Iran-linked crews are probing more flavors of US industrial kit

Bender1 pts0 comments

Iran-linked crews are probing more flavors of US industrial kit

Jump to main content

Search

REG AD

SECURITY

Iran-linked crews are probing more flavors of US industrial kit

CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure

Richard Speed

Richard<br>Speed

MICROSOFT ECOSYSTEM REPORTER

Published<br>thu 23 Jul 2026 // 15:30 UTC

The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities.<br>The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, "and potentially other branded/manufactured PLCs."<br>The conflict between the US and Iran is well into its fourth month, and authorities have noticed Iranian-affiliated advanced persistent threat (APT) crews targeting PLCs to cause disruption since March.

REG AD

PLCs are used to control and monitor industrial processes. Authorities said the activity resembled earlier attacks on PLCs by CyberAv3ngers (aka the Shahid Kaveh Group) - hackers affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC).

REG AD

MORE CONTEXT

Water company's leaky security earns near-£1M fine

Iran cyber actors disrupting US water, energy facilities, FBI warns

Iran's cyberwar has begun

Cyberpunks mess with Canada's water, energy, and farm systems

The focus is principally related to internet-facing PLCs. CISA noted attackers targeting devices through open ports: "The targeting of ports associated with other OT vendors' protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen-Bradley, including Schneider Electric and Siemens.<br>"In one reported instance, the actors utilized Dropbear Secure Shell (SSH) software on victim modems to enable them to gain remote access through port 22."<br>Once in, attackers extract device project files and modify or delete their logic.<br>"Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies," CISA said.<br>The expansion of the advisory's scope to include additional PLCs highlights the importance of being aware of what is accessible. On top of to earlier mitigations that included disconnecting the PLC from the public-facing internet, authorities have suggested organizations consider implementing isolated architectures and controlling network access to PLC devices.<br>It would also be a good idea to check project files running on PLCs for unauthorized changes, make sure service providers are aware of threats targeting PLCs, and ensure default passwords are changed. ®

critical infrastructure<br>cisa<br>security<br>iran

REG AD

Patches

Year-long Russian attacks infect users as soon as they look at an email

Phishing for dummies

DEVOPS

Model Context Protocol prepares to break with its stateful past

Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog

Gobi X: Creating more energy for AI, not taking it from society

PARTNER CONTENT: How Envision is reversing the datacenter playbook by making computing chase abundant desert power, not the other way around

security

Millions of California-bought cars can be hijacked via Bluetooth

Aftermarket dealer-installed KARR/SWDS security systems all use the same secure key, say UCSD researchers

columnists

Airbus takes flight from AWS. What happens next is critical

Which way to the Land of the Free again?

Security

Oracle drops 1,449 security patches like it's the new normal

Experts say the era of AI bug hunting is here, so defenders will simply have to adapt to busier workloads

MOST POPULAR

columnists

Airbus takes flight from AWS. What happens next is critical

off-prem

Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five

security

Linux kernel team publishes 432 CVEs in two days

AI AND ML

OpenAI admits it was the source of the agent swarm that attacked Hugging Face

off-prem

AWS customer learns the hard way how even the smallest oversight can be mission-critical

AI

DEVOPS

Model Context Protocol prepares to break with its stateful past

Biggest overhaul since launch ditches sessions, guts little-used features, and leaves homebrew implementations facing a slog

Offbeat

Tesla burns through a billion as Musk bets the farm on chips and bots

Optimus remains 'very complex' and Robotaxis will try not to flatten your cat

software

IBM insists AI didn't kill software deals, just delayed them

Big Blue says customers postponed rather than abandoned major purchases as hardware soaked up enterprise...

security plcs iran critical cisa facing

Related Articles