Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure
Jul 23, 2026
5 Mins Read
Moon

Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure

On July 22, 2026, seven US government agencies updated joint Cybersecurity Advisory AA26-097A, first published in April, warning that Iranian-affiliated APT actors are actively targeting internet-connected operational technology (OT) devices across US critical infrastructure. The update was co-authored by the FBI, CISA, NSA, EPA, the Department of Energy, US Cyber Command’s Cyber National Mission Force, and the Department of the Treasury.

The activity has disrupted programmable logic controllers (PLCs) in several critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. In some cases, the agencies report the activity caused operational disruption and financial loss.

What Changed in the July Update?

The original April advisory focused on Rockwell Automation/Allen-Bradley controllers. The July revision broadens the picture in three ways:

  • Wider manufacturer scope: The agencies now report observed targeting of Schneider Electric and Siemens PLCs, and warn that other branded controllers may also be at risk. Named device families include Rockwell CompactLogix and Micro850, Schneider BMX P34/Modicon M340, and Siemens S7-1200 series controllers.
  • New detection guidance: The update adds direction on spotting malicious changes in reusable code modules, specifically Add-On Instructions (AOIs), within Rockwell Automation programs. The agencies note that AOIs are analogous to function blocks used in other vendors’ PLC programs.
  • Fresh indicators and mitigations: Thirteen new indicator-of-compromise IP addresses were published alongside expanded network-defender recommendations.

The agencies assess this targeting has escalated since at least March 2026, likely in response to hostilities between Iran, the United States, and Israel.

How do the Attacks Work?

The reported tradecraft is opportunistic rather than reliant on a new vulnerability. The actors connect to misconfigured, internet-facing PLCs from leased third-party hosting infrastructure using the manufacturers’ own programming software. Observed malicious traffic targets OT ports 44818, 2222, 102, and 502, along with port 22 on cellular modems.

Once connected, the actors have:

  • Used configuration software such as Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal to exfiltrate device project files to attacker-controlled infrastructure.
  • Deployed Dropbear SSH on victim modems to maintain remote access over port 22.
  • Modified and deleted project file logic, including AOIs, and altered data on HMI and SCADA displays.

The agencies flag a particularly dangerous outcome: in at least one case the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without alerting operators. The mapped MITRE ATT&CK techniques include Internet Accessible Device (T0883), Commonly Used Port (T0885), Remote Access Tools (T1219), Exfiltration Over C2 Channel (T1041), and Data Manipulation (T1565).

Who Is Affected?

The targeted sectors are Government Services and Facilities (including local municipalities), Water and Wastewater Systems, and Energy. The agencies tie the current campaign to a broader pattern of Iranian activity, referencing prior reporting on CyberAv3ngers (also tracked as the Shahid Kaveh Group), a threat actor affiliated with the IRGC Cyber Electronic Command. That earlier campaign, which began in late 2023, compromised at least 75 Unitronics devices, largely in the water sector.

Recommended Mitigations

The advisory’s priority actions for OT owners and operators:

  • Remove PLCs from direct internet exposure and broker any remote access through a secure gateway or jump host.
  • Strictly control network access to PLCs using firewall rules and access control lists, and block traffic from unauthorized hosting-provider IPs.
  • Validate running project files against known-good logic, including checking AOIs for anomalous modifications; verify backups are clean before restoring.
  • Change default PLC passwords, enforce MFA for external access, and place controllers with a physical mode switch into the run position.
  • Query logs for the published IOCs and for suspicious traffic on ports 44818, 2222, 102, 502, and 22.
  • Inform service providers of active threats, since remote monitoring and maintenance arrangements can introduce exposure operators are unaware of.

Organizations that discover affected devices are urged to engage incident response plans and contact the authoring agencies and the relevant PLC vendor.

In Conclusion

This update fits a pattern SOCRadar has profiled since CyberAv3ngers first surfaced against US utilities in late 2023, when the group logged into internet-exposed Unitronics controllers at water systems in several states, including a widely reported incident at a water authority near Pittsburgh, and left defacement messages behind. What has changed is scale and diffusion. The same low-effort playbook, reaching PLCs left open on the internet with default or weak credentials, has spread well beyond any single group, and Iranian-affiliated targeting of US and allied infrastructure has escalated through 2026 in step with the broader Iran-Israel-US cyber conflict.

The core exposure the advisory describes is structural rather than incidental. An internet-facing controller with weak authentication stays reachable regardless of which persona is at the keyboard, and the July additions raise the stakes: project-file tampering that silently disables shutdown and alarm logic moves the risk from data manipulation toward real physical consequences. The practical takeaway for OT owners is to treat internet exposure of PLCs as the first risk to close, then work through the advisory’s detection and hardening steps rather than waiting for a specific IOC to fire.

The full advisory, including the complete IOCs and STIX packages, is available from CISA and the FBI’s IC3.