Jul 23, 2026

Iranian-Affiliated PLC Exploitation: SafeBreach Coverage for CISA Advisory AA26-097A

Learn how SafeBreach maps CISA Advisory AA26-097A to simulations that test your exposure to Iranian-affiliated CyberAv3ngers’ PLC exploitation and OT data manipulation attacks.

Summary

CISA Advisory AA26-097A details an escalating Iranian-affiliated campaign (CyberAv3ngers/IRGC-CEC) exploiting Internet-exposed programmable logic controllers (PLCs) from Rockwell Automation, Schneider Electric, and Siemens across US water, energy, and government infrastructure. This post outlines the attackers’ TTPs—including remote access via Dropbear SSH, project file exfiltration, and HMI/SCADA data manipulation that disables shutdown and alarm logic—mapped to MITRE ATT&CK. It also covers new IOC-based content SafeBreach has added to validate that an organization’s controls detect and block communication with the campaign’s C2 infrastructure, along with mitigation guidance for securing OT environments.

Author: Stacey Nosan, Senior Director of Content & Communications

On April 7, 2026, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), US Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury issued Cybersecurity Advisory (CSA) AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

The advisory—significantly expanded in a July 22, 2026 update—provides critical intelligence on ongoing Iranian-affiliated targeting of Internet-connected operational technology (OT) devices, including the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) observed across multiple US critical infrastructure sectors.

The activity has disrupted programmable logic controllers (PLCs) across water and wastewater systems, energy, and government facilities by maliciously interacting with PLC project files and manipulating data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays—in some cases disabling critical shutdown and alarm logic and producing both operational disruption and financial loss.

Understanding the Threat

The campaign is attributed to Iranian-affiliated APT actors linked to Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC), operating under the CyberAv3ngers persona. Across the security industry these actors are also tracked as Shahid Kaveh Group, Hydro Kitten, Storm-0784, BAUXITE, and UNC5691. The authoring agencies assess the activity is consistent with anticipated retaliatory cyber operations tied to heightened US–Iran tensions.

This campaign is the direct successor to the November 2023 CyberAv3ngers operation (AA23-335A), which compromised Unitronics PLCs across US water and wastewater facilities using default credentials. AA26-097A represents a meaningful escalation in both capability and scope:

  • Vendor expansion. The 2023 activity targeted a single vendor. The current campaign has been confirmed against Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers, and the July 2026 update expands the confirmed scope to Schneider Electric (BMX P34 / Modicon M340) and Siemens (S7-1200 series) PLCs, with port targeting suggesting still-broader, opportunistic interest across OT vendors.
  • Technique sophistication. Rather than relying solely on default credentials, the actors use the same legitimate configuration software OT engineers use for daily operations—Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal—to connect to misconfigured, Internet-exposed PLCs. In at least one instance, they deployed Dropbear SSH on victim modems for persistent remote access.
  • Confirmed operational impact. The FBI and CISA confirmed modification and deletion of project file logic—including Add-On Instructions (AOIs)—alongside HMI/SCADA display manipulation that masks adversarial changes from operators.

The underlying weakness being exploited is not a single patchable software vulnerability. It is an architectural one: PLCs deployed to the public Internet without adequate network segmentation, authentication gating, or hardening controls.

Key Tactics, Techniques, and Procedures (TTPs)

The advisory maps the activity to the MITRE ATT&CK Matrix—Enterprise and ICS version 19.

Initial Access

  • Internet Accessible Device (T0883). The actors accessed and interacted with publicly exposed, Internet-accessible PLCs that lacked sufficient network and/or hardening controls, using foreign-based IP addresses and leased, third-party hosting infrastructure. Inbound malicious traffic has been observed on ports 44818 (EtherNet/IP), 2222, 102 (ISO-TSAP / Siemens S7), and 502 (Modbus TCP), as well as targeting modems on port 22.

Command & Control

  • Commonly Used Port (T0885). The actors leveraged commonly used OT ports to communicate with PLCs. The multi-vendor port targeting indicates opportunistic interest beyond any single manufacturer.
  • Remote Access Tools (T1219). The actors deployed Dropbear SSH software on victim modems to establish persistent remote access via port 22.

Exfiltration

  • Exfiltration Over C2 Channel (T1041). (Added in the July 22, 2026 update.) The actors used PLC configuration software on leased, third-party hosted infrastructure to exfiltrate device project files from victim environments to actor-controlled infrastructure.

Impact

  • Data Manipulation (T1565). After extracting device project files, the actors modified and deleted project file logic (including AOIs) and manipulated data shown on HMI and SCADA displays. In observed cases, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without alerting operators.

Indicators of Compromise (IOCs)

The advisory provides extensive IOCs, including:

  • Foreign-based IP addresses (see Tables 1 and 2 in the advisory) used to communicate with Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs, each with an associated actor-use time frame.
  • Leased, third-party hosting infrastructure used for connection and exfiltration.
  • Suspicious traffic on OT-associated ports—44818, 2222, 102, 502, and 22 (modems).

Because the threat actors used these addresses within specific historical windows, CISA recommends organizations investigate and vet the listed IP addresses before taking action such as blocking, and query logs for historical targeting. For the authoritative, current list, refer to the full CISA advisory and the associated STIX indicator files on the CISA website.

SafeBreach Coverage & Playbook Attack Updates

Existing Related Coverage

SafeBreach customers already have access to content that simulates network connections to the threat-group servers associated with this campaign.

These simulations are mapped to MITRE ATT&CK and can be used immediately to validate detection and response capabilities across your infrastructure.

