Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)

Iranian IRGC CyberAv3ngers APT Campaign Targeting (TL-2026-0335), also tracked as CISA AA26-097A, is a critical-severity advanced persistent threat campaign scored CVSS 10, first published 2026-04-08 and last reviewed 2026-08-04. It is attributed to Cyber Av3ngers (Iran) with high confidence, affects Rockwell Automation CompactLogix PLCs, references 1 CVE (CVE-2021-22681), maps to 73 MITRE ATT&CK techniques (T0806, T0807, T0809), and is covered by 9 detection rules and 64 indicators of compromise.

Key facts for TL-2026-0335

Threat ID
TL-2026-0335
Also known as
CISA AA26-097A, Iranian PLC Campaign 2026
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
APT
First published
2026-04-08
Last reviewed
2026-08-04
Attribution
Cyber Av3ngers
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
government, water-wastewater, energy, critical-manufacturing, industrial-control-systems
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
64
Updates
2026-08-04 · 5 updates · revalidated 5× · latest source

Malware and tooling in Iranian IRGC CyberAv3ngers APT Campaign Targeting

Malware and tooling: IOCONTROL via MQTT/8883, RSLinx / FactoryTalk Linx, Rockwell Studio 5000 Logix Designer, WIBU CodeMeter License Daemon

Iranian-affiliated APT actors linked to IRGC Cyber Electronic Command (CyberAv3ngers/Storm-0784/Bauxite/UNC5691) are actively exploiting internet-exposed Rockwell Automation/Allen-Bradley PLCs using legitimate engineering software. Joint advisory AA26-097A issued by FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command on April 7, 2026, warns of PLC disruptions across U.S. Government, Water/Wastewater, and Energy sectors affecting over 5,219 globally exposed devices.

How Iranian IRGC CyberAv3ngers APT Campaign Targeting works

Iranian IRGC Cyber Electronic Command (CEC)-affiliated threat group CyberAv3ngers has been conducting an active campaign since at least March 2026 targeting internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) across U.S. critical infrastructure. The group uses leased overseas infrastructure running legitimate Rockwell configuration software — specifically Studio 5000 Logix Designer and RSLinx/FactoryTalk Linx — to establish accepted connections to victim PLCs without requiring zero-day exploitation.

The primary attack methodology leverages the inherent lack of authentication on internet-exposed EtherNet/IP (port 44818) interfaces. Once connected via legitimate engineering software, the actors interact with PLC project files, manipulate HMI and SCADA display data shown to operators, and disrupt controller operations. This approach is particularly insidious because the traffic appears as legitimate engineering communications, making detection extremely difficult without behavioral analysis.

Censys exposure analysis identified 5,219 internet-exposed hosts globally responding to EtherNet/IP on port 44818 and self-identifying as Rockwell Automation/Allen-Bradley devices. A critical 74.6% (3,891 hosts) are located in the United States, with heavy concentration on cellular carrier networks — Verizon Business (49.1%, 2,564 hosts) and AT&T Mobility (13.3%, 693 hosts) — indicating field-deployed devices at pump stations, substations, and municipal facilities using cellular modems for remote connectivity. The predominant model is MicroLogix 1400, many running end-of-sale firmware versions C/21.02 and C/21.07.

The operator infrastructure consists of a multi-homed Windows engineering workstation spanning 11 IP addresses (185.82.73.160–.171) in AS214036 (ULTAHOST, Amsterdam), active from January 2025 through March 2026. The workstation hostname DESKTOP-BOE5MUC was consistently leaked across all services via self-signed certificates. The machine runs Rockwell Studio 5000 Logix Designer, RSLinx/FactoryTalk Linx, WIBU CodeMeter license daemon, and a full Windows protocol stack. Censys identified four additional operator IPs (.160, .161, .163, .166) not listed in the original CISA advisory.

A secondary single-use staging box at 135.136.1.133 (AS9009, M247 Europe Romania) was provisioned on February 23, 2026, with a 19-day idle period before a brief 26-hour EtherNet/IP testing window around March 14-16, 2026, followed by a coordinated full teardown on March 17-18 — characteristic of single-use operational staging infrastructure.

Co-exposed services significantly amplify risk: 771 instances of VNC (direct HMI/SCADA display access), 280 Telnet sessions, 292 Modbus endpoints, and 256 Red Lion Crimson installations were identified alongside exposed PLCs. The advisory also notes probing of Modbus/TCP (port 502) and Siemens S7 (port 102) protocols, suggesting broader multi-vendor targeting intent beyond Rockwell devices.

This campaign represents an evolution of CyberAv3ngers' prior operations, including the November 2023 Unitronics PLC campaign (CISA AA23-335A) that compromised 75+ devices across U.S. water facilities, and the deployment of the custom IOCONTROL malware framework targeting IoT/OT devices with encrypted MQTT C2 and DNS-over-HTTPS capabilities. The group now coordinates through an "Electronic Operations Room" established February 28, 2026, directing 60+ pro-Iranian proxy groups using shared ICS exploitation techniques. Six IRGC-CEC officials were sanctioned by OFAC in February 2024 with a $10 million bounty.

