Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets
ID: b14c04f8-3dc9-53ad-96c0-037e42c84c6f
STIX ID: report--b14c04f8-3dc9-53ad-96c0-037e42c84c6f
Feed Name: Infosecurity Magazine (News)
US agencies warn that Iranian-affiliated hackers have been actively targeting internet-facing OT assets (notably Rockwell/Allen-Bradley PLCs) across government, water/wastewater, and energy sectors, conducting malicious project-file interactions and manipulating HMI/SCADA displays. The advisory cites inbound traffic on ports 44818, 2222, 102, 22, and 502, use of Studio 5000 Logix Designer to establish accepted connections from overseas infrastructure, and deployment of Dropbear SSH for remote access; it urges immediate review of TTPs/IOCs, network segmentation, and other mitigations and to contact CISA/FBI/NSA if compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
