TLP:GREEN  ·  Iran / Israel Conflict
When Your Perimeter Vendor Becomes the Vulnerability:

Iran's Cyber Apparatus Shifts to Covert Pre-Positioning

HIGH. Maintained from prior cycle - the character of the threat has shifted, not the level. SPECTRAL KITTEN pivoted from destructive wipers to silent reconnaissance inside an Israeli electrical utility since mid-June. MOIS fielded a new Telegram-based surveillance backdoor (HEAVYGRAM), APT42 is confirmed using generative AI to accelerate targeting, and Check Point faces a cascading five-CVE crisis with two vulnerabilities already under active exploitation.

I am a
My sector

DevelopmentWhy It Matters
SPECTRAL KITTEN compromised an Israeli electrical utility via IIS and MSSQL...An MOIS actor known for destructive ransomware (Apostle) is now conducting covert reconnaissance on...
HEAVYGRAM backdoor attributed to Handala Hack / Void Manticore (Sep 17)New Telegram-based surveillance implant with full collection suite (microphone, screenshots...
Check Point CVE-2026-91843 disclosed — unauthenticated root RCE on Security...This is the 5th critical CVE in Check Point's product line in weeks. Two others (CVE-2026-50751...
APT42 confirmed using generative AI for targeting and collection (Google Sep 8...Iran's premier cyber-espionage unit is integrating AI into its operational workflow, compressing...
8 new CISA ICS advisories covering Schneider Electric, Mitsubishi, Hitachi Energy...Directly relevant to OT environments that Iranian actors have demonstrated the capability and...
MuddyWater operational silence broken (Sep 14–16, from prior cycle)Five new PowerStats backdoor samples targeting European infrastructure after a 39-day pause — MOIS...

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026US-Iran conflict begins (Day 0).
Covert compromise begins, Check Point exploitation startsJun - Jul 2026SPECTRAL KITTEN compromises an Israeli electrical utility (reported later); Qilin begins exploiting...
AI adoption confirmed, chokepoints fallSep 8-13, 2026Google confirms APT42 generative AI adoption; Houthis seize Bab al-Mandeb; Anthropic documents...
MuddyWater resurfaces, Cisco crisis emergesSep 14-17, 2026MuddyWater breaks 39-day silence with PowerStats; Cisco ISE added to KEV; Sandworm/Qilin confirmed...
Current (Day 202) - Check Point crisis, behavioral pivot confirmedSep 18, 2026Check Point discloses CVE-2026-91843 (root RCE); CrowdStrike confirms SPECTRAL KITTEN's behavioral...

CrowdStrike's updated profile explicitly notes SPECTRAL KITTEN (Pink Sandstorm/Agrius) has evolved toward covert intelligence gathering. Evidence: a mid-June compromise of an Israeli electrical utility where the actor deployed web shells on IIS/MSSQL servers, pivoted internally, ran reconnaissance - then went quiet. Known tooling: ASPXSpy...

T1505.003T1190T1018

Void Manticore (Handala Hack, BANISHED KITTEN) fielded HEAVYGRAM, a Python backdoor using Telegram bots for C2, plus CRUDEEXCLUDE, a Delphi staging tool that configures Defender exclusions before deployment. Capabilities: microphone activation, browser/Telegram/WhatsApp data theft, screenshots, DLL sideloading. FBI and UK NCSC have issued...

T1567T1071.001T1562.001T1036

CVE-2026-91843 (root RCE, disclosed Sep 18) brings the total to five critical Check Point CVEs in weeks. Two are already under active exploitation: CVE-2026-50751 by Qilin ransomware since June, and CVE-2026-16232 (SmartConsole) since July. Two more (CVE-2026-85102/85103) have imminent-exploitation warnings from Dutch NCSC.

This is a...

T1190T1078

Google confirmed APT42 (Charming Kitten) uses generative AI throughout its targeting and collection lifecycle - alongside Sandworm using Gemini for phishing and DPRK integrating AI into social engineering. Anthropic separately documented a Chinese group using Claude to discover vulnerabilities and Midnight Blizzard using Claude agents to...

T1059T1071.001

CISA published 8 ICS advisories (Sep 17) affecting Schneider Modicon M340, Mitsubishi GX Works3, Hitachi Energy FACTS, and ABB Edgenius. The Modicon M340 advisory is particularly significant given Iranian ICS targeting history - Cyber Av3ngers has demonstrated ICS attack capability with IOCONTROL, and SPECTRAL KITTEN's utility presence means...

T1190

ScenarioProbabilityTimeframeBasis
Exploitation of Check Point CVE-2026-85102 and CVE-2026-85103 materializes75%72 hoursDutch NCSC warning; 2 other Check Point CVEs already under active exploitation; Iranian actors...
SPECTRAL KITTEN leverages Israeli utility access for data exfiltration or lateral movement to OT50%30 daysConsistent with actor's historical dwell time before destructive action; covert access has been...
APT42 launches AI-augmented phishing campaign targeting nuclear/energy sector researchers45%2 weeksConsistent with CALANQUE ION TAMECAT campaign tempo and confirmed AI adoption
Iranian retaliatory cyber operation executes without additional warning indicators35%IndeterminateUK power plant attack demonstrated completed pre-positioning → execution pattern; PIR-008...
UNGA diplomatic failure (Sep 22–27) triggers Iranian cyber retaliation surge20%7–14 days post-UNGAAssessed in prior cycle; diplomatic failure could provide political justification for escalation

HEAVYGRAM / Void Manticore Indicators:

T1567 (Exfiltration Over Web Service): Monitor for outbound connections to...

