TLP:GREEN  ·  Iran / Israel Conflict
The Six-Month Mark:

Iran's Cyber Apparatus Is Pre-Positioned and the Clock Is Ticking

HIGH. Elevated from ELEVATED based on the convergence of three factors: confirmed active Iranian APT infrastructure and fresh indicators, a dramatic expansion of the exploitable attack surface through nine new CISA KEV additions in 48 hours, and the approaching window for Iranian retaliatory cyber operations following Supreme Leader Khamenei's first public address since the conflict began — an estimated 11-day retaliation window opening ~10 September 2026. One of Iran's most dangerous destructive-capability units, Cavern Manticore, has been silent for 28 days. That silence is not reassuring. It is a warning.

I am a
My sector

DateEventSignificance
26 Aug 2026CISA adds 6 KEVs; PULSAR KITTEN/APT33 satellite-telecom phishing confirmed by CrowdStrikeAttack surface expansion; IRGC targeting US military communications
26–27 Aug 20267 ICS advisories published (Rockwell OTTO, Fuel-Boss, Mitsubishi CNC, others)Military logistics and industrial control systems exposed to remote exploitation
27 Aug 2026CISA adds 3 additional KEVs (9 total in 48 hours)Accelerated vulnerability disclosure tempo signals active or imminent exploitation
28 Aug 2026APT42 BELLACIAO/SHELLAFEL campaign updated; APT34 profile refreshedOngoing MOIS and IRGC-IO operational activity
29 Aug 2026Cactus ransomware infrastructure expands on Tehran-based ASN 213790; MuddyWater attribution confirmedMOIS-linked ransomware scanning healthcare and government targets
30 Aug 2026Pioneer Kitten (UNC757/Lemon Sandstorm) ThreatStream profile updatedIRGC VPN/gateway exploitation specialist active; KEV weaponization window opens
30 Aug 2026Khamenei's first public address since conflict began; AdaptixC2 and Cobalt Strike/Agentemis C2 infrastructure detectedDeclaratory-to-action retaliation window opens (~10 September 2026)
30 Aug 2026APT34 IOCs refreshed — two SHA-256 hashes with credential theft and security tool evasion TTPsActive MOIS espionage tooling targeting energy, government, telecom, and financial services
30 Aug 2026Fire Ant (UNC3886-adjacent) Cisco IOS XR router compromise published by SygniaNovel router-level TTP template directly transferable to Iranian actors
31 Aug 2026ASN 213790 Tor exit node (Tehran) active at highest confidence; DinDoor/Tsundere botnet refreshedPersistent Iranian C2 infrastructure; MuddyWater tooling remains operational
31 Aug 2026Cavern Manticore (MOIS) enters 28th consecutive day of silenceSilence exceeds Iranian cyber operational baseline by 2.5x; consistent with pre-operational retooling ahead of Khamenei retaliation window

PhaseTimeframeCyber Activity
InitiationFeb 28 – Mar 2026Conflict begins; initial Iranian hacktivist surge (Handala, Cyber Toufan, DieNet); opportunistic defacements and DDoS.
EscalationApr – May 2026IRGC-linked APTs (APT33, APT42) shift to targeted espionage; Pioneer Kitten exploits VPN vulnerabilities for DIB access.
Pre-positioningJun – Jul 2026MuddyWater/Mango Sandstorm deploys Cactus ransomware infrastructure; CyberAv3ngers probe ICS/OT targets; IOCONTROL malware development confirmed.
Infrastructure buildAug 2026Cobalt Strike/Agentemis and AdaptixC2 C2 infrastructure detected on Iranian ASNs; APT34 refreshes operational tooling; Cavern Manticore goes silent (potential retooling).
Declaratory trigger — currentAug 30–31, 2026Khamenei's public address confirms Strait of Hormuz closure; estimated 11-day retaliation window opens ~10 September 2026. Cavern Manticore enters its 28th consecutive day of silence — 2.5x the Iranian cyber operational baseline.

APT34, Iran's premier MOIS-affiliated espionage group (also tracked as Hexane, Chrysene, and CALANQUE), refreshed indicators on 30–31 August with severity ratings of "very high." The associated TTPs are telling: these tools are designed to steal credentials from web browsers, query the Windows registry for security product configurations, disable or modify security tools, and evade debugging and sandbox analysis.

The targeting profile spans energy, government, telecom, financial services, and retail sectors across Switzerland, China, Jordan, and Turkey — a geographic spread consistent with APT34's historical pattern of casting a wide net before narrowing to high-value targets.

The inclusion of the efiguard rootkit family in the refreshed indicators is particularly concerning. Rootkit-level persistence suggests APT34 is preparing for long-dwell operations where maintaining access through patching cycles and incident response is a priority.

T1555.003T1012T1562.001T1497.002T1622T1014

MuddyWater continues to blur the line between espionage and disruption. The Cactus ransomware infrastructure expansion on ASN 213790 — the same Tehran-based network hosting active Tor exit nodes and C2 infrastructure — confirms that MOIS is using ransomware not primarily for financial gain, but as a disruptive and deniable weapon. The DinDoor/Tsundere botnet, refreshed on 31 August, provides the initial access and persistence layer for these operations.

Healthcare and government networks are the confirmed scanning targets. Organizations in these sectors should treat MuddyWater activity as a precursor to destructive operations, not conventional ransomware.

Cavern Manticore, the MOIS unit behind the MoKhargosh/Rusty Boots destructive wiper capability, has produced zero indicators for 28 consecutive days. This silence exceeds the Iranian cyber operational baseline of 11 days between declaratory trigger and action by a factor of 2.5.

Three hypotheses explain this silence, and none of them are benign: operational retooling — developing new destructive tooling or rotating infrastructure to evade detection before a major operation; a collection gap — the actor has pivoted to infrastructure outside current intelligence collection apertures; or disruption — allied operations have degraded the group's capability (least likely given no public reporting of such action).

The convergence of Khamenei's declaratory trigger and Cavern Manticore's silence should be treated as a high-priority warning indicator for destructive wiper operations targeting critical infrastructure.

Pioneer Kitten (also tracked as UNC757 and Lemon Sandstorm) had its ThreatStream profile updated on 30 August. This group's operational specialty — exploiting internet-facing VPN and gateway appliances — makes it the most likely Iranian actor to weaponize the current wave of KEV-listed vulnerabilities, particularly CVE-2026-8452 (Citrix NetScaler, CVSS 9.8). Historically, Pioneer Kitten has weaponized KEV-listed vulnerabilities within 7–14 days of listing and has served as an initial access broker for ransomware operators, creating a direct link between IRGC espionage and disruptive ransomware operations.

Additionally, APT33/PULSAR KITTEN's satellite-telecom phishing campaigns (confirmed by CrowdStrike on 26 August) target US military-relevant communications infrastructure, and APT42/Charming Kitten's BELLACIAO and SHELLAFEL campaigns were updated on 28 August with TAMECAT and NICECURL malware for credential harvesting.

T1190

While attributed to China, the Fire Ant compromise of Cisco IOS XR routers published by Sygnia on 30 August is directly relevant to the Iran threat picture. The techniques demonstrated — TACACS credential harvesting via library injection, packet-triggered backdoors with magic strings, GRE tunnel creation for covert channels, and rootkit deployment masquerading as EDR agents — represent a capability template that Iranian actors are positioned to adopt.

This is not theoretical. TRACER KITTEN already conducts telecom-level interception operations, and Pioneer Kitten targets Cisco Firepower Management Center infrastructure. The Fire Ant playbook shows these actors exactly how to move from network appliance exploitation to persistent, stealthy router-level compromise.

