Campaigns
Iran-Linked ICS PLC Targeting Campaign Against Internet-Exposed Water Infrastructure

Iran-Linked ICS PLC Targeting Campaign Against Internet-Exposed Water Infrastructure

CyberAv3ngersUnitronicsPLC ExploitationIRGC-Affiliated ActorsICS/OT SecurityWater and Wastewater SystemsCISA Advisory AA26-097A
CISA has issued an update, tracked as AA26-097A, to its ongoing advisory on Iranian-affiliated cyber actors targeting internet-exposed Programmable Logic Controllers (PLCs), a threat line most publicly associated with the CyberAv3ngers group's prior exploitation of Unitronics Vision series devices in Water and Wastewater Systems (WWS) (unverified whether AA26-097A covers additional vendors beyond Unitronics, as the full advisory body was not available in the source material). WaterISAC republished the update as TLP:CLEAR guidance for water sector asset owners and operators. The advisory reinforces earlier CISA/FBI/NSA warnings that poorly secured.

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

REMEDIATION/DETECTION

Water and wastewater utilities and other critical infrastructure operators should immediately inventory internet-facing OT/ICS assets, close inbound access to PLC programming and HMI ports (including common ports associated with Unitronics Vision series and similar PLCs), enforce network segmentation between IT and OT environments, and deploy perimeter firewalls or VPN gateways with MFA for any legitimate remote engineering access. Organizations should also monitor for scanning activity against exposed ICS services from known malicious infrastructure and subscribe to CISA and sector ISAC (e.g., WaterISAC) alerts for updated indicators tied to AA26-097A.



MITRE Technique

Detection Strategy (DET)

Analytics (AN)

T0812 - Default Credentials

DET-Default-Credential-Login

AN: Alert on successful authentication to PLC/HMI management interfaces using known default or factory credential sets; flag repeated failed logins followed by success.

T0883 - Internet Accessible Device

DET-Exposed-ICS-Asset

AN: Continuously scan external attack surface for OT/ICS devices and management ports reachable from the public internet; alert on newly discovered exposures.

T0866 - Exploitation of Remote Services

DET-Anomalous-Remote-ICS-Access

AN: Detect connections to ICS remote management services from unexpected geographic regions or unmanaged endpoints, and correlate with known Iranian-affiliated actor infrastructure where shared by CISA.

T1078 - Valid Accounts

DET-Valid-Account-Anomaly

AN: Monitor for logins to control system accounts outside normal operational hours or from atypical source IPs, indicating possible credential misuse.

On PLC and HMI devices, hunt for unauthorized configuration changes, unexpected ladder logic or program modifications, altered setpoints, unfamiliar remote access session logs, and defacement-style text or messages pushed to device displays, a technique previously associated with CyberAv3ngers' Unitronics intrusions. Review device event logs for logins using default account names or passwords and verify firmware integrity against vendor-published baselines.


Observed Countries1

US (462)