logo

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

ID: 7c8faaae-1d3f-50f6-8209-fb9aca0d6891

STIX ID: report--7c8faaae-1d3f-50f6-8209-fb9aca0d6891

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-19

Author: CISA

...
...

U.S. authoring agencies (FBI, CISA, NSA, DOE, EPA, USCYBERCOM) warn that Iranian-affiliated APT actors have exploited internet-accessible PLCs—particularly Rockwell Automation/Allen-Bradley devices—to extract project files and manipulate HMI/SCADA displays across multiple critical infrastructure sectors (Government, Water/Wastewater, Energy), causing operational disruption and financial loss; the advisory includes IOCs (notably several overseas IPs), targeted ports, MITRE ATT&CK mappings, and urgent mitigations such as removing PLCs from direct internet exposure, enforcing MFA/gateways, applying patches, and validating backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.