Iran-linked hackers access U.S. Water Utilities East Coast - Advisory
ID: 59db32aa-f8d5-5860-b61d-b2b119bd7381
STIX ID: report--59db32aa-f8d5-5860-b61d-b2b119bd7381
Feed Name: Ransomware ISAC Blog
A Unified Threat Advisory warns that Iran-linked and Pro‑Russian aligned actors are attempting to compromise small water utilities on the U.S. East Coast by tampering with Eclipse 9800i PLCs that control chlorine residuals and flushing pumps; the advisory describes a Python-based ICS reconnaissance and exfiltration tool called TRK25-ADVANCED (similar to Kurtlar_SCADA.exe). The report is distributed TLP:CLEAR and frames this activity as part of a broader pattern of ICS targeting during geopolitical conflicts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
