Iranian Hackers Modify PLC Logic in US Infrastructure Attacks
Covert Sabotage of Critical Infrastructure
Iranian threat actors have developed sophisticated techniques to covertly manipulate programmable logic controllers (PLCs), ensuring that human operators remain completely oblivious to hazardous system alterations. Within the United States, these malicious incursions have already precipitated operational failures across critical infrastructure sectors, resulting in quantifiable financial damages.
A coalition of US agencies including the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA) issued a joint advisory warning of an ongoing, coordinated campaign targeting industrial control systems (ICS). The primary targets include internet-exposed PLCs manufactured by industry leaders such as Rockwell Automation, Schneider Electric, and Siemens.
The relentless attacks have severely impacted government facilities, energy sector enterprises, and municipal water and wastewater treatment plants. US intelligence agencies confidently attribute this campaign to state-sponsored Iranian cyber collectives. Historically, similar disruptive operations were linked to CyberAv3ngers, a group also recognized under the moniker Shahid Kaveh Group.
Exploiting Legitimate Engineering Tools
The threat actors established unauthorized connections to poorly secured PLCs by routing their traffic through leased proxy servers located outside the United States. To manipulate the compromised devices, the hackers weaponized the manufacturers’ legitimate engineering software suites, specifically utilizing Studio 5000 Logix Designer, EcoStruxure Control Expert, and TIA Portal. Employing this “Living off the Land” approach, they successfully downloaded existing project files, fundamentally altered the underlying control logic, and seamlessly uploaded the modified configurations back into the operational controllers.
In one documented incident at a critical facility, the hackers preserved the PLC’s core operational logic but strategically injected rogue commands designed to override vital safety parameters. These malicious modifications possessed the capability to disable emergency shutdown protocols and suppress critical alarm thresholds. Consequently, the physical machinery was driven into a hazardous state while the human operator received no corresponding warning signals.
Deceiving the Operator and Causing Financial Harm
Furthermore, the hackers actively manipulated the data feeds transmitted to human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The graphical displays on the operator’s screen deceptively indicated that the equipment was functioning nominally, even as the PLC executed destructive commands in the background. In several confirmed instances, this covert interference directly caused physical equipment failures and significant financial losses.
US agencies recorded malicious inbound connections targeting specific ports associated with industrial protocols, notably ports 44818, 2222, 102, and 502. Additionally, specific attacks targeted cellular modems accessible via port 22. The compromised hardware models included Allen-Bradley CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 controllers.
Mitigation Strategies and Urgent Recommendations
Cybersecurity authorities urgently advise organizations to immediately sever all direct internet access to industrial controllers. Remote connectivity must be routed exclusively through secure gateways, with all allowable connections strictly governed by robust firewalls. Furthermore, equipment owners are strongly urged to audit their control logic programs for unauthorized modifications, meticulously review connection logs, change all default passwords, and maintain verified offline backups completely isolated from the production network.
The updated joint advisory expanded the list of affected vendors and provided specific methodologies for detecting malicious alterations hidden within reusable software modules. The agencies explicitly emphasize that this campaign does not rely on novel, unpatched zero-day vulnerabilities. Instead, the hackers opportunistically scan for controllers with inherently dangerous network configurations and subsequently weaponize the standard management tools against the equipment owners.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.