T1556T1205.001T1014T1036

ProbabilityScenarioBasis
75–85%Iranian APT exploitation of CVE-2026-8452 (Citrix NetScaler) or CVE-2026-55040 (SharePoint) within 14 daysPioneer Kitten's 7–14 day KEV weaponization pattern; public PoC availability
60–70%APT34/APT42 campaign refresh produces new C2 infrastructure within 72 hoursIOC refresh cadence observed 30–31 Aug indicates active operational cycle
50–60%Cavern Manticore silence breaks with destructive wiper deployment or detectable infrastructure rotation28-day gap consistent with pre-operational retooling; Khamenei's address provides political authorization
40–50%MuddyWater Cactus ransomware deployed against healthcare or government targetsActive scanning confirmed; infrastructure on ASN 213790 operational
30–40%IRGC-proxy hacktivist groups (Handala, Cyber Toufan, DieNet) resume operations with coordinated campaign22+ days of silence may indicate infrastructure rebuild; historically surge around geopolitical inflection points
25–35%Iranian actors adopt Fire Ant router-level TTPs for Cisco IOS XR compromiseTTP transferability is high; timeline depends on Iranian R&D cycle
Near-certainContinued exploitation of Zimbra CVE-2026-73570 across all sectorsAlready actively exploited per CERT.PL; broad attack surface

1. APT34 Credential Theft and Security Tool Evasion:

Hunt hypothesis: APT34 operators deploy rootkit-enabled implants that disable endpoint security tools before harvesting browser credentials. Look for processes that query security product registry keys followed by service stop/modification events. Detection logic: Alert on any process that enumerates HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall for security product keys AND subsequently attempts to stop or modify security services. Correlate with browser credential store access (Login Data, logins.json file reads). Blocking action: Deploy the following SHA-256 hashes to EDR block lists and SIEM correlation rules: - 6013d7e0c4a54c78c846836da9e70785b3b8ca1f0b9d76fa88129baa5a4805dc - 5de4e2b07a26102fe527606ce5da1d5a4b938967c9d380a3c5fe86e2e34aaaf1

2. Cisco IOS XR Router Compromise (Fire Ant TTP Template):

Hunt hypothesis: Adversaries compromise Cisco IOS XR routers via TACACS server exploitation, deploy credential-harvesting libraries, and establish covert GRE tunnels for data exfiltration. Masquerading as legitimate monitoring agents (Zabbix, SentinelOne) provides persistence. Detection logic: - Monitor for GRE tunnel interface creation on IOS XR devices without corresponding configuration commit in the change management system - Alert on file creation at /var/log/.tacplus.acct on any TACACS server - Detect systemd services named zabbix_agent.service on hosts where Zabbix is not deployed; inspect config files at /opt/.ICEauthority - Monitor for processes named acpid, dhcpd_show_issu_status, or hd in unexpected paths (/usr/bin/acpid, /pkg/bin/) - Alert on outbound connections to TCP ports 443, 541, 8443, 10443 or UDP source port 40443 to destination port 500 from router management interfaces IOCs to deploy: - SHA-1: 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00 (TacTap injector) - SHA-1: 955cd45a2f6f226a2fdf44b329af1c8dde90cb38 (TacTap library) - SHA-1: be6b27f429324a4af05a310d8ec9635e37c68a94 (IOS XR implant) - SHA-1: 1682b652a15bde732489f22809b0b7594c228fd3 (IOS XR implant) - SHA-1: b149fa3a34bd585e7a674a4fd9538437bd06f514 (IOS XR implant) - SHA-1: 13f0c2a598e3aa63856c032a96b110aed963f0e8 (VMCI backdoor) - SHA-1: 5ba1242050b5b447052b210788a5a25593d6987d (packet-triggered backdoor)

3. Iranian C2 Infrastructure Monitoring:

Hunt hypothesis: Iranian operators use Tehran-based ASN 213790 for Tor-anonymized C2 callbacks and Cobalt Strike/Agentemis beacon infrastructure. Connections to this ASN from internal hosts indicate potential compromise. Detection logic: Alert on any outbound connection to ASN 213790 or IP 77.90.185[.]93. Correlate with Cobalt Strike beacon detection signatures. Monitor DNS resolution for appleid.iran-rom[.]ir and iran-rom[.]ir. Network IOCs to block/alert: - IP: 77.90.185[.]93 (Tor exit node, ASN 213790, Tehran) - Domain: appleid.iran-rom[.]ir (phishing infrastructure) - Domain: iran-rom[.]ir (phishing infrastructure)

