Iran-linked crews are probing more flavors of US industrial kit

← Back to the feed

Iran-linked crews are probing more flavors of US industrial kit

The Register · 2 hours ago

The US Cybersecurity and Infrastructure Security Agency (CISA) has widened its warning about Iran-linked hackers attacking American critical infrastructure, extending the alert beyond Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) to include devices made by Schneider Electric, Siemens and potentially other manufacturers. The update matters because it shows the campaign, which has been running since March amid ongoing US-Iran tensions, is broader and more opportunistic than first thought, putting more water and energy facilities at risk of disruption.

CISA said attackers are targeting internet-facing PLCs opportunistically through open ports linked to various operational technology vendors' protocols, in activity resembling earlier attacks by CyberAv3ngers (also known as the Shahid Kaveh Group), a group affiliated with Iran's Islamic Revolutionary Guard Corps. In one case, intruders used Dropbear SSH software on victim modems to gain remote access via port 22, then extracted device project files and altered or deleted their logic, including disabling shutdown and alarm functions so unsafe conditions would go unnoticed. Authorities are urging organisations to disconnect PLCs from the public internet, adopt isolated network architectures, restrict access to these devices, check for unauthorised changes to project files, alert service providers to the threat, and replace default passwords.

  • CISA expands Iran-linked PLC attack alert beyond Rockwell to Schneider, Siemens
  • Hackers target internet-facing controllers, disabling safety shutdown/alarm logic
  • CISA urges isolating PLCs, checking for tampering, changing default passwords

Americas Middle East World

Read the full article at the source →