Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
Iranian IRGC CyberAv3ngers APT Campaign Targeting (TL-2026-0335), also tracked as CISA AA26-097A, is a critical-severity advanced persistent threat campaign scored CVSS 10, first published 2026-04-08 and last reviewed 2026-08-04. It is attributed to Cyber Av3ngers (Iran) with high confidence, affects Rockwell Automation CompactLogix PLCs, references 1 CVE (CVE-2021-22681), maps to 73 MITRE ATT&CK techniques (T0806, T0807, T0809), and is covered by 9 detection rules and 64 indicators of compromise.
Key facts for TL-2026-0335
- Threat ID
- TL-2026-0335
- Also known as
- CISA AA26-097A, Iranian PLC Campaign 2026
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-04-08
- Last reviewed
- 2026-08-04
- Attribution
- Cyber Av3ngers
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- government, water-wastewater, energy, critical-manufacturing, industrial-control-systems
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 64
- Updates
- 2026-08-04 · 5 updates · revalidated 5× · latest source
Malware and tooling in Iranian IRGC CyberAv3ngers APT Campaign Targeting
Malware and tooling: IOCONTROL via MQTT/8883, RSLinx / FactoryTalk Linx, Rockwell Studio 5000 Logix Designer, WIBU CodeMeter License Daemon
Iranian-affiliated APT actors linked to IRGC Cyber Electronic Command (CyberAv3ngers/Storm-0784/Bauxite/UNC5691) are actively exploiting internet-exposed Rockwell Automation/Allen-Bradley PLCs using legitimate engineering software. Joint advisory AA26-097A issued by FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command on April 7, 2026, warns of PLC disruptions across U.S. Government, Water/Wastewater, and Energy sectors affecting over 5,219 globally exposed devices.
How Iranian IRGC CyberAv3ngers APT Campaign Targeting works
Iranian IRGC Cyber Electronic Command (CEC)-affiliated threat group CyberAv3ngers has been conducting an active campaign since at least March 2026 targeting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) across U.S. critical infrastructure. The group uses leased overseas infrastructure running legitimate Rockwell configuration software — specifically Studio 5000 Logix Designer and RSLinx/FactoryTalk Linx — to establish accepted connections to victim PLCs without requiring zero-day exploitation.
The primary attack methodology leverages the inherent lack of authentication on internet-exposed EtherNet/IP (port 44818) interfaces. Once connected via legitimate engineering software, the actors interact with PLC project files, manipulate HMI and SCADA display data shown to operators, and disrupt controller operations. This approach is particularly insidious because the traffic appears as legitimate engineering communications, making detection extremely difficult without behavioral analysis.
Censys exposure analysis identified 5,219 internet-exposed hosts globally responding to EtherNet/IP on port 44818 and self-identifying as Rockwell Automation/Allen-Bradley devices. A critical 74.6% (3,891 hosts) are located in the United States, with heavy concentration on cellular carrier networks — Verizon Business (49.1%, 2,564 hosts) and AT&T Mobility (13.3%, 693 hosts) — indicating field-deployed devices at pump stations, substations, and municipal facilities using cellular modems for remote connectivity. The predominant model is MicroLogix 1400, many running end-of-sale firmware versions C/21.02 and C/21.07.
The operator infrastructure consists of a multi-homed Windows engineering workstation spanning 11 IP addresses (185.82.73.160–.171) in AS214036 (ULTAHOST, Amsterdam), active from January 2025 through March 2026. The workstation hostname DESKTOP-BOE5MUC was consistently leaked across all services via self-signed certificates. The machine runs Rockwell Studio 5000 Logix Designer, RSLinx/FactoryTalk Linx, WIBU CodeMeter license daemon, and a full Windows protocol stack. Censys identified four additional operator IPs (.160, .161, .163, .166) not listed in the original CISA advisory.
A secondary single-use staging box at 135.136.1.133 (AS9009, M247 Europe Romania) was provisioned on February 23, 2026, with a 19-day idle period before a brief 26-hour EtherNet/IP testing window around March 14-16, 2026, followed by a coordinated full teardown on March 17-18 — characteristic of single-use operational staging infrastructure.
Co-exposed services significantly amplify risk: 771 instances of VNC (direct HMI/SCADA display access), 280 Telnet sessions, 292 Modbus endpoints, and 256 Red Lion Crimson installations were identified alongside exposed PLCs. The advisory also notes probing of Modbus/TCP (port 502) and Siemens S7 (port 102) protocols, suggesting broader multi-vendor targeting intent beyond Rockwell devices.