4. Browser Extension Supply Chain Monitoring:

Hunt hypothesis: Adversaries acquire or poison legitimate browser extensions to remove Content Security Policy headers, inject JavaScript, and steal session tokens — bypassing MFA. Detection logic: Monitor for browser extensions requesting permissions to modify HTTP headers (especially CSP removal). Alert on extension ownership transfers in enterprise extension management. Flag extensions with sudden permission escalation in update manifests.

ThreatATT&CK
1. APT34 Credential Theft and Security Tool EvasionT1562.001 T1555.003 T1012 T1027 T1497.002 T1622
2. Cisco IOS XR Router Compromise (Fire Ant TTP Template)T1556 T1205.001 T1014 T1036 T1003 T1070
3. Iranian C2 Infrastructure MonitoringT1090.003 T1573
4. Browser Extension Supply Chain MonitoringT1195.002 T1185 T1539 T1059.007
IOC Blocking Table:
77.90.185[.]93appleid.iran-rom[.]iriran-rom[.]irhttp://appleid.iran-rom[.]ir/

Network indicators: 77.90.185[.]93 (Tor exit node, ASN 213790, Tehran); appleid.iran-rom[.]ir and iran-rom[.]ir (APT phishing infrastructure). APT34 file hashes (SHA-256): 6013d7e0c4a54c78c846836da9e70785b3b8ca1f0b9d76fa88129baa5a4805dc, 5de4e2b07a26102fe527606ce5da1d5a4b938967c9d380a3c5fe86e2e34aaaf1 (efiguard rootkit). Fire Ant hashes (SHA-1): 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00, 955cd45a2f6f226a2fdf44b329af1c8dde90cb38, be6b27f429324a4af05a310d8ec9635e37c68a94, 1682b652a15bde732489f22809b0b7594c228fd3, b149fa3a34bd585e7a674a4fd9538437bd06f514, 13f0c2a598e3aa63856c032a96b110aed963f0e8, 5ba1242050b5b447052b210788a5a25593d6987d. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01
5. Cavern Manticore Proactive Hunt
Hunt hypothesis: After 28 days of silence, Cavern Manticore may have rotated to new infrastructure. Hunt for MoKhargosh/Rusty Boots wiper variants and new C2 domains on Iranian ASNs. Detection logic: Query passive DNS for new domains resolving to Iranian IP ranges (ASN 213790 and adjacent). Monitor for wiper-characteristic behaviors: mass file enumeration followed by overwrite operations, MBR modification attempts, and service deletion commands. Alert on vssadmin delete shadows or wmic shadowcopy delete commands in combination with mass file operations.

Financial Services
Trading Floors, Browser Extensions
Primary threat
Iranian APT34 indicators refreshed this week explicitly target the financial services sector. The combination of browser credential theft and security tool evasion is designed for environments with mature endpoint protection — exactly the profile of major financial institutions.
Secondary threat
Key CVE: CVE-2026-55040 (SharePoint authentication bypass, CVSS 9.1) — public proof-of-concept code is available.
Actions
  • Deploy APT34 SHA-256 hashes to endpoint block lists. Validate that EDR tamper protection is enabled and alerting on disable attempts
  • Audit browser extension policies across trading floors and privileged user workstations — high-value targets for session token theft via poisoned extensions
  • Conduct a red team exercise simulating APT34's credential theft chain: registry enumeration → security tool disablement → browser credential extraction → lateral movement
Energy
Fuel Management, ICS/SCADA, OT Routers
Primary threats
The energy sector sits at the intersection of multiple Iranian threat vectors: APT34 espionage (efiguard rootkit targeting energy), CyberAv3ngers ICS sabotage, and MuddyWater ransomware-as-disruption.
Secondary threat
Key CVEs: CVE-2026-8452 (Citrix NetScaler, CVSS 9.8) for remote access infrastructure; CVE-2026-21962 (Oracle WebLogic, CVSS 10.0) for ERP/logistics systems.
Actions
  • Validate ICS patching posture against CISA advisories ICSA-26-239-02 (Fuel-Boss RCE) and ICSA-26-239-03 (Rockwell OTTO Fleet Manager brute force)
  • Segment OT networks from IT networks with explicit deny-all rules. Monitor for IOCONTROL malware signatures on PLCs and RTUs
  • Commission an assessment of Cisco IOS XR routers in OT network segments — the Fire Ant TTP template demonstrates router-level compromise can bypass all downstream security controls
Healthcare
Email Infrastructure, Backup Systems
Primary threat
MuddyWater's Cactus ransomware infrastructure on ASN 213790 is actively scanning healthcare targets. This is not conventional ransomware — it is MOIS-directed disruption using ransomware as a deniable weapon.
Secondary threat
Key CVE: CVE-2026-73570 (Zimbra RCE) — actively exploited in the wild per CERT.PL. Healthcare organizations should treat unpatched Zimbra instances as compromised.
Actions
  • Block ASN 213790 at the network perimeter. Deploy Cactus ransomware detection signatures
  • Validate that backup systems are air-gapped and tested for restoration within RTO
  • Patch Zimbra Collaboration Suite to version 10.1.20+
  • Conduct a tabletop exercise simulating a MuddyWater-attributed ransomware attack during peak patient load — include scenarios where the attacker's goal is disruption, not extortion
Government
SharePoint, VPN, Destructive-Attack Readiness
Primary threats
Government networks face the full spectrum of Iranian cyber capability: APT34 and APT42 for espionage, MuddyWater for disruption, Cavern Manticore for destruction, and IRGC-proxy hacktivists for information operations.
Secondary threat
The approaching Khamenei retaliation window (~10 September 2026) places government networks at elevated risk for destructive operations. Ensure incident response plans are current and tested.
Actions
  • Deploy all APT34 and Fire Ant IOCs from this report. Validate that SharePoint instances are patched against CVE-2026-55040 and CVE-2026-63520 — these chain together for unauthenticated RCE
  • Audit Citrix NetScaler ADC/Gateway configurations (CVE-2026-8452, CVSS 9.8) — Pioneer Kitten has been attributed to exploitation of this vulnerability
  • Commission a proactive threat hunt for Cavern Manticore infrastructure rotation — hunt for MoKhargosh/Rusty Boots variants, new C2 domains on Iranian ASNs, and wiper precursor behaviors
Aviation / Logistics
Satellite-Telecom, Fuel Management, CI/CD
Primary threat
APT33/PULSAR KITTEN's confirmed targeting of satellite-telecom infrastructure and Pioneer Kitten's historical focus on aerospace/defense contractors make this sector a primary target. The Fuel-Boss ICS advisory adds a physical-world dimension.
Secondary threat
Supply chain compromise through DIB contractors remains the primary attack vector — audit CI/CD pipelines and pin all dependencies to verified commit SHAs.
Actions
  • Brief security operations teams on APT33 satellite-telecom phishing TTPs. Validate email security controls for credential harvesting campaigns
  • Audit PTC Windchill and Fortinet FortiOS/FortiClient deployments in engineering environments; validate VPN appliances are patched against current KEVs
  • Assess fuel management systems (Fuel-Boss or equivalent) deployed at airports and logistics hubs — segment from enterprise networks and monitor for unauthorized command execution
No sector cards match the selected filters.

