TLP:GREEN  ·  Iran / Israel Conflict
When 100 Water Systems Fall:

Iran's Cyber War on Critical Infrastructure Enters Its Most Dangerous Phase

CRITICAL. Unchanged from the prior cycle. Six months into the Iran–United States kinetic conflict, Iranian cyber operations have crossed a threshold that demands immediate executive attention. On September 1, CISA publicly confirmed that over 100 municipal water systems across at least 12 US states have been compromised by Iranian-linked hackers — the single largest confirmed Iranian offensive cyber operation against American critical infrastructure in history. The attackers are inside operational technology networks right now, armed with a malware family designed to both steal data and destroy industrial control systems.

I am a
My sector

DevelopmentSignificance
CISA confirmed 100+ US water systems compromised across 12+ states by Iranian hackers exploiting default credentials and open ports — low sophistication, catastrophic scale.Largest confirmed Iranian offensive cyber operation against American critical infrastructure in history
NBC News reported Iranian cyberattack attempts against US energy, telecom, and transportation — the first public confirmation that targeting has expanded well beyond water systems.Confirms the declaratory Telegram threat was not empty rhetoric
An Iranian hacking group issued an explicit Telegram threat warning of "unexpected and critical events" targeting American infrastructure — declaratory language that historically precedes operational escalation.Declaratory threats have historically preceded Iranian operational escalation by ~24 hours
Forbes confirmed AI-augmented exploitation tools are being used against Siemens PLCs in water systems — a capability threshold crossing that compresses exploit development timelines.Actors can now target niche and legacy PLCs without deep domain expertise
CISA published nine ICS advisories in a single day, including remote code execution vulnerabilities in Rockwell Automation ControlFLASH and IXON VPN — dramatically expanding the available attack surface.15+ ICS advisories in 3 days is an unusually high volume signaling emergency-level attack surface expansion
SPECTRAL KITTEN (MOIS-linked) was confirmed to have compromised an Israeli electrical utility, marking a shift from destructive "lock-and-leak" operations to covert intelligence gathering against energy infrastructure.Behavioral shift from destruction to espionage may indicate battle damage assessment collection
CALANQUE ION deployed TAMECAT malware against the nuclear sector, with tool-sharing between APT34 and APT42 suggesting wartime consolidation of Iranian cyber units.Detection signatures built for one MOIS actor should now be cross-applied to both
Two critical Ivanti EPMM vulnerabilities (CVE-2026-1281 and CVE-2026-1340, CVSS 9.8) have active exploitation campaigns in the wild; Iranian adoption is assessed as imminent given the group's documented history with Ivanti CVEs.Iranian adoption of newly weaponized vulnerabilities is a matter of when, not if
MuddyWater and Cavern Manticore remain operationally silent — anomalous during a period of kinetic escalation and historically a leading indicator of major retooling or pre-positioning for destructive operations.Silence from Iran's most capable destructive units is a warning signal, not reassurance

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran-US kinetic conflict begins, initiating sustained state-directed cyber campaign against Western infrastructure.
Espionage shift & UK precedentMid-Jun – Mid-Aug 2026SPECTRAL KITTEN compromises an Israeli electrical utility, marking a shift from destructive "lock-and-leak" operations to covert energy-sector espionage; NPR reports Iranian cyberattacks on US water infrastructure; an Iranian attack disables a UK power plant for 4 days — first confirmed kinetic-effect cyber operation against allied infrastructure.
AI capability threshold & escalating reportsAug 21–25, 2026Forbes confirms AI-augmented Siemens PLC exploitation — a capability threshold crossing that compresses OT exploit development cycles; The Hill and Al Jazeera report expanding water infrastructure attacks, with the FBI investigating Iranian-linked attacks across 7+ US states.
Declaratory threat & kinetic resumptionAug 31 – Sep 1, 2026"APT IRAN" issues a Telegram threat against US energy, water, and telecom infrastructure ~24 hours before kinetic strikes resume; the US strikes Iranian coastal positions near the Strait of Hormuz and Iran retaliates against US bases across 5 countries; CISA confirms 100+ US water systems compromised — the largest confirmed Iranian OT intrusion campaign; CISA publishes 6 Rockwell Automation ICS advisories.
Current (Day 189) — targeting expands, MOIS consolidatesSep 2–4, 2026NBC reports Iranian cyber attempts expanding to energy, telecom, and transportation; CISA publishes 9 additional ICS advisories (Rockwell, Schneider, IXON VPN); CALANQUE ION/TAMECAT nuclear-sector campaign updated, with APT34-APT42 tool-sharing confirmed — suggesting wartime consolidation of Iranian cyber units.

