Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
ID: 29606862-ed76-5786-87ba-57b65c15716c
STIX ID: report--29606862-ed76-5786-87ba-57b65c15716c
Feed Name: The Hacker News
Iran-affiliated cyber actors are actively targeting internet-exposed PLCs and other OT devices across U.S. critical infrastructure (government services, water and wastewater, energy). Attackers used leased third-party infrastructure and legitimate configuration software (e.g., Rockwell Studio 5000) to connect to CompactLogix and Micro850 PLCs, deployed Dropbear SSH for persistent remote access, exfiltrated project files, and manipulated HMI/SCADA displays; the report also links MuddyWater to use of CastleRAT and related malware (ChainShell, Tsundere) and highlights a broader state-directed ecosystem leveraging criminal MaaS and hacktivist personas.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
