Full Report
Iranian hackers pushed back after Wednesday’s denial of their claim that they hit AT&T service in major Texas cities on Labor Day, declaring that those rebuffing their claim “don’t even know what we tampered with” or “have access to.” APT IRAN, which threatened at the end of August that “critical events” will hit three U.S. critical infrastructure…
Analysis Summary
# Threat Actor: APT IRAN
## Attribution & Identity
* **Actor Identification:** APT IRAN
* **Aliases:** Likely associated or rebranding of Iranian state-sponsored elements.
* **Known Associations:** Closely linked to **CyberAv3ngers**, a group affiliated with the Islamic Revolutionary Guard Corps (IRGC).
## Activity Summary
* **Labor Day 2026 Operations:** The group claimed responsibility for a major telecommunications outage affecting AT&T in Texas and the breach of an unnamed Texas water utility.
* **9/11 Threats:** The actor has explicitly vowed to intensify cyber operations against U.S. critical infrastructure leading up to September 11th.
* **Historical Campaigns:** Previously claimed responsibility for water utility hacks in Minnesota and other U.S. states in mid-August 2026.
## Tactics, Techniques & Procedures
* **OT/ICS Targeting:** Specifically targets Operational Technology (OT), including Programmable Logic Controllers (PLCs).
* **Information Operations:** Uses Telegram channels to claim credit for infrastructure failures (even those attributed by victims to physical causes like cable theft) to seed public distrust.
* **System Defacement/File Manipulation:** Demonstrated the ability to append "HACKED_BY" strings to system files and program directories.
* **Exploitation of Internet-Connected Devices:** Leverages vulnerabilities in internet-exposed industrial control systems.
* **Relevant MITRE ATT&CK IDs:**
* T0813 (Denial of Service)
* T0831 (Manipulation of Control)
* T0883 (Internet Accessible Device)
## Targeting
* **Sectors:** Telecommunications, Water and Wastewater Systems, and general Critical Infrastructure.
* **Geography:** United States (specifically Texas and Minnesota).
* **Victims:**
* AT&T (Targeted/Claimed)
* Texas Water Utilities (Unnamed)
* Minnesota Water Utilities
## Tools & Infrastructure
* **Telegram:** Used for psychological operations, propaganda, and claims of responsibility.
* **Malware/Tools:** Evidence of scripts or manual commands used to modify "programs" files on PLCs.
* **Infrastructure:** Usage of compromised internet-connected PLCs (identifiable by names ending in "PLC1").
## Implications
APT IRAN represents a persistent threat to U.S. national security by focusing on the "psychological impact" of critical infrastructure disruption. By claiming credit for outages (regardless of whether the disruption was caused by a cyberattack or physical accident), the group aims to create a sense of vulnerability within the American public. Their rhetoric suggests a shift toward a "new phase of confrontation" where Iranian actors seek to exert mutual pressure on the U.S. via domestic infrastructure interference.
## Mitigations
* **OT/ICS Security:** Disconnect Programmable Logic Controllers (PLCs) and other OT equipment from the public-facing internet.
* **Identity Management:** Implement strong multi-factor authentication (MFA) for all remote access to utility control systems.
* **Vulnerability Management:** Follow CISA advisory **AA26-097A** regarding Iranian-affiliated targeting of internet-connected OT devices.
* **Resilience Planning:** Verify manual overrides for critical water and communication functions to ensure continuity of operations during a cyber incident.