CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure.
The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities.
Some victims suffered operational disruption and financial losses after attackers altered the systems that manage physical processes. The consequences can spread quickly.
The activity has been underway since at least March 2026 and relies on exposed or poorly secured operational technology. Attackers connect from leased foreign infrastructure using legitimate PLC programming software.
They download project files, change control logic, and manipulate information shown to operators on human machine interface and SCADA displays.
Analysts from CISA and the FBI identified malicious changes to project files, including reusable code modules inside Rockwell Automation programs.
The wider exposure is significant, with earlier research finding thousands of exposed Rockwell PLCs reachable online. The latest advisory also confirms observed targeting of Schneider Electric and Siemens equipment.
CISA said in a report shared with Cyber Security News (CSN) that the actors appear intent on causing disruptive effects inside the United States. The campaign has not been tied to a new product vulnerability.
Instead, it exploits unsafe internet exposure, weak access controls, and legitimate engineering functions.
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs
The intruders targeted Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 systems, and Siemens S7-1200 devices.
This activity reflects a broader pattern in which weak credentials and exposed PLCs give hostile operators a direct route into sensitive industrial environments without requiring a zero-day flaw.
At one U.S. victim, the attackers used configuration software to download a malicious project file to a PLC.
The file preserved enough ladder logic to keep downstream functions operating, but added instructions that overrode controls responsible for safe operating limits. On Rockwell devices, these project files commonly use the .ACD filename extension.
After extracting project files, the group modified or deleted control logic, including Add-On Instructions that package reusable functions. Investigators also found altered HMI and SCADA data.
These changes disabled shutdown and alarm logic, creating conditions in which equipment could move into unsafe states while operators received no warning.
The attackers used approved engineering tools from the affected manufacturers, hosted on rented third-party systems, to copy PLC project files.
They also used Dropbear SSH on victim modems for remote access. The methods echo earlier Iranian attacks on critical infrastructure involving the IRGC-linked CyberAv3ngers group and exposed industrial control equipment.
Defenders Urged to Remove Direct Internet Access
CISA urged operators to disconnect PLCs from the public internet and place secure gateways, firewalls, or VPNs in front of any required remote access.
Organizations should apply multifactor authentication, restrict communications to approved control-system devices, secure cellular modems, and regularly examine modem and network logs for unusual access.
For controllers with a physical mode switch, defenders should validate the running project file before placing the device in run mode.
This setting helps prevent remote modification, but it can also lock in a malicious file if checks are skipped. Siemens users should enable programming protection where software key switching is available.
Operators should compare active PLC programs with known-good logic, inspect reusable modules and input-output settings, and verify backups before restoration.
Logs from PLCs, modems, HMIs, and engineering workstations should be reviewed for lateral movement. If attackers reached connected systems, CISA advises reimaging affected devices to remove hidden changes or access tools.
Additional steps include replacing default passwords, applying current vendor patches, disabling unused services, and keeping offline backups of logic and configurations. Defenders should watch for unexpected protocol use or commands that change operating modes.
The risks documented around internet-connected industrial control devices show why continuous asset monitoring remains essential.
CISA also recommends checking historical logs against the indicators below before blocking them, because the addresses were linked to the actors only during specific periods.
Suspected victims should activate incident response plans, contact the relevant U.S. agencies and equipment manufacturer, and preserve evidence for investigation.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 185.82.73[.]175 |
Actor-associated from September 2025 to February 2026 |
| IP address | 141.11.164[.]153 |
Actor-associated from January 2026 to June 2026 |
| IP address | 175.110.121[.]42 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]39 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]41 |
Actor-associated from February 2026 to March 2026 |
| IP address | 175.110.121[.]107 |
Actor-associated during February 2026 |
| IP address | 192.142.54[.]79 |
Actor-associated from May 2026 to June 2026 |
| IP address | 84.200.205[.]165 |
Actor-associated from May 2026 to June 2026 |
| IP address | 185.225.17[.]225 |
Actor-associated from June 2026 to July 2026 |
| IP address | 79.133.46[.]209 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]199 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]200 |
Actor-associated during July 2026 |
| IP address | 88.80.150[.]202 |
Actor-associated during July 2026 |
| IP address | 185.82.73[.]162 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]164 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]165 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]167 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]168 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]170 |
Actor-associated from January 2025 to March 2026 |
| IP address | 185.82.73[.]171 |
Actor-associated from January 2025 to March 2026 |
| IP address | 135.136.1[.]133 |
Actor-associated during March 2026 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.
The post CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure appeared first on Cyber Security News.
Tushar Subhra Dutta
Go to cyber-security-news