US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
Key Takeaways The U.S. State Department is offering a $10 million reward for information on Amir Yaryab, a top cyber official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic...
Key Takeaways
- The U.S. State Department is offering a $10 million reward for information on Amir Yaryab, a top cyber official in Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).
- Yaryab is accused of directing cyber operations that have targeted critical infrastructure across the U.S., Europe, and the Middle East.
- The IRGC-CEC, through groups like CyberAv3ngers, has been linked to attacks on industrial control systems, including at least 75 Unitronics PLCs, with 34 in the U.S. water and wastewater sector.
- These attacks involved defacement, alteration of PLC ladder logic, and manipulation of operational data, highlighting severe vulnerabilities in critical infrastructure.
U.S. Targets Iranian Cyber Chief with $10 Million Bounty
The United States Department of State’s Rewards for Justice program has announced a substantial reward of up to $10 million. This bounty is for intelligence that leads to the identification or location of Amir Yaryab, a high-ranking officer within Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).
Table Of Content
According to U.S. officials, Yaryab is responsible for overseeing the IRGC-CEC’s Cyber Operations Command. This command manages various cyber units implicated in malicious activities against critical infrastructure in the United States, Europe, and the Middle East.
This initiative underscores a broader strategy by the U.S. government to counter aggressive cyber operations that threaten American critical infrastructure, aligning with provisions under the Computer Fraud and Abuse Act.
Yaryab’s Alleged Role in IRGC Cyber Operations
Yaryab is reportedly at the helm of several IRGC-CEC components, specifically Shahid Hemmat and Shahid Shushtari. These units are known for executing cyber and cyber-enabled information campaigns against a diverse array of sectors, including defense, telecommunications, energy, and finance.
U.S. authorities have further connected Yaryab to various IRGC-affiliated cyber groups, such as CyberAv3ngers and Dadeh Afzar Arman (DAA). These groups have been implicated in deploying malware and launching assaults on civilian infrastructure globally.
This recent announcement intensifies the focus on Iran’s cyber command, particularly as operational technology (OT) systems continue to face significant internet-borne threats. The alert reinforces earlier warnings concerning CyberAv3ngers’ activities targeting industrial control systems (ICS).
Critical Infrastructure Under Attack: The Unitronics PLC Incidents
A collaborative advisory from CISA, the FBI, NSA, EPA, and international partners revealed that actors linked to the IRGC began compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) in late 2023. These devices are integral to the functioning of various critical sectors, including water treatment, energy, transportation, and healthcare.
Reports indicate that between November 2023 and January 2024, CyberAv3ngers launched multiple waves of attacks against Unitronics PLCs based in the U.S. At least 75 devices were compromised, with 34 of these located within the U.S. water and wastewater sector.
The attackers predominantly targeted internet-exposed devices that either utilized default passwords or lacked any password protection. The cyber offensive extended beyond mere defacement; it involved altering the ladder logic within the PLCs, which directly controls physical processes like pumps and valves. Such unauthorized modifications could severely disrupt essential services. Furthermore, attackers tampered with device names, software versions, and remote access credentials, complicating recovery efforts for affected organizations.
In several incidents, the perpetrators replaced human-machine interface (HMI) displays with messages claiming responsibility and issuing threats against Israeli-manufactured equipment. This interference can prevent plant operators from accessing vital operational data, posing a direct threat to system stability and safety.
The activities attributed to CyberAv3ngers underscore the substantial risks to critical infrastructure stemming from inadequate operational technology security. When PLCs are compromised, attackers gain the ability to manipulate crucial industrial processes, potentially leading to catastrophic outcomes.
What You Should Do
- Identify and isolate any OT devices, especially PLCs and HMIs, that are directly exposed to the public internet.
- Implement and enforce robust password policies for all OT systems, ensuring complex, unique passwords are used.
- Deploy multifactor authentication (MFA) for remote access to OT environments.
- For Unitronics Vision Series PLCs, CISA recommends updating engineering workstations and firmware to the latest available versions.
- Secure all remote access to OT systems through VPNs and properly configured firewalls.
- Maintain comprehensive and up-to-date asset inventories of all industrial control systems.
- Continuously monitor OT networks for unusual activity or unauthorized changes to configurations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.