Full Report
Agencies are urgently warning U.S. organizations of ongoing Iranian-affiliated cyber targetingof internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors throughmalicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational…
Analysis Summary
# Threat Actor: Iranian-affiliated cyber actors
## Attribution & Identity
- **Identity:** Iranian-affiliated cyber actors.
- **Known Associations:** Linked specifically to ongoing Iranian geopolitical conflicts and state-sponsored interests.
- **Aliases:** While the specific group name (e.g., Cyber Av3ngers) is often associated with these TTPs in contemporary intelligence, the article refers to them broadly as "Iranian-affiliated cyber actors" and "Pro-Iran hackers."
## Activity Summary
The actors are engaged in an ongoing campaign (as of July 2026 reports) targeting internet-connected operational technology (OT) devices. Recent operations involve the exploitation of PLCs to disrupt critical infrastructure. This includes a specific claim of responsibility for a United Airlines outage and widespread targeting of industrial control systems (ICS).
## Tactics, Techniques & Procedures
- **OT Exploitation:** Direct targeting of internet-connected PLCs.
- **Malicious Project Files:** Interacting with and modifying PLC project files to alter logic.
- **HMI/SCADA Manipulation:** Manipulating data on Human Machine Interface (HMI) and Supervisory Control and Data Acquisition (SCADA) displays to mislead operators or cause disruptions.
- **Code Injection:** Exploiting reusable code modules within PLC programs.
- **Exploitation of Default Configurations:** Targeting devices left exposed to the public internet.
## Targeting
- **Sectors:** Water and Wastewater Systems (implied by PLC/SCADA focus), Energy, Transportation (United Airlines), and general Critical Infrastructure sectors.
- **Geography:** Primarily the United States.
- **Victims:** Rockwell Automation users, Schneider Electric, Siemens, and United Airlines.
## Tools & Infrastructure
- **Vulnerable Hardware:**
- Rockwell Automation PLCs
- Schneider Electric PLCs
- Siemens PLCs
- **Software:** SCADA and HMI display software.
- **Infrastructure:** The actors scan for and target devices with direct exposure to the public internet.
## Implications
These activities represent a significant shift toward the direct disruption of physical processes within U.S. critical infrastructure. The manipulation of HMI/SCADA data can lead to "blind" operations where controllers are unaware of the true state of the machinery, potentially resulting in physical damage, environmental hazards, or financial loss. The targeting of multiple brands (Rockwell, Schneider, Siemens) indicates a broad capability to adapt to diverse industrial environments.
## Mitigations
- **Restrict Connectivity:** Ensure PLCs and OT devices are not directly accessible from the public internet.
- **Secure Deployment:** Follow manufacturer-specific guidance for Schneider, Siemens, and Rockwell Automation for secure hardening.
- **Code Integrity:** Implement the IC3 guidance for detecting malicious changes in reusable code modules.
- **Access Control:** Use VPNs with Multi-Factor Authentication (MFA) for any necessary remote access to OT environments.
- **Air Gapping:** Where possible, maintain physical separation between IT and OT networks.