Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
Iran-Linked CyberAv3ngers (BAUXITE) Exploiting (TL-2026-1697), also tracked as AA26-097A Campaign, is a critical-severity ICS/SCADA threat scored CVSS 9.8, first published 2026-07-25. It is attributed to Cyber Av3ngers (Iran) with high confidence, affects Rockwell Automation CompactLogix / Micro850 controllers, references 1 CVE (CVE-2021-22681), maps to 17 MITRE ATT&CK techniques (T1005, T1021, T1041), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-1697
- Threat ID
- TL-2026-1697
- Also known as
- AA26-097A Campaign, Iran-Affiliated PLC Intrusion Campaign 2026
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-07-25
- Last reviewed
- 2026-07-25
- Attribution
- Cyber Av3ngers
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- water and wastewater systems, energy, government facilities and local municipalities
- Target regions
- united states of america
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
Malware and tooling: Intune-enrolled-device wiper (Handala/Stryker, March 2026), Dropbear SSH, EcoStruxure Control Expert, RSLogix 5000, Studio 5000 Logix Designer, TIA Portal
An IRGC Cyber Electronic Command-affiliated actor tracked as CyberAv3ngers (Dragos: BAUXITE; Microsoft: Storm-0784; Mandiant: UNC5691) has, since at least March 2026, compromised internet-exposed Rockwell Automation, Schneider Electric, and Siemens PLCs across US Water and Wastewater Systems, Energy, and Government Facilities sectors, exfiltrating project files, tampering with ladder logic and Add-On Instructions, falsifying HMI/SCADA displays, and disabling shutdown/alarm functions. CISA, FBI, NSA, EPA, DoE, and US Cyber Command jointly issued advisory AA26-097A (April 7, 2026; updated July 22, 2026) documenting the campaign's central vulnerability, CVE-2021-22681 (CVSS 9.8, an unpatchable authentication-bypass in Rockwell Studio 5000/RSLogix 5000), expanding vendor scope, and adding detection guidance for malicious Add-On Instruction changes.
How Iran-Linked CyberAv3ngers (BAUXITE) Exploiting works
Since at least March 2026, an Iranian IRGC Cyber Electronic Command-affiliated actor publicly tracked as CyberAv3ngers — and overlapping substantially with Dragos-designated BAUXITE, Microsoft's Storm-0784, and Mandiant's UNC5691 — has conducted a sustained intrusion campaign against internet-exposed operational technology (OT) in the United States. The actor scans for and connects to Rockwell Automation/Allen-Bradley (CompactLogix, Micro850, and related Logix-family controllers), Schneider Electric (Modicon M340, BMX P34), and Siemens (SIMATIC S7-1200) programmable logic controllers reachable on commonly used OT ports — EtherNet/IP (44818), an alternate OT/configuration port (2222), Siemens S7comm/ISO-TSAP (102), and Modbus TCP (502) — as well as SSH (22) exposed via cellular modems. The predecessor to this campaign is CyberAv3ngers' November 2023 compromise of 75+ internet-exposed Unitronics PLCs using default credentials in the water sector.
The core technique-enabling vulnerability is CVE-2021-22681, a CVSS 9.8 authentication-bypass in Rockwell's RSLogix 5000 (v16-20) and Studio 5000 Logix Designer (v21+), caused by an insufficiently protected cryptographic key used to verify engineering-workstation-to-controller communication (CWE-522). Because the flaw is a design limitation rather than a patchable defect, Rockwell has stated it cannot be fully resolved via software update; CISA added it to the Known Exploited Vulnerabilities catalog on March 5, 2026 with a March 26, 2026 federal remediation deadline. Exploiting this bypass — or simply reaching devices left with default credentials or unrestricted internet exposure — lets the actor authenticate to Logix controllers as if it were a legitimate engineering workstation.
Once connected, the actor uses the vendors' own legitimate engineering software (Studio 5000 Logix Designer for Rockwell, EcoStruxure Control Expert for Schneider Electric, TIA Portal for Siemens) to extract PLC project files (Rockwell's .ACD format, containing ladder logic, Add-On Instructions, and configuration parameters), then modifies or deletes project logic — including reusable Add-On Instruction (AOI) code modules, per the July 22, 2026 advisory update's detection guidance — manipulates HMI/SCADA operator displays to mask true process state, and disables shutdown and alarm functions so that unsafe operational states persist without alerting operators. For persistent remote access, the actor deploys Dropbear, a lightweight open-source SSH server, on victim-adjacent infrastructure. Confirmed victims across the Water and Wastewater Systems, Energy, and Government Services and Facilities sectors have experienced real operational disruption and financial losses. A Censys scan around April 2026 identified 5,200+ internet-exposed Rockwell Automation controllers globally, roughly 3,900 of them in the United States, illustrating the scale of the attack surface.
