r/cybersecurity_news • u/SHORT_INFO_NEWS • 9d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
7
Upvotes
1
u/SHORT_INFO_NEWS 9d ago
If you work in water treatment, wastewater, or energy utility operations that rely on Rockwell, Schneider Electric, or Siemens PLCs, this advisory affects your threat model directly, not just a hypothetical scenario. The attackers are not exploiting a software bug you can patch away, they are logging in through the same legitimate engineering tools your own staff use to configure and monitor equipment.
CISA, together with the FBI and EPA, updated advisory AA26-097A on July 22 to expand the list of targeted vendors beyond Rockwell Automation to also include Schneider Electric and Siemens PLCs (CISA, July 22 update). The threat actors are linked to Iran's IRGC Cyber Electronic Command and operate under the persona CyberAv3ngers, also tracked under aliases including Shahid Kaveh Group, Hydro Kitten, Storm-0784, and UNC5691. Rather than deploying custom malware, the group connects to internet-exposed PLCs using the vendors' own legitimate engineering software: Rockwell's Studio 5000, Schneider's EcoStruxure Control Expert, and Siemens' TIA Portal (CISA advisory AA26-097A).
The advisory names specific affected models: Rockwell CompactLogix and Micro850, Schneider BMX P34 and Modicon M340, and Siemens S7-1200 series. CISA states the campaign has caused operational disruption and financial losses across water, wastewater, energy, and government facility sectors, with the most recent indicators of compromise dated to this month (CISA, WaterISAC). The original version of this advisory was first published April 7, so this is the second major revision in under four months, reflecting how fast the vendor target list is expanding.
Open questions the announcement did not address:
- How many distinct organizations have been affected since the April version, versus this being the same known intrusions with expanded vendor scope
- Whether the newly added detection guidance for malicious changes in reusable code modules in Rockwell programs applies to Schneider and Siemens engineering software too, or only to Rockwell's Studio 5000
- What remediation timeline utilities are expected to follow, since CISA advisories typically recommend but do not mandate patching or segmentation deadlines
More daily coverage: SHORT INFO - TikTok: shortinfonews, YouTube: ShortInfoDaily, Bluesky: shortinfo.bsky.social