logo

Iranian Threat Actors Disrupt US Critical Infrastructure via Exposed PLCs

ID: 34f491f5-3c4e-589c-b537-d8602e26d044

STIX ID: report--34f491f5-3c4e-589c-b537-d8602e26d044

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

US and partner agencies warn that Iran-affiliated APT actors are conducting an active campaign against Internet-exposed OT devices — notably Rockwell/Allen‑Bradley PLCs (CompactLogix, Micro850) — across energy, water/wastewater, and government sectors, manipulating PLC project files and HMI/SCADA displays and causing some operational disruption and financial loss; attackers used leased overseas infrastructure and Rockwell Studio 5000 to establish connections, deployed Dropbear SSH, targeted ports including 44818/2222/102/22/502, and CISA published IoCs and mitigation guidance such as removing PLCs from direct Internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.