TLP:GREEN  ·  Iran / Israel Conflict
When Your VPN Credentials Are Already for Sale:

The Iran Cyber Threat Enters a Dangerous New Phase

HIGH. Maintained from prior cycle. Iran-backed actors have compromised water utilities in at least 14 US states. A ransomware operator is openly advertising a stockpile of Fortinet FortiGate VPN credentials on criminal forums. And a new breed of ransomware doesn't even bother encrypting your files - it hijacks Active Directory Group Policy to lock you out of your own domain. Three independent intelligence threads now converge on FortiGate as the single most critical attack surface of this conflict cycle.

I am a
My sector

DevelopmentSignificance
Colorado water utilities breached via...Largest coordinated ICS/OT campaign against US...
PAYLOAD ransomware IOCs published by...A TTP that evades traditional ransomware...
ISRL ransomware actor claims a FortiGate...Responsible for an estimated 80-85% of World...
CVE-2026-7273 added to CISA KEV...CVSS 8.8, exploitable via crafted HTTP requests
Seven new ICS advisories...Expands the ICS vulnerability surface across...
UNC6779 actively exploiting Palo Alto...A direct and ongoing threat to critical...
Five Iran-hosted C2 servers...Confirms continued Iranian offensive...

PhaseTimeframeCyber Activity
Conflict beginsFeb 28, 2026Iran conflict begins, initiating sustained cyber...
PAYLOAD incident, water systems compromisedApr - Jul 2026PAYLOAD ransomware hits a Middle East...
Silences begin, ISRL migratesJul - Aug 2026BANISHED KITTEN's last observed Gulf wiper...
Colorado breach, ICS advisories, active...Sep 17-21, 2026Two Colorado water utilities breached (PLC...
Current (Day ~207) - C2 confirmed activeSep 22, 2026Five active Iran-hosted C2 servers identified...

Confirmed exploitation: PAYLOAD ransomware used a compromised FortiGate SSL VPN account, then created malicious AD GPOs to deploy ransom messaging domain-wide - without encrypting a single file.

Credential stockpiling: ISRL publicly claims a stockpile of compromised FortiGate credentials, with operational...

T1078T1133T1484.001

The PAYLOAD attackers entered via FortiGate VPN, created a malicious GPO named PAYLOAD linked to the domain root, used it to hijack wallpapers/lock screens with ransom notes, disabled local admin accounts, turned off Windows Firewall, then exfiltrated data - never deploying a ransomware binary. No file encryption, no traditional detection...

T1484.001T1562.001T1491.001

The Colorado breach is the latest data point in an escalating campaign: 2023-24 initial probing by Cyber Av3ngers, 2025 IOCONTROL C2 established, July 2026's 100+ system compromise across 12+ states, and August's Colorado breach with altered PLC settings and disabled alarms.

The pattern is low sophistication, vast target surface...

T1190T1565.001T1489

Five C2 servers geolocated to Iran confirmed active as of Sep 21: two Cobalt Strike/Agentemis servers (ports 443/53), a Chaos/FakeRyuk/Yashma server, and a DCRat/AsyncRAT server. One IP is registered to the Institute for Research in Fundamental Sciences, an Iranian academic institution - suggesting institutional compromise or deliberate use of...

T1071.001T1071.004

Pioneer Kitten/Fox Kitten silent 34 days on DIB networks. Void Manticore/BANISHED KITTEN hasn't conducted a Gulf wiper attack in ~2 months - anomalous for a historically sustained actor. Cotton Sandstorm/Emennet Pasargad silent 5 months on influence operations. IOCONTROL C2 infrastructure remains active but dormant.

Absence is signal...

ScenarioProbabilityTimeframeBasis
Additional US water/wastewater utility...70–80%1–2 weeksCampaign pattern shows systematic state-by-state...
ISRL actor's FortiGate credential stockpile...40–60%30 daysActor has operational capability (Qilin/Gentlemen...
Void Manticore / BANISHED KITTEN silence breaks...40–50%2–4 weeks~2-month operational pause is historically...
Pioneer Kitten / Fox Kitten re-emerges with new...35–50%2–4 weeks34-day silence matches historical pre-activation...
APT42 BELLACIAO/SHELLAFEL campaign produces new...25–40%30 daysCALANQUE ION/TAMECAT nuclear campaign updated...
IOCONTROL malware deployed in new ICS incident30–45%30 daysC2 infrastructure (c2iznja[.]com subdomains)...

1. Active Directory GPO Abuse (T1484.001 — Domain Policy Modification: Group Policy Modification):

The PAYLOAD ransomware case demonstrates that AD...

2. FortiGate VPN Credential Abuse (T1078 — Valid Accounts):

Monitor: FortiGate VPN...

3. Iran-Hosted C2 Communication (T1071.001/T1071.004 — Application Layer Protocol):

Monitor: DNS queries and HTTPS...

4. ICS/OT Anomaly Detection (T1190, T1565.001, T1489):

Monitor: Unauthorized PLC...

5. Windows Firewall Disable via GPO (T1562.001 — Impair Defenses):

Monitor: GPO changes that modify...

