A joint U.S. government advisory said Iranian-affiliated cyber actors are actively exploiting internet-facing operational technology devices across multiple U.S. critical infrastructure sectors, with a particular focus on Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs). The activity has affected organizations in Government Services and Facilities, Water and Wastewater Systems, and Energy, where attackers maliciously interacted with project files and manipulated data displayed on HMI and SCADA systems, causing operational disruption and financial losses for some victims.
The campaign has been observed since at least March 2026 and shows similarities to prior CyberAv3ngers activity linked to the IRGC Cyber Electronic Command. According to the advisory, the actors used overseas IP infrastructure, Rockwell Studio 5000 Logix Designer, OT-related ports including 44818, 2222, 102, 22, and 502, and Dropbear SSH for remote access. U.S. authorities urged operators to remove PLCs from direct internet exposure, harden remote access, enable logging, place controllers in run mode where appropriate, and review published indicators of compromise and ATT&CK-mapped TTPs alongside Rockwell Automation security guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On April 7, 2026, CISA and partner agencies warned that Iranian-affiliated actors were actively exploiting internet-facing PLCs, disrupting operations by manipulating project files and altering data shown on HMI and SCADA displays. The advisory also shared technical details, observed ports and tooling, indicators of compromise, and mitigation guidance for defenders.
Rockwell Automation published security advisory SD1771 addressing the PLC-focused threat activity referenced in later government reporting. The advisory was released on March 20, 2026.
Since at least March 2026, Iranian-affiliated cyber actors have targeted internet-exposed operational technology devices across multiple U.S. critical infrastructure sectors, especially Rockwell Automation/Allen-Bradley PLCs. The activity affected sectors including Government Services and Facilities, Water and Wastewater Systems, and Energy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
31 references tracked. Mallory keeps watching after this page renders.
blog.polyswarm.io
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcerockwellautomation.com
Open sourceinfosec.pub
Open sourceic3.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.