Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
ID: 7c8faaae-1d3f-50f6-8209-fb9aca0d6891
STIX ID: report--7c8faaae-1d3f-50f6-8209-fb9aca0d6891
Feed Name: CISA Cybersecurity Advisories
U.S. authoring agencies (FBI, CISA, NSA, DOE, EPA, USCYBERCOM) warn that Iranian-affiliated APT actors have exploited internet-accessible PLCs—particularly Rockwell Automation/Allen-Bradley devices—to extract project files and manipulate HMI/SCADA displays across multiple critical infrastructure sectors (Government, Water/Wastewater, Energy), causing operational disruption and financial loss; the advisory includes IOCs (notably several overseas IPs), targeted ports, MITRE ATT&CK mappings, and urgent mitigations such as removing PLCs from direct internet exposure, enforcing MFA/gateways, applying patches, and validating backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
