Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure

Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices in US Critical Infrastructure

Executive Summary

In July 2026, US federal agencies including the FBI, CISA, NSA, EPA, DOE, and US Cyber Command issued a joint advisory warning of a coordinated campaign by Iranian state-sponsored threat actors targeting internet-exposed industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation. These attacks have resulted in operational disruptions and financial losses across critical infrastructure sectors, notably water, wastewater, energy, and government facilities. The threat actors are leveraging a combination of default credentials, insecure remote access protocols, and unpatched firmware to gain unauthorized access, manipulate device configurations, and disrupt operations. This report provides a comprehensive technical analysis of the threat, the tactics, techniques, and procedures (TTPs) employed, observed exploitation in the wild, victimology, and actionable mitigation strategies.

Threat Actor Profile

The primary threat actors identified in this campaign are Iranian-affiliated advanced persistent threat (APT) groups, including CyberAv3ngers (linked to the Islamic Revolutionary Guard Corps, IRGC), pro-Palestinian hacktivist group Handala, and actors associated with the Iranian Ministry of Intelligence and Security (MOIS). These groups have a documented history of targeting operational technology (OT) and ICS environments, particularly those supporting US and Israeli-aligned critical infrastructure. Their motivations are both strategic and retaliatory, aiming to disrupt essential services, erode public trust, and demonstrate cyber capabilities in response to geopolitical tensions. The groups are known for leveraging open-source intelligence, mass scanning, and exploitation of weakly secured devices, often using Telegram and other encrypted channels for command and control and malware distribution.

Technical Analysis of Malware/TTPs

The Iranian APT groups employ a multi-stage attack methodology. Initial access is typically achieved by scanning for internet-exposed PLCs and RTUs from Siemens, Schneider Electric, and Rockwell Automation. Devices are often exposed via cellular modems, satellite uplinks (including Starlink), or misconfigured firewalls. Attackers exploit industrial protocols such as EtherNet/IP (port 44818), Modbus (port 502), and Siemens S7 (port 102), as well as remote access services including VNC (port 5900), FTP (port 21), HTTP (port 80/443), and Telnet (port 23).

Credential-based attacks are prevalent, with adversaries leveraging default or weak passwords to authenticate and gain administrative access. Once inside, attackers interact directly with project files, manipulate HMI and SCADA displays, extract sensitive configuration data, and in some cases, overwrite or wipe device firmware. Persistence is maintained through the creation of unauthorized remote access accounts, modification of device configurations, and exploitation of unpatched vulnerabilities.

Command and control is facilitated via encrypted channels, notably Telegram, and in some cases, lightweight SSH servers such as Dropbear are deployed on compromised modems. The attackers have demonstrated the ability to disable security tools, erase logs, and exfiltrate sensitive data. MITRE ATT&CK for ICS mapping includes techniques such as T1190 (Exploit Public-Facing Application), T1078 (Valid Accounts), T1040 (Network Sniffing), T1021.001 (Remote Services: VNC), and T1562.001 (Impair Defenses).

Exploitation in the Wild

Multiple high-profile incidents have been confirmed. In late 2023 and early 2024, at least 75 Unitronics PLCs were compromised, resulting in water system disruptions. In March 2026, the Handala group claimed responsibility for wiping approximately 80,000 devices at US medical giant Stryker. As of April 2026, security researchers at Censys identified over 5,200 internet-exposed Rockwell Automation controllers vulnerable to exploitation, with more than 3,900 located in the United States. Devices are frequently deployed in remote or unmanned infrastructure such as pump stations, substations, and municipal facilities, often with minimal network segmentation and exposed via insecure protocols.

Attackers have been observed downloading project files, modifying operational parameters, and causing unauthorized shutdowns or process changes. In several cases, adversaries have manipulated HMI/SCADA displays to display threatening messages or disrupt operator visibility. The attack surface is exacerbated by the widespread use of default credentials, lack of firmware updates, and insufficient monitoring of remote access sessions.

Victimology and Targeting

The primary targets are organizations operating in the water and wastewater, energy, and government sectors within the United States. However, the campaign has potential implications for allied nations, including Israel and other US partners. Devices from Siemens (notably S7-1200 series), Schneider Electric (BMX P34/Modicon M340), and Rockwell Automation (CompactLogix and Micro850 PLCs) are specifically at risk if exposed to the public internet. The attackers prioritize targets with minimal security controls, such as those lacking network segmentation, using default credentials, or exposing remote access services without multi-factor authentication. The impact ranges from temporary operational disruptions to the potential for physical damage and public safety risks.

Mitigation and Countermeasures

Organizations must immediately assess their ICS environments for exposure and implement robust security controls. All PLCs and RTUs from Siemens, Schneider Electric, and Rockwell Automation should be disconnected from the public internet or routed through secure, monitored gateways. Remote access services such as VNC, Telnet, and FTP must be disabled or firewalled, and multi-factor authentication should be enforced for all remote connections to OT networks. Firmware should be updated to the latest supported versions, and devices with limited update support should be replaced.

Continuous logging and monitoring of inbound traffic from suspicious ports and IP addresses, as identified in CISA advisories, is essential. Organizations should scan for indicators of compromise, including unauthorized project file downloads, unexpected HMI/SCADA changes, and anomalous remote access sessions. For Rockwell Automation devices, placing the physical mode switch into run position can prevent remote modification. For Siemens devices, programming protection should be enabled via TIA Portal. All project files should be reviewed for unauthorized changes, and validated backups should be maintained and tested before restoration.

Security teams are strongly encouraged to consult the latest advisories from CISA, FBI, and relevant vendors for updated IOCs, threat actor infrastructure, and technical guidance. Proactive threat hunting and regular vulnerability assessments are critical to reducing the attack surface.

References

BleepingComputer: US warns of Iranian hackers targeting critical infrastructure (April 2026): https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/

Cybersecurity Dive: Nearly 4K industrial control devices vulnerable to Iran-linked hacking campaign (April 2026): https://www.cybersecuritydive.com/news/critical-infrastucture-plcs-iran-hacking-censys/817209/

CISA Advisory AA26-097A (July 2026): https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

Censys Research on exposed PLCs (April 2026): https://www.censys.io/blog/ics-exposure-2026

MITRE ATT&CK for ICS: https://attack.mitre.org/matrices/ics/

NVD Vulnerability Database: https://nvd.nist.gov

Rockwell Automation Security Advisory SD1771: https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1133601

Schneider Electric Cybersecurity User Guide for Modicon Controller Platform: https://www.se.com/ww/en/download/document/EIO0000001996/

Siemens Security Bulletin 104599: https://cert-portal.siemens.com/productcert/html/ssb-104599.html

About Rescana

Rescana is a leader in third-party risk management, providing a comprehensive platform that empowers organizations to identify, assess, and mitigate cyber risks across their extended supply chain and operational technology environments. Our advanced threat intelligence and continuous monitoring capabilities enable proactive defense against emerging threats. For more information or to discuss how Rescana can support your cybersecurity strategy, please contact us at info@rescana.com.