SUBJECT PROFILE
Two overlapping Iran-aligned threat activities were highlighted in the TrendAI H1 2026 APT roundup (July 29, 2026): Earth Vetala (MuddyWater) scanned for a newly disclosed Ivanti vulnerability within days of its release, and separately, Iran-aligned actors conducted hands-on manipulation of internet-exposed Automatic Tank Gauge (ATG) systems at U.S. gas stations across multiple states. The ATG campaign — detected May 2026 and investigated by FBI, CISA, NSA, DOE, EPA, and TSA — tampered with fuel-level display readings and in some cases deleted sensor data, escalating in parallel with the U.S.-Israeli military campaign against Iran.
Retaliatory disruption of U.S. critical infrastructure amid U.S.-Israeli military conflict with Iran; political signaling via OT manipulation; espionage via rapid vulnerability exploitation
OPERATIONAL HISTORY
Rapid CVE scanning (Ivanti within days of disclosure), exploitation of internet-exposed OT with default/no credentials, ATG display manipulation (process data tampering without physical impact), sensor data deletion, edge device exploitation (Fortinet, Citrix, Ivanti, F5, Palo Alto), RMM tool abuse (Atera, ScreenConnect), Rust-rewritten implant (RustyWater), no custom ICS malware — leverages weak authentication and exposed interfaces
KNOWN INFRASTRUCTURE
Internet-facing ATG interfaces (no authentication), Ivanti edge devices, MOIS-linked C2 infrastructure, open-source RMM tools; multi-agency joint advisory issued by CISA/FBI/NSA/DOE/EPA/TSA/DOT/USDA on ATG hardening