This campaign represents an evolution of CyberAv3ngers' prior operations, including the November 2023 Unitronics PLC campaign (CISA AA23-335A) that compromised 75+ devices across U.S. water facilities, and the deployment of the custom IOCONTROL malware framework targeting IoT/OT devices with encrypted MQTT C2 and DNS-over-HTTPS capabilities. The group now coordinates through an "Electronic Operations Room" established February 28, 2026, directing 60+ pro-Iranian proxy groups using shared ICS exploitation techniques. Six IRGC-CEC officials were sanctioned by OFAC in February 2024 with a $10 million bounty.
MITRE ATT&CK techniques used in TL-2026-0335
Impair Process Control
T0806 Brute Force I/O; T0836 Modify Parameter
Execution
T0807 Command-Line Interface; T0821 Modify Controller Tasking; T0853 Scripting; T0858 Change Operating Mode
inhibit-response-function
T0809 Data Destruction; T0835 Manipulate I/O Image
Collection
T0811 Data from Information Repositories; T0861 Point & Tag Identification; T0868 Detect Operating Mode; T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories
Impact
T0813 Denial of Control; T0826 Loss of Availability; T0828 Loss of Productivity and Revenue; T0829 Loss of View; T0831 Manipulation of Control; T0837 Loss of Protection; T0880 Loss of Safety; T1489 Service Stop; T1490 Inhibit System Recovery; T1565 Data Manipulation
Inhibit Response Function
T0814 Denial of Service; T0838 Modify Alarm Settings; T0878 Alarm Suppression
Initial Access
T0819 Exploit Public-Facing Application; T0866 Exploitation of Remote Services; T0883 Internet Accessible Device; T0886 Remote Services
initial-access
T0822 External Remote Services; T1190 Exploit Public-Facing Application
lateral-movement
T0843 Program Download; T1021 Remote Services
Discovery
T0846 Remote System Discovery; T0888 Remote System Information Discovery; T1018 Remote System Discovery
Persistence
T0859 Valid Accounts; T0889 Modify Program; T1505 Server Software Component
Command and Control
T0869 Standard Application Layer Protocol; T0884 Connection Proxy; T0885 Commonly Used Port; T1090 Proxy; T1219 Remote Access Tools; T1571 Non-Standard Port
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1694.001 Default Credentials
defense-evasion
T1027 Obfuscated Files or Information
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal
persistence
T1037 Boot or Logon Initialization Scripts; T1133 External Remote Services
Exfiltration
T1041 Exfiltration Over C2 Channel
discovery
T1046 Network Service Discovery
execution
T1059 Command and Scripting Interpreter
command-and-control
T1071 Application Layer Protocol; T1568 Dynamic Resolution
Privilege Escalation
Credential Access
T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Credentials In Files
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools
resource-development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Resource Development
T1584 Compromise Infrastructure
reconnaissance
T1595 Active Scanning; T1596 Search Open Technical Databases
evasion
Evasion
Affected products and versions in Iranian IRGC CyberAv3ngers APT Campaign Targeting
- Rockwell Automation — CompactLogix PLCs
Vulnerable versions: 1769 series; 5069 series; All internet-exposed
Fixed in: No patch — requires network architecture remediation - Rockwell Automation — Micro850 PLCs
Vulnerable versions: All internet-exposed versions
Fixed in: No patch — requires network architecture remediation - Rockwell Automation — MicroLogix 1400
Vulnerable versions: 1766 series; Firmware C/21.02; Firmware C/21.07 (end-of-sale)
Fixed in: No patch — end-of-sale, requires replacement or isolation - Rockwell Automation — Micro820 PLCs
Vulnerable versions: 2080 series; All internet-exposed
Fixed in: No patch — requires network architecture remediation - Rockwell Automation — Studio 5000 Logix Designer
Vulnerable versions: Used as attack tool by threat actors
Fixed in: N/A — legitimate software abused
Remediation for Iranian IRGC CyberAv3ngers APT Campaign Targeting
Patches
- Review Rockwell Automation PN1550 advisory for CVE-2021-22681 authentication bypass mitigation
- Apply Rockwell Automation SD1771 guidance to disconnect devices from internet and harden PLCs
- Update firmware on all Rockwell PLCs to latest supported versions
- Contact Rockwell PSIRT (PSIRT@rockwellautomation.com) for device-specific hardening guidance
Immediate actions
- Remove all Rockwell Automation/Allen-Bradley PLCs from direct internet exposure immediately
- Disable cellular modems on field-deployed PLCs if remote access is not operationally required