Deploy APT34 SHA-256 hashes and Fire Ant SHA-1 hashes (listed above) to EDR block lists and SIEM correlation rules.
SOC Analyst
Block IP 77.90.185[.]93 and domains appleid.iran-rom[.]ir / iran-rom[.]ir at network perimeter; alert on any internal host connection to ASN 213790.
SOC Analyst
Patch Zimbra Collaboration Suite to 10.1.20+ (CVE-2026-73570, actively exploited); disable the zimbra-snmp package if SNMP notifications are not required.
Incident Responder
Hunt the Cisco IOS XR estate for GRE tunnel interfaces without configuration commit history; check TACACS servers for /var/log/.tacplus.acct file creation.
Threat Hunter
Validate Citrix NetScaler ADC/Gateway patched against CVE-2026-8452 (CVSS 9.8, KEV-listed); confirm no SSL VPN/Gateway configurations are internet-exposed without patching.
Incident Responder
Patch Microsoft SharePoint against CVE-2026-55040 (auth bypass, CVSS 9.1) and CVE-2026-63520 (RCE, CVSS 8.1) — public PoC available for the former.
Incident Responder
No immediate actions for the selected roles.
Audit all browser extensions enterprise-wide against an approved allowlist; implement monitoring for ownership transfers and permission escalations in extension manifests.
Incident Responder
Create detection rules for Cisco IOS XR GRE tunnel creation without configuration commits; alert on zabbix_agent.service systemd units on non-Zabbix hosts.
SOC Analyst
Validate Oracle WebLogic patched against CVE-2026-21962 (CVSS 10.0); audit Windows IKE service exposure for CVE-2026-33824 (CVSS 9.8).
Incident Responder
Implement TACACS authentication logging to a tamper-resistant SIEM; alert on library modifications in TACACS server directories.
SOC Analyst
Brief executive leadership on the approaching Khamenei retaliation window (~10 September 2026) and the elevated probability of destructive cyber operations.
CISO / Exec
No 7-day actions for the selected roles.
Commission a proactive threat hunt for Cavern Manticore infrastructure rotation — 28 days of silence exceeds Iranian cyber operational baselines by 2.5x; hunt for MoKhargosh/Rusty Boots variants on Iranian ASNs.
CISO / ExecThreat Hunter
Conduct a tabletop exercise simulating an Iranian destructive wiper attack on critical systems; include scenarios where ransomware is deployed without decryption capability.
CISO / Exec
Assess ICS asset inventory for Fuel-Boss, Rockwell OTTO Fleet Manager, and Mitsubishi CNC/FA systems; validate segmentation and patching posture against CISA ICS advisories.
ICS / OT
Evaluate router integrity monitoring capability for Cisco IOS XR — configuration drift detection, memory forensics, and out-of-band management verification.
Incident Responder
Update incident response playbooks for destructive wiper scenarios; pre-position forensic imaging tools and validate offline backup restoration procedures.
Incident Responder
Pin all CI/CD pipeline dependencies (GitHub Actions, container images) to verified commit SHAs; audit for unauthorized pipeline modifications over the past 90 days.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

We are at the six-month mark of a conflict in which Iran has consistently demonstrated that cyber operations are its preferred tool for below-threshold retaliation. The intelligence picture as of 31 August 2026 shows an adversary that is not winding down — it is loading the chamber. Fresh APT34 tooling is circulating with capabilities specifically designed to defeat enterprise security controls. MuddyWater is scanning healthcare and government targets with ransomware infrastructure hosted on Iranian networks. Nine new exploitable vulnerabilities were added to the KEV catalog in 48 hours, and Pioneer Kitten's historical pattern says weaponization follows within two weeks. A China-nexus actor just published a router-compromise playbook that Iranian groups operating on the same Cisco infrastructure can adopt wholesale. And Cavern Manticore — the MOIS unit with destructive wiper capability — has been silent for 28 days while the Supreme Leader publicly authorized retaliation. The window between now and mid-September is not a time for routine operations. It is a time for accelerated patching, proactive hunting, and executive-level preparation for destructive scenarios.

1
The indicators are on the table. The TTPs are documented. The retaliation window is opening.
2
The organizations that act on this intelligence in the next 72 hours will be the ones that are prepared when the silence breaks.
3
Patch your VPN gateways and SharePoint instances. Hunt for Cavern Manticore infrastructure rotation. Brief your executives on the September 10 window.
No items found.