MITRE ATT&CK techniques used in TL-2026-0335

Impair Process Control

T0806 Brute Force I/O; T0836 Modify Parameter

Execution

T0807 Command-Line Interface; T0821 Modify Controller Tasking; T0853 Scripting; T0858 Change Operating Mode

inhibit-response-function

T0809 Data Destruction; T0835 Manipulate I/O Image

Collection

T0811 Data from Information Repositories; T0861 Point & Tag Identification; T0868 Detect Operating Mode; T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories

Impact

T0813 Denial of Control; T0826 Loss of Availability; T0828 Loss of Productivity and Revenue; T0829 Loss of View; T0831 Manipulation of Control; T0837 Loss of Protection; T0880 Loss of Safety; T1489 Service Stop; T1490 Inhibit System Recovery; T1565 Data Manipulation

Inhibit Response Function

T0814 Denial of Service; T0838 Modify Alarm Settings; T0878 Alarm Suppression

Initial Access

T0819 Exploit Public-Facing Application; T0866 Exploitation of Remote Services; T0883 Internet Accessible Device; T0886 Remote Services

initial-access

T0822 External Remote Services; T1190 Exploit Public-Facing Application

lateral-movement

T0843 Program Download; T1021 Remote Services

Discovery

T0846 Remote System Discovery; T0888 Remote System Information Discovery; T1018 Remote System Discovery

Persistence

T0859 Valid Accounts; T0889 Modify Program; T1505 Server Software Component

Command and Control

T0869 Standard Application Layer Protocol; T0884 Connection Proxy; T0885 Commonly Used Port; T1090 Proxy; T1219 Remote Access Tools; T1571 Non-Standard Port

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1694.001 Default Credentials

defense-evasion

T1027 Obfuscated Files or Information

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal

persistence

T1037 Boot or Logon Initialization Scripts; T1133 External Remote Services

Exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery

execution

T1059 Command and Scripting Interpreter

command-and-control

T1071 Application Layer Protocol; T1568 Dynamic Resolution

Privilege Escalation

T1078 Valid Accounts

Credential Access

T1110 Brute Force; T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1552.001 Credentials In Files

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Resource Development

T1584 Compromise Infrastructure

reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

evasion

T1692.001 Command Message

Evasion

T1692.002 Reporting Message

Affected products and versions in Iranian IRGC CyberAv3ngers APT Campaign Targeting

  • Rockwell Automation — CompactLogix PLCs
    Vulnerable versions: 1769 series; 5069 series; All internet-exposed
    Fixed in: No patch — requires network architecture remediation
  • Rockwell Automation — Micro850 PLCs
    Vulnerable versions: All internet-exposed versions
    Fixed in: No patch — requires network architecture remediation
  • Rockwell Automation — MicroLogix 1400
    Vulnerable versions: 1766 series; Firmware C/21.02; Firmware C/21.07 (end-of-sale)
    Fixed in: No patch — end-of-sale, requires replacement or isolation
  • Rockwell Automation — Micro820 PLCs
    Vulnerable versions: 2080 series; All internet-exposed
    Fixed in: No patch — requires network architecture remediation
  • Rockwell Automation — Studio 5000 Logix Designer
    Vulnerable versions: Used as attack tool by threat actors
    Fixed in: N/A — legitimate software abused

Remediation for Iranian IRGC CyberAv3ngers APT Campaign Targeting

Patches

  • Review Rockwell Automation PN1550 advisory for CVE-2021-22681 authentication bypass mitigation
  • Apply Rockwell Automation SD1771 guidance to disconnect devices from internet and harden PLCs
  • Update firmware on all Rockwell PLCs to latest supported versions
  • Contact Rockwell PSIRT (PSIRT@rockwellautomation.com) for device-specific hardening guidance

Immediate actions

  • Remove all Rockwell Automation/Allen-Bradley PLCs from direct internet exposure immediately
  • Disable cellular modems on field-deployed PLCs if remote access is not operationally required
  • Set CompactLogix/MicroLogix physical mode switch to RUN position to prevent remote project file changes
  • Block all inbound traffic from IOC IP ranges: 185.82.73.160/28 (AS214036) and 135.136.1.133 (AS9009)
  • Query firewall and IDS logs for inbound traffic on TCP ports 44818, 2222, 102, 502, 22, 43589 from all listed IOCs
  • Disable or firewall VNC, Telnet, and FTP services on hosts co-located with PLCs

Workarounds

  • Place PLCs behind VPN or industrial firewall with strict IP allowlisting
  • Use physical key switch in RUN mode as only control surface CIP cannot override remotely
  • Implement application-layer protocol filtering on EtherNet/IP traffic to block unauthorized engineering commands
  • Monitor EtherNet/IP identity responses for unexpected firmware version changes indicating tampering

