CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt US Critical Infrastructure
Key Takeaways Iran-linked threat actors are actively targeting internet-exposed industrial control systems (ICS) in U.S. critical infrastructure. The attacks, ongoing since at least March 2026,...
Key Takeaways
- Iran-linked threat actors are actively targeting internet-exposed industrial control systems (ICS) in U.S. critical infrastructure.
- The attacks, ongoing since at least March 2026, exploit insecure configurations rather than new vulnerabilities.
- Programmable Logic Controllers (PLCs) from Rockwell Automation, Schneider Electric, and Siemens have been compromised, leading to operational disruption and financial losses.
- Attackers modify control logic and manipulate human-machine interface (HMI) displays, potentially causing unsafe conditions.
- CISA urges immediate action, including removing direct internet access for PLCs and implementing robust security measures.
Iranian Hackers Exploit Exposed Industrial Control Systems in US Critical Infrastructure
A persistent campaign by threat actors linked to Iran is actively compromising internet-connected industrial controllers within vital U.S. critical infrastructure sectors. This malicious activity has led to significant disruptions in programmable logic controllers (PLCs) across government, water, wastewater, and energy facilities.
Table Of Content
Victims have reported operational outages and financial repercussions after the attackers successfully altered systems responsible for managing physical processes. The cascading effects of such compromises can rapidly escalate, posing substantial risks to industrial operations.
The campaign has been observed since at least March 2026, primarily leveraging poorly secured or directly exposed operational technology (OT) assets. The attackers are utilizing legitimate PLC programming software, connecting from leased foreign infrastructure to gain unauthorized access. Once inside, they download project files, modify control logic, and manipulate the information displayed to operators on human-machine interface (HMI) and SCADA systems.
Targeting and Tactics
Analysts from the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have identified unauthorized modifications to project files, specifically noting changes within reusable code modules in Rockwell Automation programs. The scope of potential exposure is considerable, with prior research indicating thousands of Rockwell PLCs accessible online. The recent advisory also confirms that Schneider Electric and Siemens equipment have been observed as targets.
In a report shared with Cyber Security News (CSN), CISA said that the actors’ intent appears to be causing disruptive effects within the United States. Crucially, this campaign does not rely on exploiting new product vulnerabilities. Instead, it capitalizes on unsafe internet exposure, inadequate access controls, and the misuse of legitimate engineering functions.
Specifically, the intruders have targeted Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 systems, and Siemens S7-1200 devices. This pattern underscores a broader trend where weak credentials and internet-exposed PLCs provide hostile operators with a direct entry point into sensitive industrial environments, bypassing the need for zero-day exploits.
At one U.S. victim site, the attackers employed configuration software to upload a malicious project file to a PLC. While the file maintained sufficient ladder logic to keep downstream functions operational, it introduced instructions that overrode controls designed to maintain safe operating limits. For Rockwell devices, these compromised project files typically bear the .ACD filename extension.
Upon extracting project files, the group proceeded to modify or delete critical control logic, including Add-On Instructions that encapsulate reusable functions. Investigators also discovered manipulated HMI and SCADA data. These alterations effectively disabled crucial shutdown and alarm logic, creating scenarios where equipment could transition into unsafe states without any warning to operators.
The attackers leveraged approved engineering tools from the respective manufacturers, hosted on rented third-party systems, to facilitate the copying of PLC project files. They also utilized Dropbear SSH on victim modems for remote access. These methods bear a striking resemblance to previous Iranian attacks on critical infrastructure, notably those involving the IRGC-linked CyberAv3ngers group, which also targeted exposed industrial control equipment.
What You Should Do
CISA has issued urgent recommendations for defenders to mitigate these threats:
- Immediately disconnect PLCs from the public internet. Implement secure gateways, firewalls, or Virtual Private Networks (VPNs) for any required remote access.
- Apply multi-factor authentication (MFA) to all remote access points.
- Restrict communications to only approved control-system devices and secure cellular modems.
- Regularly review modem and network logs for any unusual or unauthorized access attempts.
- For controllers equipped with a physical mode switch, validate the integrity of the running project file before placing the device into run mode. This prevents remote modification but can also lock in a malicious file if checks are bypassed.
- Siemens users should enable programming protection features, particularly where software key switching is available.
- Compare active PLC programs against known-good logic, meticulously inspect reusable modules and input-output settings, and verify backups before any restoration.
- Review logs from PLCs, modems, HMIs, and engineering workstations for signs of lateral movement. If connected systems are compromised, CISA advises re-imaging affected devices to remove hidden changes or access tools.
- Replace all default passwords, apply current vendor patches, disable unused services, and maintain offline backups of critical logic and configurations.
- Monitor for unexpected protocol usage or commands that alter operating modes. Continuous asset monitoring is crucial for internet-connected industrial control devices.
- Before blocking, check historical logs against the provided Indicators of Compromise (IoCs) below, as these IP addresses were associated with the actors only during specific periods.
- Suspected victims should activate incident response plans, contact relevant U.S. agencies and the equipment manufacturer, and preserve all evidence for investigation.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| IP address | 185.82.73[.]175 |
Actor-associated from September 2025 to February 2026 |
| IP address | 141.11.164[.]153 |
Actor-associated from January 2026 to June 2026 |
| IP address | 175.110.121[.]42 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]39 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]41 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]107 |
Actor-associated during February 2026 |
| IP address | 192.142.54[.]79 |
Actor-associated from May 2026 to June 2026 |
| IP address | 84.200.205[.]165 |
Actor-associated from May 2026 to June 2026 |
| IP address | 185.225.17[.]225 |
Actor-associated from June 2026 to July 2026 |
| IP address | 79.133.46[.]209 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]199 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]200 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]202 |
Actor-associated during July 2026 |
| IP address | 185.82.73[.]162 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]164 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]165 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]167 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]168 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]170 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]171 |
Actor-associated from January 2025 to March 2026 |
| IP address | 135.136.1[.]133 |
Actor-associated during March 2026 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.