| Development | Significance |
|---|---|
| Colorado water utilities breached via... | Largest coordinated ICS/OT campaign against US... |
| PAYLOAD ransomware IOCs published by... | A TTP that evades traditional ransomware... |
| ISRL ransomware actor claims a FortiGate... | Responsible for an estimated 80-85% of World... |
| CVE-2026-7273 added to CISA KEV... | CVSS 8.8, exploitable via crafted HTTP requests |
| Seven new ICS advisories... | Expands the ICS vulnerability surface across... |
| UNC6779 actively exploiting Palo Alto... | A direct and ongoing threat to critical... |
| Five Iran-hosted C2 servers... | Confirms continued Iranian offensive... |
| Phase | Timeframe | Cyber Activity |
|---|---|---|
| Conflict begins | Feb 28, 2026 | Iran conflict begins, initiating sustained cyber... |
| PAYLOAD incident, water systems compromised | Apr - Jul 2026 | PAYLOAD ransomware hits a Middle East... |
| Silences begin, ISRL migrates | Jul - Aug 2026 | BANISHED KITTEN's last observed Gulf wiper... |
| Colorado breach, ICS advisories, active... | Sep 17-21, 2026 | Two Colorado water utilities breached (PLC... |
| Current (Day ~207) - C2 confirmed active | Sep 22, 2026 | Five active Iran-hosted C2 servers identified... |
Confirmed exploitation: PAYLOAD ransomware used a compromised FortiGate SSL VPN account, then created malicious AD GPOs to deploy ransom messaging domain-wide - without encrypting a single file.
Credential stockpiling: ISRL publicly claims a stockpile of compromised FortiGate credentials, with operational...
The PAYLOAD attackers entered via FortiGate VPN, created a malicious GPO named PAYLOAD linked to the domain root, used it to hijack wallpapers/lock screens with ransom notes, disabled local admin accounts, turned off Windows Firewall, then exfiltrated data - never deploying a ransomware binary. No file encryption, no traditional detection...
The Colorado breach is the latest data point in an escalating campaign: 2023-24 initial probing by Cyber Av3ngers, 2025 IOCONTROL C2 established, July 2026's 100+ system compromise across 12+ states, and August's Colorado breach with altered PLC settings and disabled alarms.
The pattern is low sophistication, vast target surface...
Five C2 servers geolocated to Iran confirmed active as of Sep 21: two Cobalt Strike/Agentemis servers (ports 443/53), a Chaos/FakeRyuk/Yashma server, and a DCRat/AsyncRAT server. One IP is registered to the Institute for Research in Fundamental Sciences, an Iranian academic institution - suggesting institutional compromise or deliberate use of...
Pioneer Kitten/Fox Kitten silent 34 days on DIB networks. Void Manticore/BANISHED KITTEN hasn't conducted a Gulf wiper attack in ~2 months - anomalous for a historically sustained actor. Cotton Sandstorm/Emennet Pasargad silent 5 months on influence operations. IOCONTROL C2 infrastructure remains active but dormant.
Absence is signal...
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Additional US water/wastewater utility... | 70–80% | 1–2 weeks | Campaign pattern shows systematic state-by-state... |
| ISRL actor's FortiGate credential stockpile... | 40–60% | 30 days | Actor has operational capability (Qilin/Gentlemen... |
| Void Manticore / BANISHED KITTEN silence breaks... | 40–50% | 2–4 weeks | ~2-month operational pause is historically... |
| Pioneer Kitten / Fox Kitten re-emerges with new... | 35–50% | 2–4 weeks | 34-day silence matches historical pre-activation... |
| APT42 BELLACIAO/SHELLAFEL campaign produces new... | 25–40% | 30 days | CALANQUE ION/TAMECAT nuclear campaign updated... |
| IOCONTROL malware deployed in new ICS incident | 30–45% | 30 days | C2 infrastructure (c2iznja[.]com subdomains)... |
The PAYLOAD ransomware case demonstrates that AD...
Monitor: FortiGate VPN...
Monitor: DNS queries and HTTPS...
Monitor: Unauthorized PLC...
Monitor: GPO changes that modify...
| Threat | ATT&CK |
|---|---|
| 1. Active Directory GPO Abuse (T1484.001 — Domain... | T1484.001 |
| 2. FortiGate VPN Credential Abuse (T1078 — Valid... | T1078 |
| 3. Iran-Hosted C2 Communication... | T1071.001 T1071.004 |
| 4. ICS/OT Anomaly Detection (T1190, T1565.001... | T1190 T1565.001... |
| 5. Windows Firewall Disable via GPO (T1562.001 —... | T1562.001 |
Block the above at perimeter firewalls, proxies...
- Audit FortiGate VPN immediately; deploy AD GPO integrity monitoring; validate payment system segmentation
- Patch Palo Alto GlobalProtect for CVE-2026-0257; audit OT network segmentation for internet-accessible ICS controllers
- Prioritize AD GPO monitoring; segment medical device networks and enforce MFA on remote access
- Rotate FortiGate credentials immediately; monitor for APT42 BELLACIAO/SHELLAFEL nuclear-sector indicators
- Audit DIB contractor VPN access; pin npm dependencies to verified hashes given supply chain risk
Seven months into the Iran conflict, the cyber dimension has matured from reactive retaliation into something far more methodical. FortiGate VPN is the primary initial-access vector of this conflict cycle - confirmed exploitation, a publicly claimed credential stockpile, and a credential-harvesting vulnerability converge on a single attack surface. Encryptionless ransomware has arrived - if your SOC cannot detect a domain-wide Group Policy change, you cannot detect this attack. And Iranian ICS...