Full Report
CISA widens alert beyond Rockwell controllers as intruders target internet-facing devices across critical infrastructure
Analysis Summary
# Threat Actor: CyberAv3ngers (aka Shahid Kaveh Group)
## Attribution & Identity
* **Aliases:** CyberAv3ngers, Shahid Kaveh Group.
* **Affiliation:** Iranian Government-affiliated; specifically linked to the **Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command (CEC)**.
## Activity Summary
Since March 2026, these actors have been observed targeting internet-facing Industrial Control Systems (ICS) and Programmable Logic Controllers (PLCs) across US critical infrastructure. While initial alerts focused on Rockwell Automation equipment, recent activity shows the group has expanded its scope to probe and compromise devices from multiple vendors including Schneider Electric and Siemens. The operations are characterized by opportunistic scanning for internet-exposed industrial hardware to cause operational disruption.
## Tactics, Techniques & Procedures
* **Initial Access via Open Ports:** Opportunistic targeting of internet-facing devices through open ports associated with Operational Technology (OT) protocols.
* **Remote Access:** Use of Dropbear Secure Shell (SSH) software on victim modems to establish remote access via port 22.
* **Logic Manipulation:** Extraction of device project files followed by the modification or deletion of PLC logic.
* **Safety Logic Suppression:** Specifically disabling critical shutdown and alarm logic to allow systems to enter unsafe operating conditions without alerting human operators.
* **Exploitation of Defaults:** Leveraging default passwords on internet-connected industrial hardware.
## Targeting
* **Sectors:** Water and Wastewater Systems, Energy Sector, and general Critical Infrastructure.
* **Geography:** United States.
* **Victims:** Organizations utilizing Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs.
## Tools & Infrastructure
* **Hardware Targets:**
* Rockwell Automation/Allen-Bradley PLCs
* Schneider Electric PLCs
* Siemens PLCs
* **Software:** Dropbear SSH.
* **Network Vectors:** Port 22 (SSH) and vendor-specific OT protocol ports.
## Implications
The transition from targeting a single manufacturer to broad, vendor-agnostic probing suggests a strategic shift toward maximum disruption. By disabling safety protocols and alarm logic, the actor demonstrates an intent to cause physical "unsafe conditions" rather than simple data theft. This represents a significant risk to public safety and environmental security, as operators may be blinded to equipment failure or dangerous process deviations.
## Mitigations
* **Network De-segmentation:** Disconnect all PLCs and industrial controllers from the public-facing internet immediately.
* **Access Control:** Implement isolated architectures (DMZs) and strictly control network access to PLC devices.
* **Credential Hygiene:** Ensure all default passwords on modems, routers, and PLCs are changed to complex, unique passwords.
* **Integrity Checks:** Regularly audit and check project files running on PLCs for unauthorized logic changes or deletions.
* **Vulnerability Management:** Close unnecessary ports (specifically Port 22/SSH) on internet-facing communication hardware/modems.
* **Supply Chain Awareness:** Ensure third-party service providers and vendors are aware of this specific threat vector and have secured their remote access points.