Full Report
Your PLCs aren't internet-connected, right? Right?! Iranian-affiliated actors have escalated intrusions targeting critical US water and energy facilities, in some cases disrupting operations, the FBI and American cyber defense agencies said on Tuesday.…
Analysis Summary
# Threat Actor: CyberAv3ngers (Affiliated with IRGC)
## Attribution & Identity
* **Actor Name:** CyberAv3ngers
* **Affiliation:** Islamic Revolutionary Guard Corps (IRGC), an Iranian government entity.
* **Identification:** Advanced Persistent Threat (APT) actors affiliated with the Iranian state.
* **Associated Groups:** Broadly categorized under Iranian-affiliated APT actors; linked historically to previous IRGC OT-targeting campaigns.
## Activity Summary
According to the joint advisory (FBI, CISA, NSA, EPA, DOE, and US Cyber Command) dated April 2026, Iranian-affiliated actors have escalated cyber intrusions since March 2026. These operations focus on disrupting U.S. critical infrastructure, specifically targeting Operational Technology (OT). The actors are moving "faster and broader," increasingly targeting both IT and OT environments simultaneously. Recent activities include the manipulation of project files and data displays to cause operational disruptions and financial loss.
## Tactics, Techniques & Procedures
* **Exploitation of Internet-Exposed Devices:** Identification and targeting of PLCs, HMIs, and SCADA displays directly connected to the public internet.
* **Credential Manipulation:** Use of default passwords and weak credentials to gain unauthorized access.
* **Remote Control & Manipulation:** malingering with project files and manipulating data shown on HMI and SCADA displays to deceive operators or disrupt processes.
* **Malware Deployment:** Utilization of custom malware designed to interact with OT-specific protocols and hardware.
* **Targeted Ports:** Monitoring and exploiting traffic on ports 44818, 2222, 102, and 502.
* **MITRE ATT&CK Mapping (Inferred):**
* T1190 – Exploit Public-Facing Application
* T1078 – Valid Accounts (Default Credentials)
* T0831 – Manipulation of Control Logic (ICS)
* T0815 – External Remote Services (ICS)
## Targeting
* **Sectors:** Water and Wastewater Systems (WWS), Energy (Oil Refineries, Power Grids), Food and Agriculture.
* **Geography:** Primarily the United States and Israel; secondary focus on utilities in the wider Middle East.
* **Victims:** Specifically facilities utilizing **Rockwell Automation / Allen-Bradley** manufactured Programmable Logic Controllers (PLCs).
## Tools & Infrastructure
* **Hardware Targeted:** Rockwell Automation/Allen-Bradley PLCs, Human-Machine Interfaces (HMIs), and Supervisory Control and Data Acquisition (SCADA) systems.
* **Malware:** Custom malware designed for remote control of fuel and water management systems.
* **Infrastructure:** Usage of overseas hosting providers to mask the origin of attack traffic.
* **Network Ports:** 44818 (EtherNet/IP), 2222 (EtherNet/IP), 102 (ISO-TSAP/S7comm), and 502 (Modbus).
## Implications
The transition from simple defacements or credential harvesting to the manipulation of industrial control logic represents a severe escalation. These actors are specifically aiming for "operational disruption," which in a critical infrastructure context can lead to environmental hazards, loss of service, and physical damage. The alignment of these cyber activities with geopolitical tensions suggests that Iranian cyber capabilities are being utilized as a tool of asymmetric warfare to pressure the U.S. and its allies during kinetic conflicts.
## Mitigations
* **Eliminate Internet Exposure:** Disconnect all PLCs and OT devices from the public-facing internet immediately.
* **Credential Security:** Change all default passwords on OT hardware and implement strong, unique credentials.
* **Access Control:** Enable Multi-Factor Authentication (MFA) for all access to IT and OT networks.
* **Network Monitoring:** Audit logs for suspicious traffic on ports 44818, 2222, 102, and 502, particularly from foreign VPS or hosting providers.
* **Patch Management:** Ensure all OT and IT systems are updated with the latest security patches.
* **Vendor Guidance:** Adhere to specific security hardening guides provided by Rockwell Automation.