Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-02 and was added to the RWP archive on 2026-09-07.
Nozomi's March 2026 Iran-APT note was a telemetry spike, not a new wiper
2 March 2026 customer note — MuddyWater, APT33, UNC1549/CURIUM activity up against manufacturing and transportation after the prior conflict phase. Middle East customers under-sampled. Not AA26-097A.
Bottom line up front
CONFIRMED Nozomi, 2 March 2026 — a customer/critical-infrastructure note that Iran-linked APT detections rose in their anonymized telemetry after the prior ("Twelve-Day War") phase. Sectors called: transportation and manufacturing. Named: MuddyWater (MOIS-aligned; OilRig/Seedworm/APT34 aliases as Nozomi lists them), APT33/Elfin/Refined Kitten, and UNC1549 overlapping CURIUM/Tortoise Shell/Crimson Sandstorm as fourth-most-active in 2H 2025 in their set. They flag that many Middle East customers do not submit telemetry, so the chart is biased. This is not the April Rockwell engineering-software campaign and not the July FBI water PSA. Do not merge. Process impact: UNKNOWN in this note. IT/OT targeting of manufacturing and transport: REPORTED as Nozomi detections.
Historical backfill of 2 March 2026 reporting; added 7 September 2026.
What happened
A spike briefing. Groups that already live in your threat model got louder during kinetic escalation.
Why it mattered
Conflict calendars are detection calendars. If your OT hunt list does not change when missiles fly, you are late.
Who / what was affected
Nozomi's participating customers; manufacturing and transport in their telemetry. Not a named-victim dump.
Technical context
Watch MuddyWater phishing into engineering orgs. Do not skip internet-facing PLCs because this post is "APT email."
Exploitation / threat status at the time
CONFIRMED Nozomi saw more of these actors.
UNKNOWN OT process effects in this dataset.
What defenders should have done
- Heighten monitoring on manufacturing remote access.
- Keep Iran-linked playbooks current (CyberAv3ngers, Handala, AA26-097A as they landed).
- Do not treat "no Middle East telemetry" as "no Middle East risk."
RWP assessment
Confidence: Medium-high as a vendor telemetry note. Low as a campaign teardown.
Defensive actions
- Separate tickets: this spike vs April PLC-manual vs July water PLCs.
- Vendor PAM for manufacturing.
- Phishing + exposed engineering ports, not a new YARA family.
Sources
- Nozomi Networks — Iranian APT activity during geopolitical escalation
- Nozomi Networks — These attackers didn't need a zero-day (April AA26-097A follow-on)
- CISA AA26-097A — Iranian-affiliated PLC exploitation (7 April 2026)