- Set CompactLogix/MicroLogix physical mode switch to RUN position to prevent remote project file changes
- Block all inbound traffic from IOC IP ranges: 185.82.73.160/28 (AS214036) and 135.136.1.133 (AS9009)
- Query firewall and IDS logs for inbound traffic on TCP ports 44818, 2222, 102, 502, 22, 43589 from all listed IOCs
- Disable or firewall VNC, Telnet, and FTP services on hosts co-located with PLCs
Workarounds
- Place PLCs behind VPN or industrial firewall with strict IP allowlisting
- Use physical key switch in RUN mode as only control surface CIP cannot override remotely
- Implement application-layer protocol filtering on EtherNet/IP traffic to block unauthorized engineering commands
- Monitor EtherNet/IP identity responses for unexpected firmware version changes indicating tampering
Longer-term hardening
- Implement secure remote access via jump hosts or industrial DMZ architecture — never expose PLCs directly to internet
- Deploy network segmentation between IT and OT networks with monitored conduits
- Implement multi-factor authentication for all remote OT network access
- Deploy OT-specific network monitoring with EtherNet/IP protocol inspection capabilities
- Establish firmware version monitoring to detect unauthorized changes
- Implement CIP security features where supported by hardware generation
- Audit and replace MicroLogix 1400 units on end-of-sale firmware (C/21.02, C/21.07) with supported models
CVEs associated with Iranian IRGC CyberAv3ngers APT Campaign Targeting
Weaknesses (CWE) in Iranian IRGC CyberAv3ngers APT Campaign Targeting
CWE-522, CWE-306, CWE-321, CWE-798, CWE-1188, CWE-320, CWE-284
Timeline of Iranian IRGC CyberAv3ngers APT Campaign Targeting
Showing the 20 most recent tracked events.
- CISA adds CVE-2021-22681 to the Known Exploited Vulnerabilities (KEV) catalog after confirming active in-the-wild exploitation, setting a federal remediation deadline of 2026-03-26.
- Joint advisory AA26-097A published by FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warning of Iranian APT exploitation of Rockwell PLCs across U.S. Government, Water/Wastewater, and Energy sectors
- Censys publishes exposure analysis identifying 5,219 internet-exposed Rockwell PLCs globally (3,891 in U.S.), with 4 additional operator IPs not in original advisory and detailed infrastructure analysis
- Open-source reporting (CSO Online) ties the Handala hacktivist persona to the same IRGC-linked proxy ecosystem as CyberAv3ngers, assessing both as likely state-directed.
- As of 2026-05-29, this CyberAv3ngers (IRGC-CEC) campaign against internet-exposed Rockwell/Allen-Bradley PLCs remains active, with CISA AA26-097A confirming ongoing disruption of US water/energy/government infrastructure since March 2026. CVE-2021-22681 was added to CISA KEV (Mar 5, 2026, active exploitation); no patch, no takedown, and ~5,219 exposed devices persist.
- Handala publicly claims compromise of the FBI Director's personal email, part of a pattern of escalating claimed operations against US targets.
- Handala (MOIS-linked group) claims breach of California Water Service (Cal Water), leaking 5 GB of customer PII and administrative credentials; Mandiant investigation finds no OT compromise but confirms an IT system breach via the RTKBase NTRIP GPS platform.
- WaterISAC, Rescana, and a detailed third-party OT threat-hunt plan (Burns & McDonnell / 1898 & Co.) publish independent analysis of the updated AA26-097A advisory, including a 21-IP IOC breakdown and YARA/SIGMA/Snort-Suricata detection rules.
- CISA updates AA26-097A to add Schneider Electric (Modicon M340/BMX P34) and Siemens (S7-1200) PLCs to the campaign scope, previously limited to Rockwell Automation devices.
- TechTimes and The Hacker News ThreatsDay Bulletin publish coverage of the updated advisory (tracked separately as TL-2026-1659).
- SecurityWeek publishes coverage of the updated advisory, summarizing the expanded multi-vendor targeting and TTPs.
- City of Plymouth (pop. ~80,000) proactively disconnects cellular-connected equipment at two water towers and multiple wastewater lift stations, reverting to manual operations.
- City of Braham (pop. ~1,700) water plant taken offline for approximately 2 hours after attackers disable computerized operating controls.
- Coordinated cyber campaign begins targeting over 30 community water and wastewater systems across Minnesota; attackers exploit internet-exposed PLCs, modify passwords to lock out operators, change PLC IP addresses, and manipulate ladder logic.
