Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Bluetooth Flaw Exposes 2.2M Cars to Remote Attacks
July 23, 2026
Critical SonicWall GMS, Analytics Flaws Let Attackers Execute Code
July 23, 2026
Chick-fil-A One Accounts Compromised in Data Breach
July 23, 2026
Home/Threats/CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt US Critical Infrastructure
Threats

CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt US Critical Infrastructure

Key Takeaways Iran-linked threat actors are actively targeting internet-exposed industrial control systems (ICS) in U.S. critical infrastructure. The attacks, ongoing since at least March 2026,...

Marcus Rodriguez
Marcus Rodriguez
July 23, 2026 5 Min Read
2 0

Key Takeaways

  • Iran-linked threat actors are actively targeting internet-exposed industrial control systems (ICS) in U.S. critical infrastructure.
  • The attacks, ongoing since at least March 2026, exploit insecure configurations rather than new vulnerabilities.
  • Programmable Logic Controllers (PLCs) from Rockwell Automation, Schneider Electric, and Siemens have been compromised, leading to operational disruption and financial losses.
  • Attackers modify control logic and manipulate human-machine interface (HMI) displays, potentially causing unsafe conditions.
  • CISA urges immediate action, including removing direct internet access for PLCs and implementing robust security measures.

Iranian Hackers Exploit Exposed Industrial Control Systems in US Critical Infrastructure

A persistent campaign by threat actors linked to Iran is actively compromising internet-connected industrial controllers within vital U.S. critical infrastructure sectors. This malicious activity has led to significant disruptions in programmable logic controllers (PLCs) across government, water, wastewater, and energy facilities.

Table Of Content

  • Key Takeaways
  • Iranian Hackers Exploit Exposed Industrial Control Systems in US Critical Infrastructure
  • Targeting and Tactics
  • What You Should Do

Victims have reported operational outages and financial repercussions after the attackers successfully altered systems responsible for managing physical processes. The cascading effects of such compromises can rapidly escalate, posing substantial risks to industrial operations.

The campaign has been observed since at least March 2026, primarily leveraging poorly secured or directly exposed operational technology (OT) assets. The attackers are utilizing legitimate PLC programming software, connecting from leased foreign infrastructure to gain unauthorized access. Once inside, they download project files, modify control logic, and manipulate the information displayed to operators on human-machine interface (HMI) and SCADA systems.

Targeting and Tactics

Analysts from the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have identified unauthorized modifications to project files, specifically noting changes within reusable code modules in Rockwell Automation programs. The scope of potential exposure is considerable, with prior research indicating thousands of Rockwell PLCs accessible online. The recent advisory also confirms that Schneider Electric and Siemens equipment have been observed as targets.

In a report shared with Cyber Security News (CSN), CISA said that the actors’ intent appears to be causing disruptive effects within the United States. Crucially, this campaign does not rely on exploiting new product vulnerabilities. Instead, it capitalizes on unsafe internet exposure, inadequate access controls, and the misuse of legitimate engineering functions.

Specifically, the intruders have targeted Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 systems, and Siemens S7-1200 devices. This pattern underscores a broader trend where weak credentials and internet-exposed PLCs provide hostile operators with a direct entry point into sensitive industrial environments, bypassing the need for zero-day exploits.

At one U.S. victim site, the attackers employed configuration software to upload a malicious project file to a PLC. While the file maintained sufficient ladder logic to keep downstream functions operational, it introduced instructions that overrode controls designed to maintain safe operating limits. For Rockwell devices, these compromised project files typically bear the .ACD filename extension.

Upon extracting project files, the group proceeded to modify or delete critical control logic, including Add-On Instructions that encapsulate reusable functions. Investigators also discovered manipulated HMI and SCADA data. These alterations effectively disabled crucial shutdown and alarm logic, creating scenarios where equipment could transition into unsafe states without any warning to operators.

The attackers leveraged approved engineering tools from the respective manufacturers, hosted on rented third-party systems, to facilitate the copying of PLC project files. They also utilized Dropbear SSH on victim modems for remote access. These methods bear a striking resemblance to previous Iranian attacks on critical infrastructure, notably those involving the IRGC-linked CyberAv3ngers group, which also targeted exposed industrial control equipment.

What You Should Do

CISA has issued urgent recommendations for defenders to mitigate these threats:

  • Immediately disconnect PLCs from the public internet. Implement secure gateways, firewalls, or Virtual Private Networks (VPNs) for any required remote access.
  • Apply multi-factor authentication (MFA) to all remote access points.
  • Restrict communications to only approved control-system devices and secure cellular modems.
  • Regularly review modem and network logs for any unusual or unauthorized access attempts.
  • For controllers equipped with a physical mode switch, validate the integrity of the running project file before placing the device into run mode. This prevents remote modification but can also lock in a malicious file if checks are bypassed.
  • Siemens users should enable programming protection features, particularly where software key switching is available.
  • Compare active PLC programs against known-good logic, meticulously inspect reusable modules and input-output settings, and verify backups before any restoration.
  • Review logs from PLCs, modems, HMIs, and engineering workstations for signs of lateral movement. If connected systems are compromised, CISA advises re-imaging affected devices to remove hidden changes or access tools.
  • Replace all default passwords, apply current vendor patches, disable unused services, and maintain offline backups of critical logic and configurations.
  • Monitor for unexpected protocol usage or commands that alter operating modes. Continuous asset monitoring is crucial for internet-connected industrial control devices.
  • Before blocking, check historical logs against the provided Indicators of Compromise (IoCs) below, as these IP addresses were associated with the actors only during specific periods.
  • Suspected victims should activate incident response plans, contact relevant U.S. agencies and the equipment manufacturer, and preserve all evidence for investigation.

Indicators of Compromise (IoCs):

Type Indicator Description
IP address 185.82.73[.]175 Actor-associated from September 2025 to February 2026
IP address 141.11.164[.]153 Actor-associated from January 2026 to June 2026
IP address 175.110.121[.]42 Actor-associated from February 2026 to March 2026
IP address 175.110.121[.]39 Actor-associated from February 2026 to March 2026
IP address 175.110.121[.]41 Actor-associated from February 2026 to March 2026
IP address 175.110.121[.]107 Actor-associated during February 2026
IP address 192.142.54[.]79 Actor-associated from May 2026 to June 2026
IP address 84.200.205[.]165 Actor-associated from May 2026 to June 2026
IP address 185.225.17[.]225 Actor-associated from June 2026 to July 2026
IP address 79.133.46[.]209 Actor-associated during July 2026
IP address 88.80.150[.]199 Actor-associated during July 2026
IP address 88.80.150[.]200 Actor-associated during July 2026
IP address 88.80.150[.]202 Actor-associated during July 2026
IP address 185.82.73[.]162 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]164 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]165 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]167 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]168 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]170 Actor-associated from January 2025 to March 2026
IP address 185.82.73[.]171 Actor-associated from January 2025 to March 2026
IP address 135.136.1[.]133 Actor-associated during March 2026

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerPatchSecurityThreatVulnerabilityzero-day

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Anthropic’s Claude AI Gains Code Vulnerability Scanning Plugin

Next Post

Chick-fil-A One Accounts Compromised in Data Breach

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Check Point Authentication Vulnerability Exploited in Attacks
July 23, 2026
Critical Adobe Acrobat Flaw Steals WhatsApp Chats From 329M Users
July 22, 2026
Critical RefluxFS Linux Kernel Bug Lets Attackers Gain Root Access
July 22, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us