
Iran-Linked ICS PLC Targeting Campaign Against Internet-Exposed Water Infrastructure
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Water and wastewater utilities and other critical infrastructure operators should immediately inventory internet-facing OT/ICS assets, close inbound access to PLC programming and HMI ports (including common ports associated with Unitronics Vision series and similar PLCs), enforce network segmentation between IT and OT environments, and deploy perimeter firewalls or VPN gateways with MFA for any legitimate remote engineering access. Organizations should also monitor for scanning activity against exposed ICS services from known malicious infrastructure and subscribe to CISA and sector ISAC (e.g., WaterISAC) alerts for updated indicators tied to AA26-097A.
MITRE Technique | Detection Strategy (DET) | Analytics (AN) |
DET-Default-Credential-Login | AN: Alert on successful authentication to PLC/HMI management interfaces using known default or factory credential sets; flag repeated failed logins followed by success. | |
DET-Exposed-ICS-Asset | AN: Continuously scan external attack surface for OT/ICS devices and management ports reachable from the public internet; alert on newly discovered exposures. | |
DET-Anomalous-Remote-ICS-Access | AN: Detect connections to ICS remote management services from unexpected geographic regions or unmanaged endpoints, and correlate with known Iranian-affiliated actor infrastructure where shared by CISA. | |
DET-Valid-Account-Anomaly | AN: Monitor for logins to control system accounts outside normal operational hours or from atypical source IPs, indicating possible credential misuse. |
On PLC and HMI devices, hunt for unauthorized configuration changes, unexpected ladder logic or program modifications, altered setpoints, unfamiliar remote access session logs, and defacement-style text or messages pushed to device displays, a technique previously associated with CyberAv3ngers' Unitronics intrusions. Review device event logs for logins using default account names or passwords and verify firmware integrity against vendor-published baselines.