Iran-Linked CyberAv3ngers Target Water Utilities, Industrial Controllers
ID: 0cc237be-ab56-52fd-a32c-089b1da1b7d2
STIX ID: report--0cc237be-ab56-52fd-a32c-089b1da1b7d2
Feed Name: GBHackers
**Executive summary:** Iran-linked CyberAv3ngers (an IRGC-CEC persona) has escalated from opportunistic PLC compromises to deliberate OT disruption, employing the IOCONTROL malware and exploiting an unpatchable authentication bypass (CVE-2021-22681) in Rockwell/Allen‑Bradley Logix controllers; US agencies have confirmed active exploitation against water, energy, and government targets, and defenders are urged to immediately isolate internet-exposed PLCs, enforce secure remote access, apply defense-in-depth controls, and deploy the recommended IoCs and monitoring for EtherNet/IP (TCP 44818), MQTT over TLS (TCP 8883), and DoH activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
