DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // IRAN-OT-ATG-OPERATIONSFIRST SEEN: 2018 (ATG/OT campaign: FEB 2026)

IRAN-ALIGNED OT OPERATORS

ALSO KNOWN AS: Earth Vetala (MuddyWater/MOIS-linked), unnamed IRGC-affiliated actors
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Iran — assessed as a mix of MOIS (MuddyWater/Earth Vetala) and IRGC-affiliated operators
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2018 (ATG/OT campaign: FEB 2026)
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL65/100
RESOURCES73/100
PERSISTENCE73/100
STEALTH73/100
IMPACT65/100

Two overlapping Iran-aligned threat activities were highlighted in the TrendAI H1 2026 APT roundup (July 29, 2026): Earth Vetala (MuddyWater) scanned for a newly disclosed Ivanti vulnerability within days of its release, and separately, Iran-aligned actors conducted hands-on manipulation of internet-exposed Automatic Tank Gauge (ATG) systems at U.S. gas stations across multiple states. The ATG campaign — detected May 2026 and investigated by FBI, CISA, NSA, DOE, EPA, and TSA — tampered with fuel-level display readings and in some cases deleted sensor data, escalating in parallel with the U.S.-Israeli military campaign against Iran.

Retaliatory disruption of U.S. critical infrastructure amid U.S.-Israeli military conflict with Iran; political signaling via OT manipulation; espionage via rapid vulnerability exploitation

Rapid CVE scanning (Ivanti within days of disclosure), exploitation of internet-exposed OT with default/no credentials, ATG display manipulation (process data tampering without physical impact), sensor data deletion, edge device exploitation (Fortinet, Citrix, Ivanti, F5, Palo Alto), RMM tool abuse (Atera, ScreenConnect), Rust-rewritten implant (RustyWater), no custom ICS malware — leverages weak authentication and exposed interfaces

U.S. CRITICAL INFRASTRUCTURE
OIL & GAS
FUEL MONITORING SYSTEMS
IVANTI-EXPOSED NETWORKS
GOVERNMENT
DEFENSE

Internet-facing ATG interfaces (no authentication), Ivanti edge devices, MOIS-linked C2 infrastructure, open-source RMM tools; multi-agency joint advisory issued by CISA/FBI/NSA/DOE/EPA/TSA/DOT/USDA on ATG hardening

FILE DATE: FEB 2026
ATG Manipulation Campaign (U.S. Gas Stations)
Iran-aligned actors exploited internet-exposed Automatic Tank Gauge systems with no password protection at gas stations across multiple U.S. states (including 15 tanks at a Tennessee convenience store chain), manipulating fuel display readings and deleting sensor data — escalating with the onset of U.S.-Israeli military operations against Iran.
FILE DATE: H1 2026
Earth Vetala Ivanti Rapid Exploitation
Earth Vetala (MuddyWater) scanned for a newly disclosed Ivanti vulnerability within ███████████ public release as part of broader Iran-aligned edge-device targeting, confirmed in the TrendAI H1 2026 APT roundup published July 29, 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn