ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain
ThreatsDay Bulletin (TL-2026-1659), also tracked as ThreatsDay Bulletin 2026-07-23, is a high-severity campaign, first published 2026-07-23. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Rockwell Automation Allen-Bradley PLCs / Studio 5000 Logix, maps to 34 MITRE ATT&CK techniques (T0807, T0813, T0819), and is covered by 9 detection rules and 34 indicators of compromise.
Key facts for TL-2026-1659
- Threat ID
- TL-2026-1659
- Also known as
- ThreatsDay Bulletin 2026-07-23, AA26-097A Update, BH Alert Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- CAMPAIGN
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution
- Cyber Av3ngers
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- waterwastewater, energy, government administration, criticalinfrastructure, finance, mobileusers, telecoms
- Target regions
- North America, Middle East, bahrain, kuwait, Gulf Cooperation Council
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in ThreatsDay Bulletin
Malware and tooling: Hvoicemanual, MarkiRAT - S0652, OctagonPanel, SectopRAT, Dropbear SSH, Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, Siemens TIA Portal
CISA, FBI, and EPA updated advisory AA26-097A (originally April 7, 2026; updated July 22, 2026) on Iranian-affiliated APT actors — linked to IRGC-CEC/CyberAv3ngers tradecraft — using leased infrastructure and legitimate vendor engineering software (Studio 5000 Logix Designer, EcoStruxure Control Expert, TIA Portal) to compromise internet-exposed Rockwell/Allen-Bradley, Schneider Electric, and Siemens PLCs across Water/Wastewater, Energy, and Government Services sectors, inserting malicious Add-On Instructions and disabling shutdown/alarm logic. Separately, a four-stage OctagonPanel/Ward RAT Android spyware platform is distributed via look-alike domains cloning Google Play and official Bahraini government sites under the guise of a 'BH Alert' civil-defense siren app, harvesting lockscreen credentials, intercepting SMS/OTP, running banking overlays, and granting full remote device control.
How ThreatsDay Bulletin works
This threat bulletin (aggregated from The Hacker News' ThreatsDay roundup, published 2026-07-23) documents two converging campaigns.
**1) Iran-affiliated PLC intrusion campaign (CISA AA26-097A).** CISA, FBI, EPA, and government partners updated an advisory originally issued April 7, 2026, warning of ongoing exploitation of internet-connected operational technology by Iranian-affiliated APT actors whose tradecraft overlaps with IRGC Cyber-Electronic Command (IRGC-CEC) and the previously disclosed CyberAv3ngers persona (first publicized November 2023 for Unitronics PLC defacements). The July 22, 2026 update adds guidance for detecting malicious changes to reusable code modules — specifically malicious Add-On Instructions (AOIs) — within Rockwell Automation PLC programs. Actors used leased, third-party-hosted infrastructure and foreign-sourced IP addresses to reach misconfigured, internet-facing PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. Rather than exploiting a specific CVE, the actors abused legitimate vendor configuration software — Rockwell Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens Totally Integrated Automation (TIA) Portal — to authenticate to exposed engineering ports, exfiltrate PLC project files, delete project logic, and manipulate data rendered on HMI/SCADA displays. At one victim site, attackers inserted override routines that disabled critical shutdown and alarm logic, and used Dropbear SSH for command-and-control persistence over port 22. Targeted OT protocol ports included 44818 and 2222 (Rockwell EtherNet/IP), 102 (Siemens S7comm), and 502 (Modbus TCP). CISA published 12 malicious source IP addresses with observed activity spanning September 2025 through July 2026. Impacted sectors are Water and Wastewater Systems (WWS), Energy, and Government Services and Facilities, with confirmed operational disruption and financial loss at affected sites. Attribution confidence is assessed MEDIUM by the authoring agencies, who note Iran-affiliated actors have historically used ransomware-gang personas as cover and that attribution to a specific unit remains difficult.
**2) OctagonPanel/Ward RAT 'BH Alert' Android spyware campaign.** Discovered July 17, 2026 by researchers at DreamGroup, this campaign exploits heightened public anxiety after Gulf-nation civil-defense sirens were activated in July 2026 following regional missile threats. Threat actors built a network of look-alike domains (playgoogle.alertbh[.]com, download.alert-bh[.]com, download.bh-security[.]com) cloning both the Google Play Store storefront and official Bahraini government portals, complete with fake install animations and ad-tracking pixels, to distribute a trojanized 'BH Alert' civil-defense siren app via smishing and social-media links. The malware uses a four-stage infection chain: Stage 0 ('Ematterassist') is an RC4-encrypted loader disguised as a font file (ZfChs.ttf) that injects hidden DEX code; Stage 1 (package com.kit.kitty) presents a social-engineering UI requesting invasive Android permissions and silently installs a secondary APK; Stage 2 ('Hvoicemanual') is a secondary RC4-encrypted shell that decrypts and launches the main payload; Stage 3 (package com.kisa.octagonpanel) is the OctagonPanel/Ward RAT itself, which abuses Android AccessibilityService (registered as WardAccessibilityService) to harvest lockscreen PIN/pattern input, intercept SMS and one-time passwords, exfiltrate contacts/call logs, capture screenshots, enumerate installed apps, render phishing overlays atop legitimate banking apps, execute arbitrary remote commands via an encrypted C2 channel, self-exclude from the recent-apps switcher, and deploy a fake VPN service to disrupt legitimate connectivity while preserving attacker C2. The campaign is assessed to primarily target Bahraini (and secondarily Kuwaiti) mobile users during a period of elevated civil-defense app adoption.
**Adjacent items referenced in the same bulletin (lower-confidence, included for tag/technique coverage only, not separately scored):** a GitHub pull-request prompt-injection technique ('GhostCommit') hiding malicious LLM-reviewer instructions inside PNG image bytes to exfiltrate repository secrets; an Iran-nexus group tracked as TAG-182 distributing MarkiRAT via fake VPN/download-tool Android apps targeting the Iranian diaspora, sharing tradecraft with previously reported Ferocious Kitten activity; a TrickBot variant adding DNS-tunneling C2 (encrypted DNS query packets used to carry command traffic) for evasion; and a malvertising campaign ('FakeAgent') redirecting victims to spoofed Claude Artifacts pages serving a trojanized 'ClaudeDesktop.exe' that deploys SectopRAT, affecting at least 29 organizations July 21-22, 2026.
MITRE ATT&CK techniques used in TL-2026-1659
Execution
T0807 Command-Line Interface; T0821 Modify Controller Tasking
Impact
T0813 Denial of Control; T0837 Loss of Protection; T1582 SMS Control
initial-access
T0819 Exploit Public-Facing Application; T0848 Rogue Master; T0886 Remote Services; T1660 Phishing
Impair Process Control
lateral-movement
Collection
T0861 Point & Tag Identification; T0868 Detect Operating Mode; T1513 Screen Capture; T1636 Protected User Data; T1636.003 Contact List; T1636.004 SMS Messages
command-and-control
T0869 Standard Application Layer Protocol; T0885 Commonly Used Port; T1437 Application Layer Protocol; T1663 Remote Access Software
execution
Inhibit Response Function
Persistence
T0889 Modify Program; T1541 Foreground Persistence
defense-evasion
T1406 Obfuscated Files or Information; T1628 Hide Artifacts; T1629.002 Device Lockout
collection
T1417 Input Capture; T1638 Adversary-in-the-Middle
credential-access
Discovery
impact
T1471 Data Encrypted for Impact
evasion
Affected products and versions in ThreatsDay Bulletin
- Rockwell Automation — Allen-Bradley PLCs / Studio 5000 Logix Designer-managed controllers
Vulnerable versions: internet-exposed deployments, all firmware versions
Fixed in: N/A - misconfiguration issue; mitigate via network isolation - Schneider Electric — PLCs managed via EcoStruxure Control Expert
Vulnerable versions: internet-exposed deployments, all firmware versions
Fixed in: N/A - misconfiguration issue; mitigate via network isolation - Siemens — Controllers managed via TIA Portal (S7 protocol)
Vulnerable versions: internet-exposed deployments, all firmware versions
Fixed in: N/A - misconfiguration issue; mitigate via network isolation - Unofficial / Malicious — 'BH Alert' trojanized Android application (com.kisa.octagonpanel and dropper chain)
Vulnerable versions: all versions distributed via look-alike domains
Fixed in: N/A - malicious app; only official Google Play / Bahraini government-verified listing is legitimate
Remediation for ThreatsDay Bulletin
Patches
- No CVE-based patch applicable; this is a misconfiguration/exposure and legitimate-tool-abuse issue, not a software vulnerability
Immediate actions
- Disconnect all PLCs and OT engineering interfaces from direct internet exposure
- Block inbound traffic to OT ports 44818, 2222 (Rockwell EtherNet/IP), 102 (Siemens S7comm), and 502 (Modbus TCP) at the perimeter
- Block the 12 published malicious source IP addresses at network egress/ingress
- Uninstall any 'BH Alert' APK not obtained from the official Google Play Store listing; scan devices for com.kisa.octagonpanel, com.kit.kitty, WardAccessibilityService
- Revoke and rotate credentials on any device that had the fake BH Alert app installed, prioritizing banking and SMS/OTP-linked accounts
Workarounds
- Set Rockwell/Allen-Bradley controller key switch to a protected/RUN-only mode to block remote program uploads
- Restrict Studio 5000 Logix Designer, EcoStruxure Control Expert, and TIA Portal remote-connection capability to segmented management networks only
- Monitor OT logs for overseas/foreign-sourced connection attempts to engineering ports
Longer-term hardening
- Implement network segmentation between OT/ICS engineering workstations and the internet, using firewalls and secure remote-access gateways
- Require VPN with strong multi-factor authentication for any remote PLC engineering access
- Deploy integrity monitoring / code-review workflows for reusable PLC program modules and Add-On Instructions (AOIs)
- Maintain offline, periodically-tested backups of PLC project files and configurations
- Enable mobile threat defense (MTD) and restrict sideloading / unknown-sources installs on managed Android fleets
- User awareness training on civil-defense/emergency-alert app spoofing during regional crisis events
Weaknesses (CWE) in ThreatsDay Bulletin
CWE-284, CWE-306, CWE-250, CWE-923
Timeline of ThreatsDay Bulletin
- CyberAv3ngers persona first publicized for defacements of internet-exposed Unitronics PLCs, establishing baseline tradecraft later linked to this campaign
- Earliest activity window for the 12 published malicious IP addresses targeting internet-exposed PLCs begins
- CISA, FBI, EPA, and government partners publish original advisory AA26-097A on Iran-affiliated APT actors exploiting internet-connected OT/PLC devices
- DreamGroup researchers discover the OctagonPanel/Ward RAT 'BH Alert' Android spyware campaign impersonating Bahrain's civil-defense siren app
- Cybersecuritynews.com and Dark Reading publish technical analysis of the fake Bahrain Civil Defense Android RAT campaign
- Bahraini news outlet GDN publishes a public warning about the fake alert app
- FakeAgent malvertising campaign begins redirecting victims to spoofed Claude Artifacts pages delivering SectopRAT via trojanized ClaudeDesktop.exe, ultimately affecting at least 29 organizations
- The Record, WaterISAC, ISSSource, GBHackers, and Rescana publish independent coverage/analysis of the updated CISA advisory
- CISA updates AA26-097A with new guidance for detecting malicious Add-On Instruction (AOI) changes in Rockwell Automation PLC programs, plus the 12-IP IOC list covering the Sept 2025-Jul 2026 window
- The Hacker News publishes the ThreatsDay Bulletin aggregating both the PLC advisory update and the OctagonPanel Android spyware campaign alongside adjacent threats (GhostCommit, MarkiRAT/TAG-182, TrickBot DNS tunneling, SectopRAT/FakeAgent)
Sources cited for ThreatsDay Bulletin
- ThreatsDay Bulletin: Android Spyware, PLC Attacks, and More
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A)
- CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers
- Federal agencies broaden alert on Iran-linked OT attacks
- CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure
- Iranian Hackers Infiltrate Siemens and Schneider PLCs, Blinding Operators With Fake Readings
- (TLP:CLEAR) CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A)
- Iranian Threat Actors Continuing OT Attacks: Feds
- Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices
- Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
- Fake Bahrain Alert App Deploys Android Surveillance Malware
- Bahrain News: Fake alert app warning
- Middle East Hack-for-Hire Operation Traced to South Asian APT Group
Threats related to ThreatsDay Bulletin
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage Payload
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
Detection coverage for TL-2026-1659
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1659 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.