CISA/FBI/NSA/EPA/DoE/US Cyber Command originally published joint advisory AA26-097A on April 7, 2026 with TTPs and 8 IP-address indicators of compromise tied to overseas hosting infrastructure. The July 22, 2026 update expanded the manufacturer scope beyond Rockwell to explicitly include Schneider Electric and Siemens, expanded the published machine-readable IOC set from 8 to 21 IP addresses, and added specific detection guidance for identifying malicious changes to reusable Rockwell Logix code modules (Add-On Instructions) by comparing running programs against known-good baselines.
This OT-focused campaign is occurring against the backdrop of a broader surge in Iran-affiliated offensive cyber activity following the February 2026 escalation of US-Iran-Israel military tensions. A related but operationally and attributionally distinct persona, Handala (also tracked as Void Manticore/Storm-0842/Banished Kitten, assessed with high confidence as MOIS-affiliated within the Banished Kitten ecosystem), has conducted separate, IT-focused destructive operations in the same period: a March 11, 2026 compromise of Stryker Corporation's Microsoft Intune administrator console that wiped roughly 200,000 enrolled devices across 79 countries (with ~50GB of data reportedly stolen), and a June 12, 2026 claimed breach of California Water Service (Cal Water) — publicly naming Bakersfield, Visalia, and Chico and claiming 5GB of exfiltrated billing data — which independent analysis found was limited to a GPS correction server and customer billing database, with no evidence of OT/ICS compromise. These incidents are documented here as corroborating context for the same Iran-aligned threat ecosystem's capability and escalating intent, not as direct evidence implicating CyberAv3ngers/BAUXITE in the Stryker or Cal Water intrusions.
MITRE ATT&CK techniques used in TL-2026-1697
Collection
Lateral Movement
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1046 Network Service Discovery
Defense Evasion
Command and Control
T1071 Application Layer Protocol; T1571 Non-Standard Port
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
command-and-control
Impact
T1489 Service Stop; T1565 Data Manipulation
Resource Development
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning
defense-impairment
Affected products and versions in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
- Rockwell Automation — CompactLogix / Micro850 controllers
Vulnerable versions: RSLogix 5000 v16-20; Studio 5000 Logix Designer v21 and later
Fixed in: No complete software fix; compensating controls per Rockwell PN1550/SD1771 (network isolation, physical RUN-mode keyswitch, programming-protection key) - Rockwell Automation — ControlLogix / GuardLogix / Compact GuardLogix / SoftLogix / DriveLogix (CVE-2021-22681-affected families)
Vulnerable versions: ControlLogix 5550/5560/5570/5580; GuardLogix 5570/5580; Compact GuardLogix 5370/5380; DriveLogix 5560/5730/1794-L34; SoftLogix 5800; CompactLogix 1768/1769/5370/5380/5480
Fixed in: No complete software fix; compensating controls per Rockwell advisory - Schneider Electric — Modicon M340 / BMX P34 series PLCs
Vulnerable versions: Internet-exposed Modicon M340 and BMX P34 controllers reachable via Modbus TCP/502
Fixed in: Not disclosed in public reporting; vendor guidance is network isolation, EcoStruxure Control Expert access protection, and firmware updates - Siemens — SIMATIC S7-1200 series PLCs
Vulnerable versions: Internet-exposed S7-1200 controllers reachable via S7comm/ISO-TSAP port 102
Fixed in: Not disclosed in public reporting; vendor guidance is TIA Portal access protection and network isolation - Unitronics — Vision-series PLCs (predecessor 2023-2024 campaign)
Vulnerable versions: Devices deployed with default/unchanged credentials
Fixed in: Default-credential change enforced per post-2023 CISA guidance
Remediation for Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
Patches
- No complete software patch exists for CVE-2021-22681 (Rockwell Studio 5000 Logix Designer / RSLogix 5000); apply Rockwell's compensating-control guidance (PN1550, SD1771, 2026)
- Apply the latest available firmware to Schneider Electric Modicon M340/BMX P34 and Siemens SIMATIC S7-1200 controllers per current vendor security bulletins
Immediate actions
- Remove all PLCs and OT devices from direct internet exposure; place behind a secure gateway/firewall requiring VPN access with multi-factor authentication
- Query firewall and network logs against the 21 IP-address indicators published in the July 22, 2026 AA26-097A update (expanded from the original 8) across the applicable observation windows, vetting each address before taking blocking action
- Set Rockwell Logix controller physical/keyswitch mode switches to RUN to block remote logic changes
- Change all default and vendor-preset credentials on PLCs, HMIs, engineering workstations, and remote-access/cellular-modem equipment
- Disable or firewall unused remote-access services (SSH/22, Telnet/23, VNC/5900, FTP/21) on OT-facing assets
Workarounds
- Enable Rockwell Studio 5000/RSLogix programming-protection (software key-switch) to require authenticated engineering access
- Enable Siemens TIA Portal access protection and Schneider EcoStruxure Control Expert application password protection
- Validate PLC project files and Add-On Instructions against known-good baselines before returning controllers to RUN mode after any maintenance or engineering connection
Longer-term hardening
- Segment OT networks from IT/corporate networks and from the public internet; disable direct-to-internet cellular-modem paths where operationally unnecessary
- Deploy continuous OT network monitoring for anomalous engineering-workstation connections, project-file interactions, and protocol activity on ports 44818, 2222, 102, and 502
- Establish and maintain offline, verified-good baselines of PLC ladder logic and Add-On Instructions to detect drift/tampering, per the July 2026 AA26-097A detection guidance
- Enforce MFA and least-privilege access for all remote engineering, vendor-support, and third-party service-provider connections
- Coordinate with PLC/HMI vendors (Rockwell Automation, Schneider Electric, Siemens) and sector ISACs (WaterISAC, E-ISAC) for updated IOC feeds and detection signatures
CVEs associated with Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
Weaknesses (CWE) in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
CWE-522
Timeline of Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
- CyberAv3ngers (later cross-tracked as Dragos BAUXITE, Microsoft Storm-0784, Mandiant UNC5691) emerges as an IRGC Cyber Electronic Command-affiliated persona, active since at least 2020 per Tenable and Dragos reporting.
