logo

Iranian APT alert: 5,219 Rockwell PLCs exposed online

ID: 5a346add-1b79-54bf-ae01-dc26350f3c93

STIX ID: report--5a346add-1b79-54bf-ae01-dc26350f3c93

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-10

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Censys and U.S. agencies warn that Iranian-affiliated APT actors (linked to IRGC Cyber Electronic Command/CyberAv3ngers) are actively targeting internet-facing Rockwell/Allen‑Bradley PLCs using legitimate Rockwell tooling to access and modify PLC/HMI projects. Telemetry shows 5,219 exposed EtherNet/IP hosts (74.6% in the U.S.), numerous co-exposed services (VNC, Telnet, Modbus), and attacker infrastructure tied to specific IPs and certificates; agencies advise immediate isolation of PLCs from the internet, use of VPN/jump hosts, hardening of exposed services, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.