New IOC-Based Coverage

To address the newly released IOC guidance in AA26-097A, we have added two network-reachability simulations that validate whether egress controls detect and block communication with the advisory’s C2 indicators:

  • 11750 – Communication with APT (US-CERT AA26-097A) using HTTP. Sends an outbound HTTP request to a SafeBreach-controlled server with an advisory-listed C2 IP address set in the Host header.
  • 11751 – ICMP Ping Request to APT (US-CERT AA26-097A) C2 Servers. Sends a real ICMP echo request to IP addresses associated with the threat actor. This is an Advanced Action (it contacts real external infrastructure) and should be scheduled accordingly.

These simulations validate detection and blocking of the campaign’s C2 indicators; they do not emulate the PLC exploitation, remote-access-tool deployment, project-file exfiltration, or HMI/SCADA manipulation described above.

What You Should Do Now

Existing SafeBreach customers can now validate their security controls against the advisory’s C2 indicators in multiple ways.

Method 1 — SafeBreach Scenarios: Navigate to the SafeBreach Scenarios page and choose CISA Alert AA26-097A.

Method 2 — Attack Playbook: Open the Attack Playbook and filter by AA26-097A to view all associated attacks. You can also refer to the list above to confirm which AA26-097A attacks are available.

Method 3 — Known Attack Series Report: Select the AA26-097A report from the Known Attack Series report and click Run Simulations.

Additional Advisory Steps

Run the SafeBreach Platform Simulations

  1. Log into the SafeBreach platform and navigate to the updated playbooks mapped to AA26-097A.
  2. Execute the AA26-097A simulations to test whether your controls detect and block outbound communication with the campaign’s C2 infrastructure over HTTP and ICMP.
  3. Use simulation IDs 11750 and 11751 to test your IOC-based detection and blocking coverage.
  4. Review results to validate detection, surface gaps, and guide remediation.

Implement Mitigation Strategies (from the CISA advisory)

  1. Remove PLCs from direct Internet exposure. Route all remote access through a secure gateway or jump host that mediates, monitors, and controls the connection (CISA CPG 3.S).
  2. Strictly control network access to PLC devices using firewall rules or ACLs that permit only authorized control-system communications, and block unauthorized or hosting-provider IP addresses.
  3. Set physical mode switches to RUN where available (and validate project files before switching), and enable programming protection for software key switches (e.g., in the Siemens S7 TIA Portal).
  4. Enforce multifactor authentication (MFA) for external access to the OT network (CPG 3.F), using a VPN or gateway to enforce MFA even where the PLC itself does not support it.
  5. Create, test, and store offline backups of PLC logic and configurations, and verify backups are free of malicious logic before restoring.
  6. Secure cellular modems with strong authentication and logging, and consider isolated architectures such as private APN, 5G PNI-NPN, cellular SD-WAN, or ZTNA.

Refer also to the vendor hardening guidance called out in the advisory: Rockwell Automation Security Advisory SD1771, Schneider Electric’s Modicon controller guidance, and Siemens Security Bulletin 104599.=

Employ Proactive Threat Monitoring

  • Query logs for suspicious traffic on OT ports 44818, 2222, 102, 502, and 22, especially connections from foreign hosting providers outside your authorized engineering-workstation list.
  • Review PLC project files and Add-On Instructions (AOIs) for unauthorized modifications using vendor integrity-checking tools; visually compare running logic against known-good baselines.
  • Hunt for Dropbear SSH or any unrecognized SSH service on OT endpoints and modems.
  • Watch for HMI/SCADA display values that diverge from ground-truth process readings—a signal of display manipulation masking underlying changes.
  • Review logs and configurations on connected modems, HMIs, and engineering workstations for signs of lateral movement, and reimage any device the actors may have reached.

Stay Ahead with SafeBreach

To test your defenses against this campaign’s C2 indicators, sign into SafeBreach and run the latest simulations mapped to AA26-097A. To assess your broader exposure, you can go a step further with SafeBreach Propagate.

Propagate enables you to assess how attackers could pivot across your environment post-compromise—mapping high-risk attack paths, visualizing lateral movement across network zones, and prioritizing remediation based on exposure to your most critical assets. Find out more in the SafeBreach Propagate solution brief.

Frequently Asked Questions

What is CISA Advisory AA26-097A?

AA26-097A is a joint cybersecurity advisory issued by the FBI, CISA, NSA, EPA, DOE, US Cyber Command, and the Treasury Department on April 7, 2026 (and significantly expanded on July 22, 2026). It details an Iranian-affiliated campaign exploiting Internet-exposed programmable logic controllers (PLCs) across U.S. water, energy, and government infrastructure.

The campaign initially targeted Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers. The July 2026 update expanded confirmed targeting to Schneider Electric (BMX P34/Modicon M340) and Siemens (S7-1200 series), with port-scanning activity suggesting broader, opportunistic interest across other OT vendors.

The activity is attributed to Iranian-affiliated actors linked to IRGC-CEC, operating under the CyberAv3ngers persona (also tracked as Shahid Kaveh Group, Hydro Kitten, Storm-0784, BAUXITE, and UNC5691). They use legitimate PLC configuration software to access misconfigured, Internet-exposed controllers, then exfiltrate project files and manipulate HMI/SCADA displays—in some cases disabling shutdown and alarm logic without alerting operators.

SafeBreach customers can validate their defenses through the SafeBreach Scenarios page (filtered by AA26-097A), the Attack Playbook, or the Known Attack Series report, all of which provide IOC-based content to validate that their controls detect and block communication with the campaign’s C2 infrastructure.

Get the latest
research and news