| Development | Why It Matters |
|---|---|
| SPECTRAL KITTEN compromised an Israeli electrical utility via IIS and MSSQL... | An MOIS actor known for destructive ransomware (Apostle) is now conducting covert reconnaissance on... |
| HEAVYGRAM backdoor attributed to Handala Hack / Void Manticore (Sep 17) | New Telegram-based surveillance implant with full collection suite (microphone, screenshots... |
| Check Point CVE-2026-91843 disclosed — unauthenticated root RCE on Security... | This is the 5th critical CVE in Check Point's product line in weeks. Two others (CVE-2026-50751... |
| APT42 confirmed using generative AI for targeting and collection (Google Sep 8... | Iran's premier cyber-espionage unit is integrating AI into its operational workflow, compressing... |
| 8 new CISA ICS advisories covering Schneider Electric, Mitsubishi, Hitachi Energy... | Directly relevant to OT environments that Iranian actors have demonstrated the capability and... |
| MuddyWater operational silence broken (Sep 14–16, from prior cycle) | Five new PowerStats backdoor samples targeting European infrastructure after a 39-day pause — MOIS... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | US-Iran conflict begins (Day 0). |
| Covert compromise begins, Check Point exploitation starts | Jun - Jul 2026 | SPECTRAL KITTEN compromises an Israeli electrical utility (reported later); Qilin begins exploiting... |
| AI adoption confirmed, chokepoints fall | Sep 8-13, 2026 | Google confirms APT42 generative AI adoption; Houthis seize Bab al-Mandeb; Anthropic documents... |
| MuddyWater resurfaces, Cisco crisis emerges | Sep 14-17, 2026 | MuddyWater breaks 39-day silence with PowerStats; Cisco ISE added to KEV; Sandworm/Qilin confirmed... |
| Current (Day 202) - Check Point crisis, behavioral pivot confirmed | Sep 18, 2026 | Check Point discloses CVE-2026-91843 (root RCE); CrowdStrike confirms SPECTRAL KITTEN's behavioral... |
CrowdStrike's updated profile explicitly notes SPECTRAL KITTEN (Pink Sandstorm/Agrius) has evolved toward covert intelligence gathering. Evidence: a mid-June compromise of an Israeli electrical utility where the actor deployed web shells on IIS/MSSQL servers, pivoted internally, ran reconnaissance - then went quiet. Known tooling: ASPXSpy...
Void Manticore (Handala Hack, BANISHED KITTEN) fielded HEAVYGRAM, a Python backdoor using Telegram bots for C2, plus CRUDEEXCLUDE, a Delphi staging tool that configures Defender exclusions before deployment. Capabilities: microphone activation, browser/Telegram/WhatsApp data theft, screenshots, DLL sideloading. FBI and UK NCSC have issued...
CVE-2026-91843 (root RCE, disclosed Sep 18) brings the total to five critical Check Point CVEs in weeks. Two are already under active exploitation: CVE-2026-50751 by Qilin ransomware since June, and CVE-2026-16232 (SmartConsole) since July. Two more (CVE-2026-85102/85103) have imminent-exploitation warnings from Dutch NCSC.
This is a...
Google confirmed APT42 (Charming Kitten) uses generative AI throughout its targeting and collection lifecycle - alongside Sandworm using Gemini for phishing and DPRK integrating AI into social engineering. Anthropic separately documented a Chinese group using Claude to discover vulnerabilities and Midnight Blizzard using Claude agents to...
CISA published 8 ICS advisories (Sep 17) affecting Schneider Modicon M340, Mitsubishi GX Works3, Hitachi Energy FACTS, and ABB Edgenius. The Modicon M340 advisory is particularly significant given Iranian ICS targeting history - Cyber Av3ngers has demonstrated ICS attack capability with IOCONTROL, and SPECTRAL KITTEN's utility presence means...
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Exploitation of Check Point CVE-2026-85102 and CVE-2026-85103 materializes | 75% | 72 hours | Dutch NCSC warning; 2 other Check Point CVEs already under active exploitation; Iranian actors... |
| SPECTRAL KITTEN leverages Israeli utility access for data exfiltration or lateral movement to OT | 50% | 30 days | Consistent with actor's historical dwell time before destructive action; covert access has been... |
| APT42 launches AI-augmented phishing campaign targeting nuclear/energy sector researchers | 45% | 2 weeks | Consistent with CALANQUE ION TAMECAT campaign tempo and confirmed AI adoption |
| Iranian retaliatory cyber operation executes without additional warning indicators | 35% | Indeterminate | UK power plant attack demonstrated completed pre-positioning → execution pattern; PIR-008... |
| UNGA diplomatic failure (Sep 22–27) triggers Iranian cyber retaliation surge | 20% | 7–14 days post-UNGA | Assessed in prior cycle; diplomatic failure could provide political justification for escalation |
T1567 (Exfiltration Over Web Service): Monitor for outbound connections to...
CVE-2026-91843: Monitor Check Point Audit and Admin login logs for the string...
T1059 (Command and Scripting Interpreter): Monitor for wscript.exe...
| Threat | ATT&CK |
|---|---|
| HEAVYGRAM / Void Manticore Indicators | T1567 T1547.001 T1562.001 T1036 |
| Check Point Vulnerability Detection | T1190 T1078 |
| AI-Augmented Threat Detection | T1059 |
Block the above at perimeter firewalls, proxies, and DNS. Hashes...
- Audit all Check Point deployments for the 5 CVEs; deploy AI-generated phishing detection
- Initiate a threat hunt for SPECTRAL KITTEN indicators on externally facing IIS/MSSQL servers adjacent to OT
- Patch Check Point and Cisco appliances; review Telegram/messaging policies given HEAVYGRAM delivery
- Deploy HEAVYGRAM/CRUDEEXCLUDE detection; audit GitHub/CI-CD pipeline security for UNC6446 phishing
- Monitor logistics/port OT systems; develop contingency plans for cyber-kinetic maritime disruption
Two hundred and two days into this conflict, the Iranian cyber apparatus is not slowing down - it is maturing. The shift from loud, destructive operations to quiet pre-positioning on energy infrastructure is the most strategically significant development of this cycle. SPECTRAL KITTEN sitting silently inside an Israeli electrical utility since June is not inaction - it is preparation. The tools available to Iranian operators are improving (AI-augmented targeting by APT42), surveillance...