logo

Critical Alert: Iranian-Affiliated Actors Target U.S. Infrastructure via Industrial Control Systems

ID: 53bcd440-0ab8-59f2-adbb-6fc61e3e8205

STIX ID: report--53bcd440-0ab8-59f2-adbb-6fc61e3e8205

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

A coalition of U.S. federal agencies (FBI, CISA, NSA, EPA, DOE, CNMF) issued an urgent April 7, 2026 advisory warning that Iranian-affiliated APT actors are actively compromising internet-facing Rockwell Automation/Allen-Bradley PLCs (e.g., CompactLogix, Micro850) using leased overseas infrastructure and legitimate engineering tools (Studio 5000), deploying Dropbear SSH and targeting OT ports (44818, 2222, 102, 502, 22) to manipulate HMIs/SCADA displays and cause operational disruptions across Energy, Water/Wastewater, and Government facilities; the advisory provides IOCs, TTPs, and immediate mitigations (disconnect PLCs, use secure gateways/jump hosts, set physical switches to Run, monitor OT ports).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.