DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // IRGC-CEC-ICS-PLC-2026FIRST SEEN: NOV 2023

IRGC CEC-AFFILIATED ICS/OT APT

ALSO KNOWN AS: Iranian-Affiliated APT (AA26-097A), CyberAv3ngers (overlapping infrastructure)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Iran (Islamic Revolutionary Guard Corps Cyber-Electronic Command)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:NOV 2023
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL78/100
RESOURCES86/100
PERSISTENCE86/100
STEALTH86/100
IMPACT78/100

CISA updated advisory AA26-097A on July 22, 2026, confirming this Iranian-affiliated APT has expanded its PLC targeting beyond Rockwell Automation to now include Schneider Electric and Siemens hardware. The FBI observed actors using vendors' own engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal) to download malicious project files directly to internet-exposed PLCs, overriding safety alarm and shutdown logic, causing confirmed operational disruption and financial loss at victim sites. The campaign, active since at least March 2026, reflects a deliberate platform shift toward Western-made controllers far more widely deployed across U.S. infrastructure.

Physical disruption of U.S. critical infrastructure; retaliatory cyber operations following Operation Epic Fury (U.S.-Israel strikes on Iran, Feb 2026)

T1190 (Exploit Public-Facing Application), T0885 (Exploitation of Remote Services - OT), T0836 (Modify Parameter), T0855 (Unauthorized Command Message), T1041 (Exfiltration Over C2 Channel - vendor config software), Malicious PLC ladder logic injection via AOI modules, HMI/SCADA display falsification, Dropbear SSH on victim modems

ENERGY
WATER & WASTEWATER SYSTEMS
GOVERNMENT FACILITIES
INDUSTRIAL CONTROL SYSTEMS

Foreign-based IP addresses targeting PLC ports 44818, 2222, 102, 502; Dropbear SSH; vendor engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) abused for access; STIX IOCs published by CISA July 22, 2026

FILE DATE: APR 2026
Operation PLC Sabotage - Phase 1 (Rockwell)
Initial CISA advisory AA26-097A disclosed Iranian-affiliated actors exploiting internet-exposed Rockwell/Allen-Bradley PLCs at U.S. critical infrastructure, manipulating HMI and SCADA displays to cause operational disruption.
FILE DATE: JUL 2026
Operation PLC Sabotage - Phase 2 (Siemens/Schneider Expansion)
CISA July 22 update confirmed expanded targeting to Schneider Electric BMX/Modicon ████████████████ S7-1200 PLCs; malicious AOIs confirmed to have disabled alarm and shutdown logic at a U.S. victim site, shifting campaign from reconnaissance to confirmed physical-consequence operations.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn