U.S. agencies alert: Iran-linked actors target critical infrastructure PLCs
ID: 8f104515-8998-5725-9955-5874ab0b39d6
STIX ID: report--8f104515-8998-5725-9955-5874ab0b39d6
Feed Name: Security Affairs
U.S. federal agencies (including FBI and CISA) published a joint advisory warning that Iran-affiliated APT actors—linked to groups such as CyberAv3ngers—have been targeting internet-exposed PLCs (notably Rockwell/Allen-Bradley CompactLogix and Micro850, and Unitronics devices) and manipulating project files and HMI/SCADA displays to cause operational disruptions across critical infrastructure sectors (water, energy, government services). The actors used leased overseas infrastructure and tools like Studio 5000 and Dropbear, communicated over ports including 44818, 2222, 102, 22, and 502, and are credited with compromising at least 75 devices; the advisory includes IOCs and recommends disconnecting PLCs from the internet, applying vendor guidance, enabling MFA, patching firmware, disabling unused services, monitoring OT ports, and coordinating with authorities for incident response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
