logo

U.S. agencies alert: Iran-linked actors target critical infrastructure PLCs

ID: 8f104515-8998-5725-9955-5874ab0b39d6

STIX ID: report--8f104515-8998-5725-9955-5874ab0b39d6

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

U.S. federal agencies (including FBI and CISA) published a joint advisory warning that Iran-affiliated APT actors—linked to groups such as CyberAv3ngers—have been targeting internet-exposed PLCs (notably Rockwell/Allen-Bradley CompactLogix and Micro850, and Unitronics devices) and manipulating project files and HMI/SCADA displays to cause operational disruptions across critical infrastructure sectors (water, energy, government services). The actors used leased overseas infrastructure and tools like Studio 5000 and Dropbear, communicated over ports including 44818, 2222, 102, 22, and 502, and are credited with compromising at least 75 devices; the advisory includes IOCs and recommends disconnecting PLCs from the internet, applying vendor guidance, enabling MFA, patching firmware, disabling unused services, monitoring OT ports, and coordinating with authorities for incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.