Iranian APT alert: 5,219 Rockwell PLCs exposed online
ID: 5a346add-1b79-54bf-ae01-dc26350f3c93
STIX ID: report--5a346add-1b79-54bf-ae01-dc26350f3c93
Feed Name: GBHackers
Censys and U.S. agencies warn that Iranian-affiliated APT actors (linked to IRGC Cyber Electronic Command/CyberAv3ngers) are actively targeting internet-facing Rockwell/Allen‑Bradley PLCs using legitimate Rockwell tooling to access and modify PLC/HMI projects. Telemetry shows 5,219 exposed EtherNet/IP hosts (74.6% in the U.S.), numerous co-exposed services (VNC, Telnet, Modbus), and attacker infrastructure tied to specific IPs and certificates; agencies advise immediate isolation of PLCs from the internet, use of VPN/jump hosts, hardening of exposed services, and offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
