CISA Alert AA26-097A: Iranian-Affiliated Actors Target PLCs Across US Critical Infrastructure: Analysis, Simulation, and Mitigation
LAST UPDATED ON APRIL 08, 2026
On April 7, 2026, the FBI, CISA, NSA, EPA, Department of Energy, and US Cyber Command jointly warned [1] that Iranian-affiliated APT actors are actively exploiting internet-facing programmable logic controllers (PLCs), primarily Rockwell Automation/Allen-Bradley devices, across U.S. Government Services, Water and Wastewater Systems (WWS), and Energy sectors. The campaign has caused operational disruptions by tampering with PLC project files, manipulating HMI and SCADA displays, and in some cases producing financial losses for victim organizations.
This is not a hypothetical warning. The authoring agencies confirmed active compromises since at least March 2026, identified through direct engagements with victims, and assess the activity is motivated by geopolitical retaliation linked to US-Iran hostilities.
In this blog, we analyze the TTPs behind this campaign, explain why it represents a significant escalation from prior Iranian OT operations, and provide actionable guidance on how organizations can validate their defenses.
For a comprehensive overview of all Iranian APT groups, their toolsets, and detection opportunities, see: Iranian Threat Actors: What Defenders Need to Know.
>> Simulate Emerging Threats with a 14-Day Free Trial of the Picus Platform
Why This Advisory Matters: From Unitronics to Rockwell, An Escalation in Capability and Scope
This campaign is the direct successor to the CyberAv3ngers operation of November 2023 (also tracked as the Shahid Kaveh Group, Hydro Kitten, Storm-0784, and UNC5691), which compromised at least 75 Unitronics PLC devices using default credentials across U.S. water and wastewater facilities [2]. The escalation is significant in three ways.
Vendor expansion. The 2023 campaign targeted a single vendor (Unitronics) with default passwords. The current campaign targets Rockwell Automation CompactLogix and Micro850 controllers using legitimate engineering software (Studio 5000 Logix Designer), and port targeting suggests Siemens S7 (port 102) and Modbus-compatible devices (port 502) are also in scope.
Technique sophistication. Instead of exploiting default credentials, the actors are now using the same configuration software that OT engineers use for legitimate operations, creating accepted connections to exposed PLCs. This approach is harder to distinguish from authorized administrative activity. They also deployed Dropbear SSH on victim endpoints for persistent remote access, indicating intent to maintain long-term footholds rather than conduct one-off disruptions.
Confirmed operational impact. While the 2023 Unitronics campaign caused limited real-world disruption, this advisory confirms that victims have experienced operational disruption and financial loss from PLC manipulation. The observed activity includes extraction of .ACD project files (containing ladder logic and configuration settings) and falsification of HMI/SCADA display values.
This trajectory is consistent with what Dragos reported in its 2026 OT/ICS Cybersecurity Year in Review [4]: adversaries are moving beyond pre-positioning to actively mapping control loops and understanding how to manipulate physical processes. Dragos tracks BAUXITE, a threat group with technical overlaps with CyberAv3ngers, as a Stage 2 ICS Cyber Kill Chain adversary capable of compromising PLCs and deploying custom backdoors on OT devices. The newly identified PYROXENE group, an Iranian IRGC-backed group that targets OT and ICS environments, further illustrates how Iran's OT-targeting ecosystem is diversifying and maturing.
Meanwhile, CVE-2021-22681, related to an insufficiently protected cryptographic key in Rockwell's Studio 5000 Logix Designer and multiple Logix PLCs, was added to CISA's Known Exploited Vulnerabilities catalog in March 2026 [5], confirming that Rockwell controllers are under active exploitation by threat actors. The advisory specifically references this vulnerability and Rockwell's guidance (PN1550) as relevant to the current campaign.
Technical Analysis
Initial Access: T0883, Internet Accessible Device
The actors scanned for and connected to internet-exposed Rockwell Automation PLCs using overseas-based IP addresses and leased third-party hosting infrastructure. Their access method was straightforward: they used Rockwell's own Studio 5000 Logix Designer to establish legitimate protocol connections to exposed CompactLogix and Micro850 controllers.
The fundamental weakness being exploited is not a software vulnerability. It is an architectural one. These PLCs were deployed without sufficient network segmentation, authentication gating, or hardening controls. As the CloudSEK Iran-US conflict threat assessment noted [6], tens of thousands of ICS devices are directly internet-reachable, many with default or no credentials. The three highest-impact defensive actions require no budget at all: take ICS interfaces off the internet, change default passwords, and block industrial protocol ports at the perimeter.
Command and Control: T0885 / T1219
Malicious traffic was directed to devices across five ports: 44818 (EtherNet/IP, used by Rockwell Automation), 2222 (OT configuration), 102 (ISO-TSAP, associated with Siemens S7), 22 (SSH), and 502 (Modbus TCP). The multi-vendor port targeting strongly suggests the actors are not limiting their operations to Rockwell devices alone.
The actors also deployed Dropbear SSH, a lightweight open-source SSH implementation commonly used in embedded Linux environments, on victim endpoints via port 22. This provides persistent remote access that can survive PLC reboots and is well-suited for resource-constrained OT endpoints.
Impact: T1565, Stored Data Manipulation
Two categories of impact were confirmed. First, project file extraction: the .ACD files containing ladder logic, control sequences, and configuration parameters were exfiltrated, giving the actors a detailed blueprint of the target's industrial processes. Second, HMI/SCADA display manipulation: displayed values were falsified, which can mislead operators, mask ongoing attacks, or undermine confidence in monitoring systems.
