Iranian Hackers Broaden PLC Attacks on US Critical Infrastructure
ID: 0edb1ae7-75e4-5c0e-9762-4b0f4d2899c5
STIX ID: report--0edb1ae7-75e4-5c0e-9762-4b0f4d2899c5
Feed Name: SOCRadar Blog
A July 2026 update to a multi-agency advisory warns that Iranian-affiliated APT actors are actively targeting internet-exposed PLCs (Rockwell, Schneider, Siemens and others) across US critical infrastructure—using vendor programming tools to exfiltrate and modify project files (including AOIs), deploying Dropbear SSH on modems, and manipulating HMI/SCADA data; activity has caused operational disruption and, in at least one case, disabled shutdown and alarm logic. The advisory expands detection guidance, publishes additional IOCs and ports to monitor (44818, 2222, 102, 502, 22), and recommends removing controllers from direct internet exposure, validating project files/backups, tightening access controls, and engaging incident response and vendor contacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