Longer-term hardening

  • Implement secure remote access via jump hosts or industrial DMZ architecture — never expose PLCs directly to internet
  • Deploy network segmentation between IT and OT networks with monitored conduits
  • Implement multi-factor authentication for all remote OT network access
  • Deploy OT-specific network monitoring with EtherNet/IP protocol inspection capabilities
  • Establish firmware version monitoring to detect unauthorized changes
  • Implement CIP security features where supported by hardware generation
  • Audit and replace MicroLogix 1400 units on end-of-sale firmware (C/21.02, C/21.07) with supported models

CVEs associated with Iranian IRGC CyberAv3ngers APT Campaign Targeting

CVE-2021-22681

Weaknesses (CWE) in Iranian IRGC CyberAv3ngers APT Campaign Targeting

CWE-522, CWE-306, CWE-321, CWE-798, CWE-1188, CWE-320, CWE-284

Timeline of Iranian IRGC CyberAv3ngers APT Campaign Targeting

Showing the 20 most recent tracked events.

  • CISA adds CVE-2021-22681 to the Known Exploited Vulnerabilities (KEV) catalog after confirming active in-the-wild exploitation, setting a federal remediation deadline of 2026-03-26.
  • Joint advisory AA26-097A published by FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warning of Iranian APT exploitation of Rockwell PLCs across U.S. Government, Water/Wastewater, and Energy sectors
  • Censys publishes exposure analysis identifying 5,219 internet-exposed Rockwell PLCs globally (3,891 in U.S.), with 4 additional operator IPs not in original advisory and detailed infrastructure analysis
  • Open-source reporting (CSO Online) ties the Handala hacktivist persona to the same IRGC-linked proxy ecosystem as CyberAv3ngers, assessing both as likely state-directed.
  • As of 2026-05-29, this CyberAv3ngers (IRGC-CEC) campaign against internet-exposed Rockwell/Allen-Bradley PLCs remains active, with CISA AA26-097A confirming ongoing disruption of US water/energy/government infrastructure since March 2026. CVE-2021-22681 was added to CISA KEV (Mar 5, 2026, active exploitation); no patch, no takedown, and ~5,219 exposed devices persist.
  • Handala publicly claims compromise of the FBI Director's personal email, part of a pattern of escalating claimed operations against US targets.
  • Handala (MOIS-linked group) claims breach of California Water Service (Cal Water), leaking 5 GB of customer PII and administrative credentials; Mandiant investigation finds no OT compromise but confirms an IT system breach via the RTKBase NTRIP GPS platform.
  • WaterISAC, Rescana, and a detailed third-party OT threat-hunt plan (Burns & McDonnell / 1898 & Co.) publish independent analysis of the updated AA26-097A advisory, including a 21-IP IOC breakdown and YARA/SIGMA/Snort-Suricata detection rules.
  • CISA updates AA26-097A to add Schneider Electric (Modicon M340/BMX P34) and Siemens (S7-1200) PLCs to the campaign scope, previously limited to Rockwell Automation devices.
  • TechTimes and The Hacker News ThreatsDay Bulletin publish coverage of the updated advisory (tracked separately as TL-2026-1659).
  • SecurityWeek publishes coverage of the updated advisory, summarizing the expanded multi-vendor targeting and TTPs.
  • City of Plymouth (pop. ~80,000) proactively disconnects cellular-connected equipment at two water towers and multiple wastewater lift stations, reverting to manual operations.
  • City of Braham (pop. ~1,700) water plant taken offline for approximately 2 hours after attackers disable computerized operating controls.
  • Coordinated cyber campaign begins targeting over 30 community water and wastewater systems across Minnesota; attackers exploit internet-exposed PLCs, modify passwords to lock out operators, change PLC IP addresses, and manipulate ladder logic.
  • Minnesota IT Services (MNIT) activates statewide cybersecurity incident response; Minnesota Department of Health confirms drinking water quality was not affected in any confirmed case.
  • Maple Plain declares a local state of emergency to expand response capabilities; South St. Paul reports automated water utility control disruptions.
  • IOActive publishes a standalone analysis of the updated CISA advisory, framing the Schneider Electric/Siemens vendor-scope expansion and its implications for critical national infrastructure defenders.
  • Investigations confirm the campaign extends beyond Minnesota to at least 6 other states (Michigan, South Dakota, Georgia, and three unnamed); a leaked TLP:Amber Fusion Center memo aligns the attacks with Iranian hacking campaigns.
  • Rockwell Automation issues security guidance for restoring access to MicroLogix 1400 controllers when passwords are unknown, after investigators identify MicroLogix 1400 as a likely common vector across affected utilities.
  • CISA issues an urgent alert urging water and wastewater utilities to immediately disconnect PLCs from the internet, citing a significant increase in threat-actor targeting of water-sector PLCs.

Update history for TL-2026-0335

Sources cited for Iranian IRGC CyberAv3ngers APT Campaign Targeting

Threats related to Iranian IRGC CyberAv3ngers APT Campaign Targeting

Detection coverage for TL-2026-0335

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0335 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats