logo

Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets

ID: b14c04f8-3dc9-53ad-96c0-037e42c84c6f

STIX ID: report--b14c04f8-3dc9-53ad-96c0-037e42c84c6f

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

...
...

US agencies warn that Iranian-affiliated hackers have been actively targeting internet-facing OT assets (notably Rockwell/Allen-Bradley PLCs) across government, water/wastewater, and energy sectors, conducting malicious project-file interactions and manipulating HMI/SCADA displays. The advisory cites inbound traffic on ports 44818, 2222, 102, 22, and 502, use of Studio 5000 Logix Designer to establish accepted connections from overseas infrastructure, and deployment of Dropbear SSH for remote access; it urges immediate review of TTPs/IOCs, network segmentation, and other mitigations and to contact CISA/FBI/NSA if compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.