The CISA disclosure is a watershed moment. Cyber Av3ngers, an IRGC-affiliated group operating under the Shahid Hemmat umbrella, has compromised over 100 municipal water systems using a malware family known as IOCONTROL (also tracked as SalatStealer and SewerGoo).

IOCONTROL is not a simple backdoor. It is a dual-use OT weapon capable of both data exfiltration and system destruction — it can steal operational data from Linux-based PLCs and wipe them. Two active samples remain in circulation with very-high severity ratings. The attack methodology was disturbingly simple: default credentials and open ports on internet-facing SCADA systems. Utah was specifically named as lacking "foundational protections."

What makes this campaign uniquely dangerous is the AI augmentation. Forbes confirmed that Iranian-backed hackers are using AI-generated exploitation tools to target vulnerable Siemens PLCs — exploit development cycles are compressing, and patch-to-exploit windows are shrinking.

T1078T1190T1485T1565.001

NBC News reporting confirms what the Telegram threat foreshadowed: Iranian cyber operations are expanding beyond water systems to target energy, telecommunications, and transportation infrastructure. While NBC characterized attempts against these sectors as "so far unsuccessful," the declaratory language — "unexpected and critical events" — maps to a well-established Iranian pattern of signaling intent before operational escalation.

This expansion is consistent with multiple tracked Iranian actor groups operating simultaneously: Cyber Av3ngers (IRGC/Shahid Hemmat) on water/energy/utilities; SPECTRAL KITTEN (MOIS/Jahat Pardaz) on energy, telecom, financial services; APT42/Charming Kitten (IRGC-IO) on government, nuclear, defense; APT34/OilRig (MOIS) on nuclear, energy, government; and Nimbus Manticore/UNC1549 (IRGC-linked) on defense and aerospace.

On September 3, CISA published nine ICS advisories covering products at the heart of industrial control environments. The Rockwell ControlFLASH RCE and IXON VPN RCE are the highest-priority items. ControlFLASH allows arbitrary command execution on industrial controllers. IXON VPN is widely used for remote OT access — an RCE on the client machine means an attacker can pivot from IT networks directly into OT environments through the VPN tunnel. In the context of active Iranian ICS campaigns targeting these exact product families, these vulnerabilities represent an immediate patching emergency. Additional advisories cover OPC UA LocalDiscoveryServer (privilege escalation), Rockwell ArmorStart LT (DoS/code injection), Rockwell 1756-ENBT Module (crash), Inductive Automation Ignition (unauthorized project creation), Schneider Electric (Easergy/EcoStruxure/PowerLogic/Saitel), and two Tycon Systems TPDIN-Monitor products.

T1190

The CALANQUE ION campaign targeting the nuclear sector deployed TAMECAT, a backdoor historically associated with APT42/Charming Kitten. Its appearance in an APT34/OilRig-adjacent campaign is significant — it suggests either deliberate tool-sharing between MOIS cyber units, a joint operation, or APT42 operators embedded within an APT34-led campaign.

If confirmed, this collapses a long-standing analytical assumption that APT34 and APT42 operate independently. Under wartime pressure, MOIS may be consolidating its cyber units, meaning IOC sets previously attributed to one group should now be treated as potentially shared across both — with direct implications for detection engineering.

Separately, two critical vulnerabilities in Ivanti Endpoint Manager Mobile — CVE-2026-1281 and CVE-2026-1340 (both CVSS 9.8, unauthenticated RCE) — have active exploitation campaigns already detected in the wild. Iranian actors have a well-documented history of rapidly adopting Ivanti vulnerabilities.

T1566.001T1204.002T1059.001T1547.001

MuddyWater (TEMP.Zagros / Static Kitten / Seedworm) is Iran's most prolific MOIS cyber unit. Their operational silence during a period of kinetic escalation is historically anomalous and has preceded major retooling or operational shifts. Cavern Manticore's silence carries the same ominous pattern — quiet before destructive operations.

