Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors.
A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology (OT) environments, with attackers leveraging misconfigured, internet-exposed PLCs to manipulate industrial processes.
The campaign has impacted multiple U.S. sectors, including government facilities, water and wastewater systems, and energy infrastructure.
Investigations reveal that threat actors are interacting directly with PLC project files and altering data displayed on human-machine interfaces (HMI) and supervisory control and data acquisition (SCADA) systems.
In several confirmed cases, these manipulations resulted in operational disruption and financial losses.
Authorities attribute the activity to Iranian-affiliated actors, potentially linked to the IRGC Cyber Electronic Command, consistent with previously tracked groups such as CyberAv3ngers (also known as APT Iran, UNC5691, and Shahid Kaveh Group).
Similar tactics were observed in earlier campaigns, including the 2023 compromise of Unitronics PLCs, where attackers deployed malicious ladder logic to override legitimate control processes.
CISA Researchers said that, the advisory, originally published on April 7, 2026, was updated on July 22, 2026, to expand the scope of affected vendors and provide new detection guidance, particularly around malicious modifications in reusable code modules within Rockwell PLC environments.
Rockwell, Schneider and Siemens Exploited
Technically, the attackers are exploiting exposed PLC services using vendor-specific programming software, including Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, and Siemens TIA Portal.
Initial access is achieved via internet-facing devices communicating over industrial protocol ports such as 44818, 2222, 102, and 502, alongside SSH access over port 22.
The adversaries use leased infrastructure and foreign IP addresses to connect to these devices, aligning with MITRE ATT&CK techniques such as T0883 (Exploitation of Remote Services).
A notable evolution in this campaign is the deployment of malicious project files that retain legitimate ladder logic while introducing unauthorized instructions that override safety-critical parameters.
In one observed case, the malicious logic selectively modified control functions without disrupting downstream processes, making detection significantly more challenging.
The actors have also demonstrated the ability to exfiltrate PLC project files by leveraging legitimate engineering tools, effectively blending malicious activity with normal operational workflows.
This behavior aligns with ATT&CK technique T0885 (Commonly Used Port) and highlights the growing abuse of trusted OT engineering environments for command-and-control and data exfiltration.
Additionally, the use of Dropbear SSH on compromised modems has been observed to maintain persistent remote access, further complicating incident response efforts.
These tactics indicate a deliberate focus on persistence, stealth, and operational impact rather than simple reconnaissance.
The advisory strongly emphasizes that internet exposure of OT devices remains a primary risk factor. Organizations are urged to immediately restrict direct internet access to PLCs, implement network segmentation, and monitor for unauthorized changes in control logic and project files.
IOCs
IndicatorBeginning of Actor AssociationEnd of Actor Association185.82.73[.]175September 2025February 2026141.11.164[.]153January 2026June 2026175.110.121[.]42February 2026March 2026175.110.121[.]39February 2026March 2026175.110.121[.]41February 2026March 2026175.110.121[.]107February 2026February 2026192.142.54[.]79May 2026June 202684.200.205[.]165May 2026June 2026185.225.17[.]225June 2026July 202679.133.46[.]209July 2026July 2026
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist