shells.
HUNT 04
3. Iranian C2 Infrastructure Monitoring
Iranian-hosted Cobalt Strike BEACON infrastructure is being used for pre-positioned access into target networks, with DNS-based C2 on port 53 to evade standard web traffic monitoring.
HUNT 05
5. Cloud Service Principal Security (JADEPUFFER Template)
Compromised service principal credentials exposed in code repositories are being used for cloud reconnaissance and destruction.

Financial Services
Cloud Infrastructure, Remote Access
Primary threat
Cloud resource destruction (JADEPUFFER template) and credential harvesting via compromised service...
Actions
  • Enforce Azure resource locks on production Storage/SQL/Key Vaults; patch Citrix NetScaler for trading platform remote access
Energy
ICS/OT, Third-Party Integrators
Primary threat
HYDRO KITTEN has demonstrated willingness to target energy ICS; FBI/CISA integrator fact sheet...
Actions
  • Audit third-party ICS integrator access; block Iran-hosted C2 IPs at the OT perimeter, not just IT
Healthcare
PeopleSoft, Personnel Records
Primary threat
Explicitly confirmed target for ShinyHunters/UNC6240 PeopleSoft exploitation; IMPERIAL KITTEN...
Actions
  • Audit PeopleSoft deployments for WAF-bypass exploitation; inspect PSEMHUB.war for unauthorized web shells
Government
NetScaler, PeopleSoft, SharePoint
Primary threats
Primary target for Citrix zero-day exploitation, PeopleSoft personnel data collection, and UNC6446...
Actions
  • Patch NetScaler by the Sep 30 deadline; conduct forensic review before patching for signs of prior compromise
Aviation / Logistics
Aerospace, Maritime
Primary threat
UNC6446/GRITCASPIAN and IMPERIAL KITTEN both actively target aerospace and defense personnel...
Actions
  • Brief teams on UNC6446 GitHub phishing lures; review maritime system security (FURUNO, NAVTOR, AIS/ECDIS)
No sector cards match the selected filters.

Patch all Citrix NetScaler appliances to...
Incident Responder
Block WAF-bypass patterns for Oracle PeopleSoft; enforce...
SOC Analyst
Add Iran-hosted C2 IPs to blocklist/watchlist; monitor for...
SOC Analyst
Review NetScaler Console for Citrix-published IoCs immediately...
Incident Responder
No immediate actions for the selected roles.
Audit Azure service principal credentials for GitHub exposure...
Incident Responder
Verify Kiteworks deployments are on version 9.5.1; review auth...
Incident Responder
Conduct a proactive threat hunt for MuddyWater TTPs - Power...
Threat Hunter
Review SharePoint deployments for CVE-2026-65660 exploitation...
Incident Responder
No 7-day actions for the selected roles.
Audit all third-party ICS integrator access per the FBI/CISA...
ICS / OT
Conduct a tabletop exercise simulating coordinated Iranian...
CISO / ExecIncident Responder
Review and harden edge device inventory given the accelerating...
CISO / Exec
Evaluate alternative intelligence collection sources to avoid...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Persistent C2 infrastructure on Iranian state networks, coordinated silence across multiple Iranian threat groups spanning different operational mandates, accelerating edge device exploitation, and a federal intelligence community actively warning about ICS supply-chain compromise - this is not ambiguous. This is what pre-positioning looks like. The Citrix NetScaler dual zero-day is the most urgent tactical threat, with a narrow window before the September 30 federal deadline. But the strategic...

1
Patch Citrix. Hunt for web shells in PeopleSoft.
2
Block Iranian C2 infrastructure. Audit your cloud service principals.
3
Review ICS integrator access. Run the tabletop. The window is closing.
No items found.