This silence is itself a warning signal, not reassurance — historically, extended quiet periods from Iran's most destructive units precede major campaigns.

ScenarioProbabilityBasis
Additional CISA ICS advisories and/or KEV additions for industrial control productsHIGH (>75%)Advisory cadence is accelerating; 15 ICS advisories in 3 days
Iranian hacktivist groups (Handala, Cyber Toufan) break silence with coordinated wiper or data leak operationMODERATE-HIGH (50–70%)Operational silence during kinetic escalation historically precedes major operations
MuddyWater resurfaces with retooled infrastructure and new campaignMODERATE-HIGH (50–70%)Actor profile updated Sep 2 with no new campaign reporting — suggests tracked but unreported activity
Iranian actors adopt Ivanti EPMM CVE-2026-1281/1340 for initial accessMODERATE (30–50%)Active exploitation in the wild + Iranian history with Ivanti CVEs
Destructive cyber operation against US or allied energy infrastructureMODERATE (30–50%)SPECTRAL KITTEN energy-sector reconnaissance + Cyber Av3ngers declaratory threats + AI-augmented PLC exploitation capability
Iranian cyber operations expand to target allied nations (UK, Gulf states) beyond IsraelMODERATE (30–50%)Al Jazeera reports UK power plant attack; Gulf states are historical Iranian cyber targets during regional conflicts
AI-augmented exploit development extends beyond Siemens PLCs to other ICS vendorsMODERATE (30–50%)Capability threshold crossed; technique is vendor-agnostic once developed

IOC Blocking Table:
217.60.241[.]17185.93.89[.]4377.90.185[.]248192.253.248[.]6562.60.227[.]10887.107.191[.]3962.60.155[.]3377.90.185[.]118176.123.87[.]16

Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1059.004
Hunt Hypothesis 1: IOCONTROL on Linux-based PLCs and HMIs
What to look for: Unexpected shell processes on Linux-based OT devices (PLCs, HMIs, historians). Outbound HTTP/HTTPS from OT network segments to unknown external IPs. File system changes on PLC firmware partitions. Detection: Monitor OT network segments for any outbound connections to the C2 IPs listed above. Deploy Claroty, Dragos, or Nozomi signatures for IOCONTROL if available.
HUNT 02 · T1505.003
Hunt Hypothesis 2: Web Shell Persistence on IIS/MSSQL (SPECTRAL KITTEN TTP)
What to look for: New .aspx/.asp files in IIS web directories. Unexpected w3wp.exe child processes (cmd.exe, powershell.exe). MSSQL xp_cmdshell execution. Lateral movement via SMB from web-facing servers. Detection: File integrity monitoring on IIS wwwroot directories. Sysmon Event ID 1 for w3wp.exe spawning command interpreters. Windows Security Event 4688 for process creation chains.
HUNT 03 · T1566.001
Hunt Hypothesis 3: TAMECAT Delivery via Malicious LNK Files
What to look for: LNK files received via email that spawn PowerShell. Registry Run key modifications following LNK execution. Also hunt for related APT42 tools: NICECURL, CharmPower/PowerStar. Detection: Email gateway rules for LNK attachments. Sysmon Event ID 13 for registry Run key modifications. PowerShell ScriptBlock logging (Event ID 4104) for encoded/obfuscated commands.
HUNT 04 · T1078
Hunt Hypothesis 4: Default Credential Exploitation on SCADA/ICS
What to look for: Authentication events using factory-default usernames on SCADA systems. Internet-facing HMIs, historians, or engineering workstations with default credentials. Shodan/Censys exposure of OT web interfaces. Detection: Audit all SCADA/ICS systems for default credentials immediately. Monitor for brute-force or credential-stuffing patterns against OT web interfaces.
HUNT 05 · T1190
Hunt Hypothesis 5: IXON VPN Client Exploitation for IT-to-OT Pivot
What to look for: Anomalous process execution on machines running IXON VPN client software. Unexpected network connections from VPN client hosts to OT network segments. IXON VPN client versions that predate the ICSA-26-246-02 advisory patch. Detection: Inventory all IXON VPN client installations. Monitor for exploitation indicators per CISA advisory. Segment VPN client hosts from sensitive OT networks until patched.
HUNT 06 · T1557
Hunt Hypothesis 6: AiTM/OAuth Token Theft (Credential Harvesting)
What to look for: Anomalous OAuth consent grants in M365/Azure AD. Phishing pages mimicking Microsoft login portals. Session token replay from unusual geolocations. Detection: Azure AD sign-in logs filtered for impossible travel. Conditional Access policies enforcing device compliance. Review OAuth app consent grants for suspicious third-party applications. ---

