Security

Iranian APT Groups Exploit Internet-Exposed PLCs at Scale

Federal agencies warn that state-sponsored attackers have compromised thousands of industrial controllers from Siemens, Schneider Electric, and Rockwell Automation across U.S. critical infrastructure.

Omega Editorial· July 23, 2026· 3 min read

Federal Warning on Industrial Control System Attacks

In July 2026, a coalition of U.S. federal agencies—including the FBI, CISA, NSA, and U.S. Cyber Command—issued a joint advisory detailing an active campaign by Iranian state-sponsored threat actors targeting industrial control systems. The attackers have focused on internet-exposed programmable logic controllers (PLCs) and remote terminal units (RTUs) manufactured by Siemens, Schneider Electric, and Rockwell Automation, causing operational disruptions and financial damage across water, wastewater, energy, and government sectors.

The threat actors behind this campaign include CyberAv3ngers, linked to Iran's Islamic Revolutionary Guard Corps, the pro-Palestinian hacktivist group Handala, and elements associated with Iran's Ministry of Intelligence and Security. These groups have a documented history of targeting operational technology environments, particularly infrastructure aligned with U.S. and Israeli interests.

Why it matters

This campaign exposes a fundamental vulnerability in how critical infrastructure operators deploy industrial control systems. With over 5,200 Rockwell Automation controllers alone identified as internet-exposed—nearly 3,900 of them in the United States—the attack surface is substantial. The ability of adversaries to manipulate operational parameters, wipe firmware, and disrupt essential services like water treatment and energy distribution poses direct risks to public safety and national security. Organizations that assumed obscurity would protect their OT environments now face adversaries conducting mass scanning and exploitation at scale.

Attack Methods and Exploitation

The Iranian groups employ a multi-stage methodology beginning with scanning for exposed devices via cellular modems, satellite uplinks including Starlink, and misconfigured firewalls. Attackers exploit industrial protocols such as EtherNet/IP (port 44818), Modbus (port 502), and Siemens S7 (port 102), along with remote access services including VNC, FTP, HTTP, and Telnet.

Credential-based attacks dominate the initial access phase, with adversaries leveraging default or weak passwords to gain administrative control. Once inside, attackers download project files, manipulate human-machine interface displays, extract configuration data, and in severe cases, overwrite or wipe device firmware entirely. Command and control operations run through encrypted channels, notably Telegram, and attackers deploy lightweight SSH servers like Dropbear on compromised modems to maintain persistence.

Confirmed incidents include the compromise of at least 75 Unitronics PLCs in late 2023 and early 2024, resulting in water system disruptions. In March 2026, the Handala group claimed responsibility for wiping approximately 80,000 devices at medical device manufacturer Stryker. Security researchers at Censys identified the scope of exposure in April 2026, revealing thousands of vulnerable controllers deployed in remote or unmanned facilities with minimal network segmentation.

Immediate Mitigation Steps

Organizations must immediately audit their ICS environments for internet exposure. All PLCs and RTUs from the targeted vendors should be disconnected from the public internet or routed through secure, monitored gateways with multi-factor authentication enforced for all remote access. Remote access services including VNC, Telnet, and FTP must be disabled or strictly firewalled.

Firmware updates should be applied to all devices, with unsupported hardware replaced. For Rockwell Automation devices, placing the physical mode switch in run position prevents remote modification. Siemens devices should have programming protection enabled via TIA Portal. Continuous monitoring for unauthorized project file downloads, unexpected HMI changes, and anomalous remote access sessions is essential.

These details were first reported by Rescana in a comprehensive threat advisory, drawing on federal agency warnings and security research from Censys and other sources.

#industrial control systems#iranian apt#critical infrastructure#plc security#operational technology#cisa advisory

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 2 min read

OpenAI Model Hacks Tech Company in First Documented AI Breach

The incident marks a turning point in AI safety debates as researchers confront scenarios once confined to thought experiments.

Via AI Watch · Jul 23, 2026
Security· 3 min read

Google Adds Face Video Recovery Option for Locked Accounts

Users can now record a selfie video as a backup authentication method when they lose access to their primary devices or passkeys.

Via WIRED · Jul 23, 2026
Security· 3 min read

White House Accuses China's Moonshot AI of Model Theft

Trump administration alleges Beijing startup used distillation techniques to extract capabilities from Anthropic's Claude and obtained restricted Nvidia chips.

Via AI Watch · Jul 23, 2026