Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) — Threadlinqs Intelligence
As of 2026-07-25, Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) is a critical-severity apt threat attributed to Cyber Av3ngers (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 54 indicators of compromise.
Threat ID: TL-2026-0335 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: APT
Updated: 2026-07-25 · 3 updates · revalidated 3× · latest source
Attribution: Cyber Av3ngers · Iran · DESTRUCTION
Iranian-affiliated APT actors linked to IRGC Cyber Electronic Command (CyberAv3ngers/Storm-0784/Bauxite/UNC5691) are actively exploiting internet-exposed Rockwell Automation/Allen-Bradley PLCs using
Iranian IRGC Cyber Electronic Command (CEC)-affiliated threat group CyberAv3ngers has been conducting an active campaign since at least March 2026 targeting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) across U.S. critical infrastructure. The group uses leased overseas infrastructure running legitimate Rockwell configuration software — specifically Studio 5000 Logix Designer and RSLinx/FactoryTalk Linx — to establish accepted connections to victim PLCs without requiring zero-day exploitation.
The primary attack methodology leverages the inherent lack of authentication on internet-exposed EtherNet/IP (port 44818) interfaces. Once connected via legitimate engineering software, the actors interact with PLC project files, manipulate HMI and SCADA display data shown to operators, and disrupt controller operations. This approach is particularly insidious because the traffic appears as legitimate engineering communications, making detection extremely difficult without behavioral analysis.
Censys exposure analysis identified 5,219 internet-exposed hosts globally responding to EtherNet/IP on port 44818 and self-identifying as Rockwell Automation/Allen-Bradley devices. A critical 74.6% (3,891 hosts) are located in the United States, with heavy concentration on cellular carrier networks — Verizon Business (49.1%, 2,564 hosts) and AT&T Mobility (13.3%, 693 hosts) — indicating field-deployed devices at pump stations, substations, and municipal facilities using cellular modems for remote connectivity. The predominant model is MicroLogix 1400, many running end-of-sale firmware versions C/21.02 and C/21.07.
The operator infrastructure consists of a multi-homed Windows engineering workstation spanning 11 IP addresses (185.82.73.160–.171) in AS214036 (ULTAHOST, Amsterdam), active from January 2025 through March 2026. The workstation hostname DESKTOP-BOE5MUC was consistently leaked across all services via self-signed certificates. The machine runs Rockwell Studio 5000 Logix Designer, RSLinx/FactoryTalk Linx, WIBU CodeMeter license daemon, and a full Windows protocol stack. Censys identified four additional operator IPs (.160, .161, .163, .166) not listed in the original CISA advisory.
A secondary single-use staging box at 135.136.1.133 (AS9009, M247 Europe Romania) was provisioned on February 23, 2026, with a 19-day idle period before a brief 26-hour EtherNet/IP testing window around March 14-16, 2026, followed by a coordinated full teardown on March 17-18 — characteristic of single-use operational staging infrastructure.
Co-exposed services significantly amplify risk: 771 instances of VNC (direct HMI/SCADA display access), 280 Telnet sessions, 292 Modbus endpoints, and 256 Red Lion Crimson installations were identified alongside exposed PLCs. The advisory also notes probing of Modbus/TCP (port 502) and Siemens S7 (port 102) protocols, suggesting broader multi-vendor targeting intent beyond Rockwell devices.
This campaign represents an evolution of CyberAv3ngers' prior operations, including the November 2023 Unitronics PLC campaign (CISA AA23-335A) that compromised 75+ devices across U.S. water facilities, and the deployment of the custom IOCONTROL malware framework targeting IoT/OT devices with encrypted MQTT C2 and DNS-over-HTTPS capabilities. The group now coordinates through an "Electronic Operations Room" established February 28, 2026, directing 60+ pro-Iranian proxy groups using shared ICS exploitation techniques. Six IRGC-CEC officials were sanctioned by OFAC in February 2024 with a $10 million bounty.
Weaknesses (CWE)
CWE-522, CWE-306, CWE-321, CWE-798, CWE-1188, CWE-320
Target sectors: government, water-wastewater, energy, critical-manufacturing, industrial-control-systems
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 54 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, CVE-2021-22681, T0883, T0819, T0821, T0855, T0812, T0836, T0814, T0826, T0829, T0828