SUBJECT PROFILE
CISA updated advisory AA26-097A on July 22, 2026, confirming this Iranian-affiliated APT has expanded its PLC targeting beyond Rockwell Automation to now include Schneider Electric and Siemens hardware. The FBI observed actors using vendors' own engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal) to download malicious project files directly to internet-exposed PLCs, overriding safety alarm and shutdown logic, causing confirmed operational disruption and financial loss at victim sites. The campaign, active since at least March 2026, reflects a deliberate platform shift toward Western-made controllers far more widely deployed across U.S. infrastructure.
Physical disruption of U.S. critical infrastructure; retaliatory cyber operations following Operation Epic Fury (U.S.-Israel strikes on Iran, Feb 2026)
OPERATIONAL HISTORY
T1190 (Exploit Public-Facing Application), T0885 (Exploitation of Remote Services - OT), T0836 (Modify Parameter), T0855 (Unauthorized Command Message), T1041 (Exfiltration Over C2 Channel - vendor config software), Malicious PLC ladder logic injection via AOI modules, HMI/SCADA display falsification, Dropbear SSH on victim modems
KNOWN INFRASTRUCTURE
Foreign-based IP addresses targeting PLC ports 44818, 2222, 102, 502; Dropbear SSH; vendor engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) abused for access; STIX IOCs published by CISA July 22, 2026