ThreatATT&CK
1. Active Directory GPO Abuse (T1484.001 — Domain...T1484.001
2. FortiGate VPN Credential Abuse (T1078 — Valid...T1078
3. Iran-Hosted C2 Communication...T1071.001 T1071.004
4. ICS/OT Anomaly Detection (T1190, T1565.001...T1190 T1565.001...
5. Windows Firewall Disable via GPO (T1562.001 —...T1562.001
IOC Blocking Table:
217.60.241[.]1787.107.191[.]3994.184.37[.]6862.60.155[.]3337.19.210[.]12146.70.117[.]239149.102.229[.]15477.90.185[.]66176.65.139[.]206live-hk.c2iznja[.]combase64.c2iznja[.]comapi80.c2iznja[.]comchat5188[.]tk

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01 · T1484.001
1. Active Directory GPO Abuse (T1484.001 — Domain Policy Modification: Group Policy Modification)
"An attacker with domain admin privileges creates a malicious GPO linked to the domain root to deploy ransomware messaging, disable security controls, or execute payloads across all domain-joined systems — without deploying a traditional ransomware binary."
HUNT 02 · T1078
2. FortiGate VPN Credential Abuse (T1078 — Valid Accounts)
"An attacker uses stolen FortiGate VPN credentials to establish initial access, then pivots to Active Directory for domain-wide compromise."
HUNT 03 · T1071.001
3. Iran-Hosted C2 Communication (T1071.001/T1071.004 — Application Layer Protocol)
"Cobalt Strike Agentemis beacons communicate over HTTPS (port 443) or DNS (port 53) to Iran-hosted infrastructure, potentially using DNS tunneling for low-and-slow exfiltration."
HUNT 04 · T1190
4. ICS/OT Anomaly Detection (T1190, T1565.001, T1489)
"Iran-backed actors access internet-exposed PLCs via cellular modems, modify operational parameters, and disable alarms to mask the intrusion."

Financial Services
SWIFT, Payment Systems
Primary threat
Ransomware operators (ISRL/Qilin) with FortiGate credential stockpiles targeting high-value...
Actions
  • Audit FortiGate VPN immediately; deploy AD GPO integrity monitoring; validate payment system segmentation
Energy
ICS/SCADA, VPN Gateways
Primary threat
UNC6779 actively exploiting Palo Alto GlobalProtect against energy networks; Iran-backed water...
Actions
  • Patch Palo Alto GlobalProtect for CVE-2026-0257; audit OT network segmentation for internet-accessible ICS controllers
Healthcare
AD Environments, Medical Devices
Primary threat
Flat AD architectures are especially vulnerable to PAYLOAD's GPO-abuse technique; Schneider...
Actions
  • Prioritize AD GPO monitoring; segment medical device networks and enforce MFA on remote access
Government
Defense, Nuclear Policy
Primary threats
Compound exposure from ISRL's credential stockpile, PAYLOAD's confirmed FortiGate entry, and...
Actions
  • Rotate FortiGate credentials immediately; monitor for APT42 BELLACIAO/SHELLAFEL nuclear-sector indicators
Aviation / Logistics
DIB Contractors, Supply Chain
Primary threats
IRGC-affiliated actors (UNC1549, UNC6446, APT33) targeting aerospace/transportation for espionage...
Actions
  • Audit DIB contractor VPN access; pin npm dependencies to verified hashes given supply chain risk
No sector cards match the selected filters.

Block all Iran-hosted C2 IPs at perimeter firewall (see IOC...
SOC Analyst
Enforce phishing-resistant MFA on all FortiGate VPN accounts...
Incident Responder
Deploy AD GPO abuse detection: monitor Event IDs 5137, 5136...
SOC Analyst
Verify no Zyxel GS1900 switches are internet-exposed; patch...
Incident Responder
No immediate actions for the selected roles.
Apply Linux kernel patches for CVE-2025-39682, CVE-2026-53266...
Incident Responder
Audit all internet-exposed PLCs/ICS controllers; remove direct...
ICS / OT
Implement FortiGate VPN anomaly detection - impossible-travel...
SOC Analyst
Patch Palo Alto GlobalProtect for CVE-2026-0257 - UNC6779 is...
Incident Responder
No 7-day actions for the selected roles.
Commission a comprehensive FortiGate credential audit; rotate...
CISO / Exec
Evaluate ICS/OT network segmentation for water, wastewater...
CISO / Exec
Update IR playbooks for encryptionless ransomware - tabletop...
CISO / ExecIncident Responder
Evaluate Void Manticore destructive attack preparedness given...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Seven months into the Iran conflict, the cyber dimension has matured from reactive retaliation into something far more methodical. FortiGate VPN is the primary initial-access vector of this conflict cycle - confirmed exploitation, a publicly claimed credential stockpile, and a credential-harvesting vulnerability converge on a single attack surface. Encryptionless ransomware has arrived - if your SOC cannot detect a domain-wide Group Policy change, you cannot detect this attack. And Iranian ICS...

1
Audit FortiGate VPN credentials today - treat them as compromised.
2
Deploy AD GPO monitoring this week.
3
Audit internet-exposed ICS assets immediately.
No items found.