- Minnesota IT Services (MNIT) activates statewide cybersecurity incident response; Minnesota Department of Health confirms drinking water quality was not affected in any confirmed case.
- Maple Plain declares a local state of emergency to expand response capabilities; South St. Paul reports automated water utility control disruptions.
- IOActive publishes a standalone analysis of the updated CISA advisory, framing the Schneider Electric/Siemens vendor-scope expansion and its implications for critical national infrastructure defenders.
- Investigations confirm the campaign extends beyond Minnesota to at least 6 other states (Michigan, South Dakota, Georgia, and three unnamed); a leaked TLP:Amber Fusion Center memo aligns the attacks with Iranian hacking campaigns.
- Rockwell Automation issues security guidance for restoring access to MicroLogix 1400 controllers when passwords are unknown, after investigators identify MicroLogix 1400 as a likely common vector across affected utilities.
- CISA issues an urgent alert urging water and wastewater utilities to immediately disconnect PLCs from the internet, citing a significant increase in threat-actor targeting of water-sector PLCs.
Update history for TL-2026-0335
- 2026-08-04 — Coordinated Cyber Campaign Targeting PLCs at US Water and Wastewater Systems (July 2026): What changed Campaign escalated from a documented exposure/reconnaissance advisory to confirmed real-world attacks: 30+ Minnesota water utilities compromised July 26-27, 2026, causing a plant shutdown (Braham), proactive disconnections (Ply
- 2026-07-27 — Iranian-Affiliated Actors Expand PLC Targeting to Siemens and Schneider Electric — CISA AA26-097A Update Adds 13 IOCs and Add-On Instruction Detection Guidance: What changed No severity/exploitability/status escalation — the new report's own severity (HIGH), CVSS (9.8), and attribution confidence (MEDIUM) are each lower than the existing record's (CRITICAL/10/HIGH), so per the escalation-only polic
- 2026-07-25 — Iran-Affiliated Actors (CyberAv3ngers / IRGC-CEC) Exploit Internet-Exposed Rockwell Automation/Allen-Bradley PLCs via CVE-2021-22681 Across US Critical Infrastructure (CISA AA26-097A): What changed No field escalations — severity/exploitability/status unchanged (new report's HIGH severity/8.1 CVSS is a downgrade from the existing CRITICAL/10 and was ignored per the escalation-only rule). New indicators (1) 1 new entity IO
- 2026-07-23 — Iran-Linked CyberAv3ngers (IRGC-CEC) Exploit CVE-2021-22681 Authentication Bypass and Internet-Exposed Rockwell, Schneider, and Siemens PLCs to Disrupt U.S. Critical Infrastructure (CISA AA26-097A): What changed No field escalations: the newer report's severity_level (HIGH) and cvss_score (9.8) are lower than the existing record's (CRITICAL/10) and are withheld per the escalation-only, no-downgrade rule; exploitability, status, and att
- 2026-07-23 — Iran-Linked Threat Actors (CyberAv3ngers/IRGC-CEC, Handala) Actively Exploit Rockwell, Schneider Electric, and Siemens PLCs Across US Critical Infrastructure (CVE-2021-22681): What changed CVSS escalated 9.8 → 10.0 for CVE-2021-22681. CISA's 2026-07-22 update to AA26-097A expands the campaign from Rockwell-only to also include Schneider Electric (Modicon M340) and Siemens (S7-1200) PLCs, and formally ties the Han
Sources cited for Iranian IRGC CyberAv3ngers APT Campaign Targeting
- CISA Advisory AA26-097A — Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure
- Censys — Iranian-Affiliated APT Targeting Rockwell/Allen-Bradley PLCs Exposure Analysis
- CISA Advisory AA23-335A — IRGC-Affiliated Cyber Actors Exploit PLCs (Unitronics Campaign)
- Rockwell Automation PN1550 — CVE-2021-22681 Authentication Bypass in Logix Controllers
- Rockwell Automation SD1771 — Disconnect Devices from Internet and Harden PLCs
- MITRE ATT&CK — CyberAv3ngers Group Profile (G1027)
- Claroty Team82 — Inside IOCONTROL: A New OT/IoT Cyberweapon
- SecurityWeek — Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks
- CyberWarrior76 — CyberAv3ngers IRGC-CEC Modus Operandi Analysis
- CISA STIX Data — AA26-097A Machine-Readable Indicators
Threats related to Iranian IRGC CyberAv3ngers APT Campaign Targeting
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
Detection coverage for TL-2026-0335
As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0335 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.