logo

From Exploits to Forensics: Unraveling the Unitronics Attack

ID: 4897ddbe-7b83-52fe-8f1d-77ee8cd83988

STIX ID: report--4897ddbe-7b83-52fe-8f1d-77ee8cd83988

Feed Name: Claroty Team82

Threat Score
80/100

Date Published: 2024-08-07

Date Updated: 2026-04-17

...
...

Team82 documents their reverse-engineering of Unitronics’ proprietary PCOM protocol and the development of two forensic tools (PCOM2TCP and PCOMClient) to extract evidence from Vision/Samba PLCs; their research uncovered two CVEs and detailed how an Iran-linked group (CyberAv3ngers) exploited weak authentication to deface water-treatment facility devices, while the report also enumerates PCOM opcodes and PLC-resident forensic artifacts (VisiLogic project file and signature log).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.