Iranian Hackers Disable Industrial Safety Alarms in Critical Infrastructure
Key Takeaways Iranian-backed threat actors are actively targeting internet-exposed industrial control systems (ICS) across critical infrastructure in the U.S. The attackers are manipulating...
Key Takeaways
- Iranian-backed threat actors are actively targeting internet-exposed industrial control systems (ICS) across critical infrastructure in the U.S.
- The attackers are manipulating Programmable Logic Controllers (PLCs) to disable safety alarms and alter operational data, creating severe risks of physical disruption and equipment damage.
- The campaign affects devices from multiple major vendors, including Rockwell Automation, Schneider Electric, and Siemens.
- Poorly secured, publicly accessible PLCs are the primary entry point for these attacks.
A persistent cyber campaign linked to Iranian state-sponsored groups is targeting internet-connected industrial controllers within critical infrastructure sectors across the United States. These malicious activities pose a significant threat to essential services such as water, energy, and government operations, where even minor alterations to control logic can lead to severe real-world consequences.
Table Of Content
The attackers are exploiting publicly exposed Programmable Logic Controllers (PLCs), gaining unauthorized access to and manipulating the project files that dictate their operations. This intrusion allows them to alter the information displayed on operator screens, effectively blinding staff to abnormal system behaviors and potential dangers.
According to analysts from the Cybersecurity and Infrastructure Security Agency (CISA), this campaign has expanded beyond a single manufacturer, now encompassing devices from several prominent industrial automation providers. CISA has indicated that the ongoing activity has already resulted in operational disruptions and financial losses for affected organizations.
In a report shared with Cyber Security News (CSN), CISA said in a report that Iranian-linked actors leverage third-party hosted infrastructure and industrial programming software to infiltrate vulnerable systems. This advisory underscores the critical risk presented by exposed industrial equipment, which serves as a direct gateway for threat actors aiming to interrupt physical operations.
Iranian Hackers Manipulating Industrial Safety Alarms
The most alarming aspect of this campaign is the documented manipulation of safety controls. Investigators have discovered that attackers are capable of modifying or entirely removing PLC project logic, including critical reusable code components designed to maintain safe operating limits within industrial processes.
In one specific incident, a malicious project file was observed to retain enough legitimate ladder logic to keep downstream functions operational. However, it also incorporated additional instructions that specifically overrode safety-related functions, allowing equipment to continue running outside approved parameters without immediately triggering alerts or drawing operator attention.
Furthermore, the attackers have been manipulating data presented through human-machine interface (HMI) and supervisory control screens. This sophisticated tactic means that an operator might observe seemingly normal values on their display, while the underlying controller has been compromised and altered. This creates a dangerous disparity between the actual conditions in the field and what personnel perceive, increasing the risk of catastrophic failure.
Such a risk is particularly severe in sectors where alarms and shutdown logic are specifically engineered to halt equipment before conditions escalate to unsafe levels. This ongoing campaign reiterates concerns previously highlighted in various industrial control system advisories, emphasizing how exposed devices and inadequate remote-access controls continue to create avoidable vulnerabilities within critical infrastructure.
CISA specifically identified targeted devices as Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 PLCs. The agency also cautioned that other internet-facing controllers could be susceptible to similar opportunistic attacks.
Exposed PLCs Provide Initial Access
The threat actors gained access to PLCs that were directly accessible from the public internet, utilizing ports commonly associated with industrial protocols. Reports also indicate their use of Dropbear Secure Shell software on compromised modems to establish remote access via port 22.
Once a device was compromised, the group was able to extract project files, thoroughly analyze the operating environment, and upload their modified logic. This capability allows attackers to customize their changes specifically for a victim’s unique industrial process, moving beyond generic disruption methods to highly targeted sabotage.
What You Should Do
- Remove PLCs from Direct Internet Exposure: Ensure all PLCs are isolated from the public internet. Implement secure remote access solutions, such as monitored gateways or jump hosts, for any necessary external connectivity.
- Implement Secure Connectivity Principles: Adhere to secure connectivity principles for Operational Technology (OT), emphasizing controlled access, robust logging, network segmentation, and comprehensive isolation plans.
- Regularly Review Project Files and Backups: Periodically compare current controller project files against known-good versions. Verify the integrity of all backups before restoration and inspect connected modems, workstations, and operator screens for any unauthorized modifications.
- Utilize Physical Mode Switches: For controllers equipped with a physical mode switch, set it to the “run” position after legitimate work is complete to prevent unauthorized remote modifications.
- Strengthen Authentication and Access Controls: Enforce strong, unique passwords and multi-factor authentication (MFA) for all remote OT access. Implement strict firewall rules and conduct regular reviews of network logs.
- Monitor for Suspicious Activity: Actively monitor for unusual connections to industrial ports, unexpected programming activity, and login attempts originating from unfamiliar or foreign hosting providers.
- Maintain Accurate Asset Inventories: Develop and maintain precise asset inventories for all industrial control systems. Clearly define ownership and responsibility for all remote connections.
- Prioritize External-Facing Controllers: Treat every externally reachable controller as a high-priority exposure. Isolate or secure these devices immediately if they are accessible from the public internet.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.