Friday, September 11, 2026

Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure

Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors.

A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology (OT) environments, with attackers leveraging misconfigured, internet-exposed PLCs to manipulate industrial processes.

The campaign has impacted multiple U.S. sectors, including government facilities, water and wastewater systems, and energy infrastructure.

Investigations reveal that threat actors are interacting directly with PLC project files and altering data displayed on human-machine interfaces (HMI) and supervisory control and data acquisition (SCADA) systems.

In several confirmed cases, these manipulations resulted in operational disruption and financial losses.

Authorities attribute the activity to Iranian-affiliated actors, potentially linked to the IRGC Cyber Electronic Command, consistent with previously tracked groups such as CyberAv3ngers (also known as APT Iran, UNC5691, and Shahid Kaveh Group).

Similar tactics were observed in earlier campaigns, including the 2023 compromise of Unitronics PLCs, where attackers deployed malicious ladder logic to override legitimate control processes.

CISA Researchers said that, the advisory, originally published on April 7, 2026, was updated on July 22, 2026, to expand the scope of affected vendors and provide new detection guidance, particularly around malicious modifications in reusable code modules within Rockwell PLC environments.

Rockwell, Schneider and Siemens Exploited

Technically, the attackers are exploiting exposed PLC services using vendor-specific programming software, including Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, and Siemens TIA Portal.

Initial access is achieved via internet-facing devices communicating over industrial protocol ports such as 44818, 2222, 102, and 502, alongside SSH access over port 22.

The adversaries use leased infrastructure and foreign IP addresses to connect to these devices, aligning with MITRE ATT&CK techniques such as T0883 (Exploitation of Remote Services).

A notable evolution in this campaign is the deployment of malicious project files that retain legitimate ladder logic while introducing unauthorized instructions that override safety-critical parameters.

In one observed case, the malicious logic selectively modified control functions without disrupting downstream processes, making detection significantly more challenging.

The actors have also demonstrated the ability to exfiltrate PLC project files by leveraging legitimate engineering tools, effectively blending malicious activity with normal operational workflows.

This behavior aligns with ATT&CK technique T0885 (Commonly Used Port) and highlights the growing abuse of trusted OT engineering environments for command-and-control and data exfiltration.

Additionally, the use of Dropbear SSH on compromised modems has been observed to maintain persistent remote access, further complicating incident response efforts.

These tactics indicate a deliberate focus on persistence, stealth, and operational impact rather than simple reconnaissance.

The advisory strongly emphasizes that internet exposure of OT devices remains a primary risk factor. Organizations are urged to immediately restrict direct internet access to PLCs, implement network segmentation, and monitor for unauthorized changes in control logic and project files.

IOCs

IndicatorBeginning of Actor AssociationEnd of Actor Association
185.82.73[.]175September 2025February 2026
141.11.164[.]153January 2026June 2026
175.110.121[.]42February 2026March 2026
175.110.121[.]39February 2026March 2026
175.110.121[.]41February 2026March 2026
175.110.121[.]107February 2026February 2026
192.142.54[.]79May 2026June 2026
84.200.205[.]165May 2026June 2026
185.225.17[.]225June 2026July 2026
79.133.46[.]209July 2026July 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist : Download the AI SOC Features Checklist

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News