Financial Services
SWIFT/Banking, M365 Environments
Primary threat
SPECTRAL KITTEN (Black Shadow / Agrius) has financial services in its confirmed target set. The group's shift from destructive "lock-and-leak" operations to covert intelligence gathering means financial institutions may be under surveillance without knowing it.
Actions
  • Audit all internet-facing IIS and MSSQL servers for web shell artifacts (ASPXSpy, custom .aspx files) — SPECTRAL KITTEN's known tooling includes IPSecHelper, Apostle ransomware, Orcus RAT, and HellLoader
  • Review SWIFT and core banking system access logs for anomalous queries that could indicate reconnaissance or battle damage assessment collection
  • Ensure AiTM/OAuth phishing defenses are current — Iranian actors are running active credential harvesting campaigns against M365 environments
Energy
SCADA/PLC, Rockwell/Schneider Systems
Primary threat
This sector faces the most acute threat. SPECTRAL KITTEN has compromised an Israeli electrical utility. Cyber Av3ngers are actively inside US water/energy SCADA networks. AI-augmented exploitation of Siemens PLCs is confirmed. Nine CISA ICS advisories in a single day cover products deployed across the energy sector.
Actions
  • Patch Rockwell ControlFLASH (ICSA-26-246-03) and IXON VPN (ICSA-26-246-02) within 24 hours — both are RCE vulnerabilities in products that bridge IT and OT
  • Audit all Schneider Electric Easergy, EcoStruxure, PowerLogic, and Saitel deployments per ICSA-26-169-07
  • Conduct emergency credential audit on all SCADA/ICS systems — the 100+ water system compromises exploited default passwords
  • Verify OT network segmentation — ensure no direct internet connectivity to PLCs, RTUs, or engineering workstations
Healthcare
Building Management, Medical Device Networks
Primary threats
Healthcare is not a primary target in current Iranian campaigns, but the sector's reliance on OT systems (building management, medical device networks) and historically weak network segmentation makes it a collateral damage risk.
Actions
  • Audit building management systems (HVAC, power distribution) that use Schneider Electric or Rockwell controllers for default credentials and internet exposure
  • Ensure medical device network segments are isolated from IT networks that could be compromised via AiTM phishing or Ivanti EPMM exploitation
  • Review mobile device management posture — Ivanti EPMM is widely deployed in healthcare for clinician device management
Government
Nuclear Policy, Classified Systems
Primary threats
Government agencies — particularly those involved in defense, intelligence, diplomacy, and critical infrastructure regulation — are primary targets for Iranian espionage operations. APT42, APT34/OilRig, and MuddyWater all have government targeting in their confirmed operational mandates.
Actions
  • Hunt for TAMECAT, NICECURL, and CharmPower/PowerStar across all endpoints — government agencies involved in nuclear policy or regulation are at elevated risk
  • Audit all Citrix NetScaler deployments — Pioneer Kitten/Fox Kitten has historically exploited Citrix vulnerabilities for initial access
  • Brief personnel with access to classified or sensitive systems on Iranian spearphishing TTPs, particularly LNK-based delivery and fake resume/GitHub lures
  • Monitor for MuddyWater resurgence — the operational silence is anomalous and historically precedes retooling
Aviation / Logistics
OPC UA, CI/CD, Flight Operations
Primary threat
NBC reporting confirms Iranian targeting has expanded to transportation infrastructure. Aviation and logistics organizations face both direct targeting and supply-chain risk through compromised critical infrastructure dependencies.
Actions
  • Audit all OPC UA LocalDiscoveryServer installations (ICSA-26-246-01) — widely deployed in airport and logistics facility automation systems
  • Review CI/CD pipeline security — Iranian actors have been observed using fake GitHub repositories and compromised browser extensions for credential theft in supply-chain attacks targeting aerospace
  • Ensure flight operations, air traffic management, and logistics control systems are segmented from corporate IT networks
No sector cards match the selected filters.