- CVE-2021-22681, a CVSS 9.8 authentication-bypass affecting Rockwell RSLogix 5000 (v16-20) and Studio 5000 Logix Designer (v21+), is disclosed; CISA publishes ICS advisory ICSA-21-056-03.
- CyberAv3ngers compromises 75+ internet-exposed Unitronics PLCs in the US water sector using default credentials, establishing the technical and sectoral precedent for the current campaign.
- US-Iran-Israel military tensions escalate, driving a broader surge in Iran-affiliated offensive cyber activity against US targets.
- Confirmed compromises begin in the current campaign against internet-exposed Rockwell, Schneider Electric, and Siemens PLCs across US water, energy, and government-facilities sectors.
- CISA adds CVE-2021-22681 to the Known Exploited Vulnerabilities catalog, setting a March 26, 2026 mandatory federal remediation deadline.
- Pro-Iranian persona Handala (Void Manticore/Storm-0842/Banished Kitten) compromises Stryker Corporation's Microsoft Intune administrator console and wipes roughly 200,000 enrolled devices across 79 countries — a distinct, IT-focused operation within the same broader Iran-aligned threat ecosystem.
- A Censys internet scan identifies 5,200+ internet-exposed Rockwell Automation controllers globally, approximately 3,900 of them located in the United States.
- CISA, FBI, NSA, EPA, DoE, and US Cyber Command jointly publish the original AA26-097A advisory, detailing TTPs and 8 IP-address indicators of compromise for the PLC exploitation campaign.
- Handala publicly claims a breach of California Water Service (Bakersfield, Visalia, Chico), publishing billing-system screenshots and claiming 5GB exfiltrated; independent analysis finds the intrusion limited to a GPS correction server and billing database with no OT/ICS impact.
- CISA updates AA26-097A: expands manufacturer scope to explicitly include Schneider Electric and Siemens, adds detection guidance for malicious Add-On Instruction changes in Rockwell Logix programs, and expands the published machine-readable IOC set from 8 to 21 IP addresses.
- SecurityAffairs reports on the updated advisory and the ongoing campaign, prompting this Threadlinqs Intelligence hunt entry.
Sources cited for Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
- SecurityAffairs: Iran-linked actors breach and are targeting US water and energy control systems
- CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
- WaterISAC: CISA Updates Iranian-Affiliated PLC Targeting Advisory (AA26-097A)
- Picus Security: CISA Alert AA26-097A — Iranian-Affiliated Actors Target PLCs Across US Critical Infrastructure: Analysis, Simulation, and Mitigation
- Rescana: Active Exploitation Alert — Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric, and Rockwell Automation ICS Devices
- 1898 & Co. (Burns & McDonnell): July 2026 Update — Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers
- CISA ICS Advisory ICSA-21-056-03: Rockwell Automation Logix Controllers (Update A)
- NVD: CVE-2021-22681 Detail
- Dragos: BAUXITE Threat Group Profile
- Tenable: CyberAv3ngers FAQ About Iran-Linked Threat Group Targeting U.S. Critical Infrastructure
- CybelAngel: Iranian Threat Actors Target US Critical Infrastructure
- Industrial Cyber: Iran-linked Handala group targets Cal Water, exposing potential pathways between IT and OT environments
- SecurityAffairs: Iran-Linked Handala Breached a California Water Utility
- TechCrunch: US government says Iran-linked hackers are disrupting American water and energy providers
- Krebs on Security: Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
Threats related to Iran-Linked CyberAv3ngers (BAUXITE) Exploiting
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A)
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines
Detection coverage for TL-2026-1697
As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1697 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.