Check Point Vulnerability Detection:

CVE-2026-91843: Monitor Check Point Audit and Admin login logs for the string...

AI-Augmented Threat Detection:

T1059 (Command and Scripting Interpreter): Monitor for wscript.exe...

ThreatATT&CK
HEAVYGRAM / Void Manticore IndicatorsT1567 T1547.001 T1562.001 T1036
Check Point Vulnerability DetectionT1190 T1078
AI-Augmented Threat DetectionT1059
IOC Blocking Table:
176.46.152[.]4677.90.185[.]118185.93.89[.]43192.253.248[.]6577.90.185[.]248checrity[.]comshinewrist[.]netipify[.]orgpolicenationale[.]cc

Block the above at perimeter firewalls, proxies, and DNS. Hashes...

Hunting Hypotheses:
HUNT 01 · T1567
HEAVYGRAM C2 via Telegram Bot API
Proxy logs, DNS, EDR network telemetry — IMMEDIATE
HUNT 02 · T1562.001
CRUDEEXCLUDE disabling Defender
Endpoint telemetry, PowerShell logs — IMMEDIATE
HUNT 03 · T1505.003
ASPXSpy web shells on IIS (SPECTRAL KITTEN)
File integrity monitoring, IIS logs — HIGH
HUNT 04 · T1190
MSSQL exploitation for initial access
SQL audit logs, process creation from sqlservr.exe — HIGH
HUNT 05 · T1190
Check Point management server exploitation
Check Point audit logs, network flow to mgmt interfaces — IMMEDIATE
HUNT 06 · T1059
AI API abuse from endpoints
Proxy logs, DNS, EDR — MEDIUM
HUNT 07 · T1018
Reconnaissance from web/DB service accounts
Windows Security Event Log (4688), Sysmon — HIGH

Financial Services
Check Point Firewalls, VPN
Primary threat
Credential harvesting via AI-augmented phishing (APT42) and ransomware via perimeter exploitation...
Actions
  • Audit all Check Point deployments for the 5 CVEs; deploy AI-generated phishing detection
Energy
IIS/MSSQL Servers, ICS
Primary threat
Most directly threatened sector - SPECTRAL KITTEN is inside an Israeli electrical utility; UK power...
Actions
  • Initiate a threat hunt for SPECTRAL KITTEN indicators on externally facing IIS/MSSQL servers adjacent to OT
Healthcare
Research Institutions
Primary threat
Ransomware via perimeter exploitation and data theft targeting nuclear/dual-use technology...
Actions
  • Patch Check Point and Cisco appliances; review Telegram/messaging policies given HEAVYGRAM delivery
Government
Defense, National CERTs
Primary threats
Full spectrum of Iranian operations: espionage (APT42, MuddyWater), pre-positioning (SPECTRAL...
Actions
  • Deploy HEAVYGRAM/CRUDEEXCLUDE detection; audit GitHub/CI-CD pipeline security for UNC6446 phishing
Aviation / Logistics
Maritime, Port Logistics
Primary threat
Houthi control of Bab al-Mandeb alongside Iran's Hormuz blockade creates direct risk for logistics...
Actions
  • Monitor logistics/port OT systems; develop contingency plans for cyber-kinetic maritime disruption
No sector cards match the selected filters.

Patch all Check Point Security Management/Log Servers for...
Incident Responder
Deploy HEAVYGRAM detection: alert on Telegram Bot API calls...
SOC Analyst
Deploy Check Point exploitation detection: monitor for the...
SOC Analyst
Deploy CRUDEEXCLUDE detection: alert on Defender...
SOC Analyst
No immediate actions for the selected roles.
Hunt for SPECTRAL KITTEN on energy/utility networks - ASPXSpy...
Threat Hunter
Apply the 8 CISA ICS advisories for Modicon M340, GX Works3...
ICS / OT
Implement AI API abuse detection - monitor for connections to...
SOC Analyst
Audit all Cisco FMC/ISE deployments for the prior cycle's CVSS...
Incident Responder
No 7-day actions for the selected roles.
Commission a Check Point dependency risk assessment - 5...
CISO / Exec
Develop an AI-threat detection strategy incorporating...
CISO / Exec
Conduct a tabletop exercise simulating Iranian destructive...
CISO / ExecIncident Responder
Establish actor behavioral baseline tracking - track what...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Two hundred and two days into this conflict, the Iranian cyber apparatus is not slowing down - it is maturing. The shift from loud, destructive operations to quiet pre-positioning on energy infrastructure is the most strategically significant development of this cycle. SPECTRAL KITTEN sitting silently inside an Israeli electrical utility since June is not inaction - it is preparation. The tools available to Iranian operators are improving (AI-augmented targeting by APT42), surveillance...

1
Authorize emergency patching for Check Point and Cisco today.
2
Launch a threat hunt for SPECTRAL KITTEN indicators today.
3
Invest in behavioral detection - signature-based approaches alone will not close the gap.
No items found.