This combination of intelligence collection and operational disruption mirrors the broader Iranian APT pattern. As we documented in our Iranian Threat Actors analysis [3], groups like Agrius routinely conduct data theft before deploying destructive payloads, maximizing both intelligence value and disruptive impact. Project files extracted today could fuel more destructive follow-on operations tomorrow.
Actionable Mitigations
Do Now (Immediate)
1. Remove PLCs from direct internet exposure. This is the single highest-impact action. Route all remote access through a secure gateway or jump host with MFA. Ensure cellular modems used for field connectivity have strong authentication and logging enabled.
2. Set physical mode switches to RUN. For controllers with a hardware key switch, this prevents remote modification of PLC logic. Only switch to PROGRAM or REMOTE during active maintenance windows.
3. Enable programming protection for software key switches. For Siemens PLCs, configure protection in TIA Portal. For Rockwell devices, follow the SD1771 guidance issued in 2026.
4. Back up all PLC logic and configurations offline. Store on secured physical media. Test restore procedures regularly.
5. Check logs for IOC activity on OT ports. Query firewall, IDS, and network monitoring logs for traffic to or from the listed IOCs, particularly on ports 44818, 2222, 102, 22, and 502 originating from overseas hosting providers.
Do Next (Hardening)
6. Enforce MFA on all OT network remote access. Even if PLCs do not support MFA natively, gateways and VPNs in front of them can enforce it. This is consistent with the top defensive recommendation across all Iranian APT groups; phishing-resistant MFA is the single most impactful control.
7. Block unnecessary OT ports at the perimeter. Block 44818, 2222, 102, 502, and 22 where these protocols are not operationally required for the specific segment.
8. Disable unused services. Remove Telnet, FTP, RDP, VNC, web interfaces, and default authentication keys from all OT devices.
9. Monitor for configuration changes. Use asset management and OT monitoring tools to baseline PLC configurations and alert on unexpected parameter changes or logic modifications.
10. Validate your controls continuously. The advisory itself recommends testing against the MITRE ATT&CK techniques identified in this campaign. But point-in-time assessments do not reflect the dynamic nature of threats targeting IT/OT systems; new vulnerabilities emerge constantly in unmanaged or unpatched assets, and adversaries adapt quickly. Organizations with hybrid IT/OT environments should continuously validate that segmentation controls, firewalls, ACLs, and detection pipelines actually prevent lateral movement between IT and OT zones, rather than relying on static checklists or annual pen tests.
How Picus Helps Simulate Iranian-Affiliated OT/ICS Campaigns
Advisories like AA26-097A highlight a persistent reality for organizations running hybrid IT/OT environments: the threat landscape moves faster than static assessments can capture. Attackers are actively mapping control loops, probing segmentation boundaries, and testing which OT devices are reachable from the internet. Defenders need to do the same, but safely.
The Picus Security Validation Platform enables organizations to simulate end-to-end attack campaigns across IT/OT boundaries, from initial access through lateral movement to industrial segments, without risking operational uptime. This includes validating ransomware resilience across IT/OT, assessing whether network segmentation between enterprise and control layers is enforced effectively, and confirming that SIEM, IDS, and endpoint tools detect real adversarial behaviors specific to OT environments. For a detailed overview of Picus capabilities for industrial and critical infrastructure environments, see: Validate Security Across IT/OT Environments.
You can validate your defenses against CyberAv3ngers, APT33, APT34, APT35, MuddyWater, Fox Kitten, and the full spectrum of Iranian threat actors within minutes by starting a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for CyberAv3ngers and related Iranian APT campaigns:
|
Threat ID |
Threat Name |
Attack Module |
|
34425 |
CyberAv3ngers Threat Group Campaign Malware Download Threat |
Network Infiltration |
|
97455 |
CyberAv3ngers Threat Group Campaign Malware Email Threat |
Email Infiltration (Phishing) |
|
65765 |
APT33 Threat Group Campaign |
Windows Endpoint |
|
91557 |
APT33 Threat Group Campaign Malware Download Threat |
Network Infiltration |
|
45755 |
OilRig Threat Group Campaign |
Windows Endpoint |
|
81502 |
APT35 Threat Group Campaign |
Windows Endpoint |
|
81428 |
MuddyWater Threat Group Campaign |
Windows Endpoint |
|
56839 |
Fox Kitten Threat Group Attack Campaign |
Windows Endpoint |
|
36690 |
HomeLand Justice Threat Group Campaign |
Windows Endpoint |
|
78689 |
Agrius Threat Group Campaign |
Windows Endpoint |
For the full list of 80+ Iranian APT simulations available in the Picus Threat Library, see: Iranian Threat Actors: What Defenders Need to Know.
Picus Mitigation Library also provides actionable prevention signatures for CyberAv3ngers and related Iranian APT attack campaigns across supported security controls.
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Security Validation Platform.
References
[1] "Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure," CISA, April 7, 2026. Available: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
[2] "IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities," CISA, December 2023. Available: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
[3] "Iranian Threat Actors: What Defenders Need to Know," Picus Security. Available: https://www.picussecurity.com/resource/iranian-threat-actors-what-defenders-need-to-know
[4] "Dragos 2026 OT/ICS Cybersecurity Year in Review," Dragos, February 2026. Available: https://www.dragos.com/ot-cybersecurity-year-in-review
[5] "Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks," SecurityWeek, March 2026. Available: https://www.securityweek.com/rockwell-vulnerability-allowing-remote-ics-hacking-exploited-in-attacks/
[6] "A Threat Actor Landscape Assessment of ICS/OT Targeting in the 2026 Iran-US Conflict," CloudSEK, March 2026. Available: https://www.cloudsek.com/blog/a-threat-actor-landscape-assessment-of-ics-ot-targeting-in-the-2026-iran-us-conflict-and-the-scale-of-the-risk