Block all nine Iranian C2/APT IPs listed above across EDR, firewalls, SIEM, and proxy/DNS. Pull current IOCONTROL/SalatStealer/SewerGoo file hashes from Anomali ThreatStream and deploy blocking rules immediately.
SOC Analyst
Patch Rockwell ControlFLASH per ICSA-26-246-03 — RCE allows arbitrary command execution on industrial controllers. If patching is not possible within 24 hours, isolate affected systems from all network connectivity.
ICS / OT
Patch IXON VPN Client per ICSA-26-246-02 — RCE on VPN client enables direct IT-to-OT pivot. Disable IXON VPN remote access until patched.
Incident Responder
Conduct an emergency credential audit on all internet-facing SCADA/ICS systems. Change every default password. Disable unnecessary open ports — the 100+ water system compromises used default credentials as the primary attack vector.
ICS / OT
Elevate alert posture for energy and telecom sectors. Increase monitoring sensitivity for reconnaissance activity against OT-adjacent network segments.
SOC Analyst
Activate incident response retainers. Ensure IR teams have current OT/ICS playbooks. Pre-position forensic imaging capabilities for SCADA systems.
CISO / ExecIncident Responder
No immediate actions for the selected roles.
Audit all Rockwell 1756-ENBT, ArmorStart LT, and ControlFLASH firmware versions against ICSA-26-246-03/04/05. Segment all affected devices from IT networks.
ICS / OT
Audit and patch Schneider Electric Easergy C5, EcoStruxure, PowerLogic, and Saitel deployments per ICSA-26-169-07 Update A.
ICS / OT
Deploy detection for the TAMECAT execution chain: LNK file execution → PowerShell → registry Run key persistence. Extend hunt to include NICECURL, CharmPower/PowerStar, and other APT42 tooling.
SOC Analyst
Patch Ivanti EPMM against CVE-2026-1281 and CVE-2026-1340 (CVSS 9.8, unauthenticated RCE). Active exploitation campaigns are already in the wild.
Incident Responder
Initiate proactive monitoring of Telegram channels associated with Handala, Cyber Toufan, and BANISHED KITTEN — hacktivist silence during kinetic escalation is anomalous and historically precedes coordinated destructive operations.
Threat Hunter
No 7-day actions for the selected roles.
Commission a formal assessment of AI-augmented exploit risk to OT environments. Evaluate whether current PLC patching cadences are viable given compressed exploit development timelines — legacy "quarterly patch" cycles for internet-adjacent ICS are no longer defensible.
CISO / Exec
Conduct a tabletop exercise simulating a coordinated Iranian destructive cyber operation against energy and water infrastructure, including wiper deployment, simultaneous hacktivist data leaks, and public attribution challenges.
CISO / ExecIncident Responder
Establish a proactive hunt cadence for MuddyWater infrastructure rotation. If silence extends beyond 14 days from last known activity, escalate to active threat hunt across all network segments.
Threat Hunter
Conduct a comprehensive OT network segmentation review. Verify that no PLCs, RTUs, HMIs, or engineering workstations have direct internet connectivity.
ICS / OT
Review and update the Iran-specific threat model to account for MOIS unit consolidation — detection signatures and hunting rules built for one actor should now be cross-applied to both APT34 and APT42.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Iranian cyber operations have entered their most dangerous phase since the conflict began on February 28, 2026. The CISA confirmation of 100+ compromised water systems is not the ceiling — it is the floor. The target set is expanding to energy, telecom, and transportation. Exploit development is being accelerated by AI. Organizational boundaries between MOIS cyber units are collapsing under wartime pressure. And the operational silence of Iran's most capable destructive units — MuddyWater, Cavern Manticore, Handala, Cyber Toufan — is not reassurance. It is a leading indicator of pre-positioning. The nine CISA ICS advisories published in a single day are not routine vulnerability management. They are an emergency expansion of the attack surface at the exact moment the most motivated adversary in a generation is looking for ways in. We are now 189 days into the Iran–US conflict, and the cyber dimension has become the most consequential theater for organizations that don't wear uniforms.

1
Patch ControlFLASH. Patch IXON VPN. Change every default credential on every SCADA system.
2
Block the IOCs. Hunt for web shells. Activate your IR retainers.
3
Brief your board. The next 30 days will determine whether your organization is a headline or a case study in resilience.
No items found.