Full Report
Iranian hackers who claimed to have struck telecommunications and water systems in Texas last week said they targeted AT&T because of consumer dissatisfaction with the company and backed off from a vow to escalate attacks in conjunction with the 9/11 anniversary. APT IRAN, which threatened at the end of August that “critical events” will hit three U.S.…
Analysis Summary
# Threat Actor: APT IRAN
## Attribution & Identity
* **Actor Identification:** APT IRAN
* **Known Associations:** Closely linked to **CyberAv3ngers**.
* **State Affiliation:** Affiliated with the Iranian Islamic Revolutionary Guard Corps (IRGC).
## Activity Summary
In late August and early September 2026, APT IRAN claimed responsibility for several operations targeting U.S. critical infrastructure:
* **Texas Telecommunications:** Claimed credit for a Labor Day outage affecting AT&T services in Houston, Dallas, Austin, and San Antonio (though AT&T attributed the outage to physical cable theft).
* **Texas Water Infrastructure:** Claimed to have penetrated an unnamed water utility in Texas, disrupting services.
* **Minnesota Water Sector:** Previously claimed hacks against water systems in Minnesota as a "warning."
* **9/11 Anniversary Threats:** Initially vowed to escalate "critical events" through September 11, 2026, but later publicly withdrew this stance, claiming a desire to avoid civilian casualties.
## Tactics, Techniques & Procedures
* **OT Targeting:** Specific focus on Operational Technology (OT) and Industrial Control Systems (ICS).
* **PLC Manipulation:** Tampering with Programmable Logic Controllers (PLCs); evidence showed modifications to files named "PLC1."
* **Influence Operations/Hacktivism:** Use of Telegram channels to announce attacks, post video "proof," and frame activities as retaliation for U.S. political decisions (specifically citing "Trump's adventures").
* **Defacement/File Modification:** Appending strings like `HACKED_BY_APT_IRAN` and `HACKED_BY_CyberAv3ngers` to system program files.
* **Exploitation of Dissatisfaction:** Strategic selection of targets based on perceived public dissatisfaction (e.g., targeting AT&T due to consumer complaints).
## Targeting
* **Sectors:** Water and Wastewater Systems, Telecommunications, Government/Critical Infrastructure.
* **Geography:** United States (specifically Texas and Minnesota).
* **Victims:** AT&T (claimed), unnamed Texas water utility, unnamed Minnesota water utilities.
## Tools & Infrastructure
* **Operational Technology (OT) Exploits:** Tools capable of interacting with and disrupting internet-connected PLCs.
* **Telegram:** Used for command-and-control communication with the public and dissemination of propaganda.
* **Infrastructure Note:** The actor often targets internet-facing OT devices that lack robust authentication.
## Implications
APT IRAN demonstrates a persistent intent to disrupt U.S. critical infrastructure by capitalizing on poorly secured OT environments. While their claims are sometimes disputed by the victims (e.g., AT&T), the group uses these incidents to exert psychological pressure and influence U.S. domestic sentiment. Their alignment with CyberAv3ngers suggests a coordinated Iranian effort to signal capability in disrupting essential services like water and communications.
## Mitigations
* **Secure OT/ICS Environments:** Ensure that Programmable Logic Controllers (PLCs) and other OT devices are not directly accessible from the public internet.
* **Identity and Access Management:** Implement strong, multi-factor authentication (MFA) for all remote access to industrial networks.
* **Network Segmentation:** Isolate OT networks from corporate IT networks to prevent lateral movement.
* **Change Monitoring:** Implement integrity monitoring for PLC logic and system files to detect unauthorized modifications.
* **Vulnerability Management:** Regularly patch internet-facing gateways and VPNs used to access critical infrastructure.