Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstate-sponsored-disruptionindustrial-control-system-vulnerabilityinternet-exposed-service

Iranian-Linked Actors Exploit Internet-Facing Rockwell PLCs in US Critical Infrastructure

Updated 2mo agoFirst seen Mar 21, 202631 sources

A joint U.S. government advisory said Iranian-affiliated cyber actors are actively exploiting internet-facing operational technology devices across multiple U.S. critical infrastructure sectors, with a particular focus on Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). The activity has affected organizations in Government Services and Facilities, Water and Wastewater Systems, and Energy, where attackers maliciously interacted with project files and manipulated data displayed on HMI and SCADA systems, causing operational disruption and financial losses for some victims.

The campaign has been observed since at least March 2026 and shows similarities to prior CyberAv3ngers activity linked to the IRGC Cyber Electronic Command. According to the advisory, the actors used overseas IP infrastructure, Rockwell Studio 5000 Logix Designer, OT-related ports including 44818, 2222, 102, 22, and 502, and Dropbear SSH for remote access. U.S. authorities urged operators to remove PLCs from direct internet exposure, harden remote access, enable logging, place controllers in run mode where appropriate, and review published indicators of compromise and ATT&CK-mapped TTPs alongside Rockwell Automation security guidance.

Share:
Iranian-Linked Actors Exploit Internet-Facing Rockwell PLCs in US Critical Infrastructure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Apr 7, 20263mo ago

US government issues joint advisory on Iranian PLC exploitation campaign

On April 7, 2026, CISA and partner agencies warned that Iranian-affiliated actors were actively exploiting internet-facing PLCs, disrupting operations by manipulating project files and altering data shown on HMI and SCADA displays. The advisory also shared technical details, observed ports and tooling, indicators of compromise, and mitigation guidance for defenders.

Mar 20, 20263mo ago

Rockwell Automation publishes security advisory SD1771

Rockwell Automation published security advisory SD1771 addressing the PLC-focused threat activity referenced in later government reporting. The advisory was released on March 20, 2026.

Mar 1, 20264mo ago

Iranian-affiliated actors begin exploiting internet-facing PLCs in the US

Since at least March 2026, Iranian-affiliated cyber actors have targeted internet-exposed operational technology devices across multiple U.S. critical infrastructure sectors, especially Rockwell Automation/Allen-Bradley PLCs. The activity affected sectors including Government Services and Facilities, Water and Wastewater Systems, and Energy.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

118 LINKEDOpen in app
Affected products
18 linked
CompactlogixStudio 5000 Logix DesignerMicro850Totally Integrated Automation PortalMicro820Micrologix 1400TelegramWindowsControllogixRemote Desktop ProtocolTeamviewerAnydeskFactorytalk LinxCodemeterGmailMicro870Logix 5000 ControllersFactorytalk Security
Organizations
67 linked
Rockwell AutomationUnitronicsPolySwarmSiemensStrykerCensysFlashpointDragosGoogleCheck Point Software TechnologiesVerizon CommunicationseSentireAnthropicRecorded FutureMicrosoft CorporationRed LionTeltonikaKeeper SecurityPhoenix ContactEdisonWibu-SystemsOrpakThe RegisterBeyondtrustAmazon Web ServicesComparitechHikvisionColorTokensSchneider ElectricTenableStarlinkAT&TDomainToolsThe TimesNetflixT-Mobile USComcastClarotyDark ReadingSouthern CompanyCharter CommunicationsD-LinkDarktraceVerizon BusinessAppleBroadcomPinterestAnyDesk Software GmbHOracleTeamviewerPicus LabsExabeamEdison Electric InstituteUltahostSpaceXRed Lion ControlsSecurity AffairsJUMPSECThe Hacker NewsAvnet Data SecurityHavana ClubNCR VoyixAT&T MobilityM247 Europe SRLOmniTrustCalpine Corp.Los Angeles Metro
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.