Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A) — Threadlinqs Intelligence
As of 2026-07-25, Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A) is a critical-severity ics scada threat attributed to Cyber Av3ngers (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-1697 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: ICS_SCADA
Attribution: Cyber Av3ngers · Iran · DESTRUCTION
An IRGC Cyber Electronic Command-affiliated actor tracked as CyberAv3ngers (Dragos: BAUXITE; Microsoft: Storm-0784; Mandiant: UNC5691) has, since at least March 2026, compromised internet-exposed
Since at least March 2026, an Iranian IRGC Cyber Electronic Command-affiliated actor publicly tracked as CyberAv3ngers — and overlapping substantially with Dragos-designated BAUXITE, Microsoft's Storm-0784, and Mandiant's UNC5691 — has conducted a sustained intrusion campaign against internet-exposed operational technology (OT) in the United States. The actor scans for and connects to Rockwell Automation/Allen-Bradley (CompactLogix, Micro850, and related Logix-family controllers), Schneider Electric (Modicon M340, BMX P34), and Siemens (SIMATIC S7-1200) programmable logic controllers reachable on commonly used OT ports — EtherNet/IP (44818), an alternate OT/configuration port (2222), Siemens S7comm/ISO-TSAP (102), and Modbus TCP (502) — as well as SSH (22) exposed via cellular modems. The predecessor to this campaign is CyberAv3ngers' November 2023 compromise of 75+ internet-exposed Unitronics PLCs using default credentials in the water sector.
The core technique-enabling vulnerability is CVE-2021-22681, a CVSS 9.8 authentication-bypass in Rockwell's RSLogix 5000 (v16-20) and Studio 5000 Logix Designer (v21+), caused by an insufficiently protected cryptographic key used to verify engineering-workstation-to-controller communication (CWE-522). Because the flaw is a design limitation rather than a patchable defect, Rockwell has stated it cannot be fully resolved via software update; CISA added it to the Known Exploited Vulnerabilities catalog on March 5, 2026 with a March 26, 2026 federal remediation deadline. Exploiting this bypass — or simply reaching devices left with default credentials or unrestricted internet exposure — lets the actor authenticate to Logix controllers as if it were a legitimate engineering workstation.
Once connected, the actor uses the vendors' own legitimate engineering software (Studio 5000 Logix Designer for Rockwell, EcoStruxure Control Expert for Schneider Electric, TIA Portal for Siemens) to extract PLC project files (Rockwell's .ACD format, containing ladder logic, Add-On Instructions, and configuration parameters), then modifies or deletes project logic — including reusable Add-On Instruction (AOI) code modules, per the July 22, 2026 advisory update's detection guidance — manipulates HMI/SCADA operator displays to mask true process state, and disables shutdown and alarm functions so that unsafe operational states persist without alerting operators. For persistent remote access, the actor deploys Dropbear, a lightweight open-source SSH server, on victim-adjacent infrastructure. Confirmed victims across the Water and Wastewater Systems, Energy, and Government Services and Facilities sectors have experienced real operational disruption and financial losses. A Censys scan around April 2026 identified 5,200+ internet-exposed Rockwell Automation controllers globally, roughly 3,900 of them in the United States, illustrating the scale of the attack surface.
CISA/FBI/NSA/EPA/DoE/US Cyber Command originally published joint advisory AA26-097A on April 7, 2026 with TTPs and 8 IP-address indicators of compromise tied to overseas hosting infrastructure. The July 22, 2026 update expanded the manufacturer scope beyond Rockwell to explicitly include Schneider Electric and Siemens, expanded the published machine-readable IOC set from 8 to 21 IP addresses, and added specific detection guidance for identifying malicious changes to reusable Rockwell Logix code modules (Add-On Instructions) by comparing running programs against known-good baselines.
This OT-focused campaign is occurring against the backdrop of a broader surge in Iran-affiliated offensive cyber activity following the February 2026 escalation of US-Iran-Israel military tensions. A related but operationally and attributionally distinct persona, Handala (also tracked as Void Manticore/Storm-0842/Banished Kitten, assessed with high confidence as MOIS-affiliated within the Banished Kitten ecosystem), has conducted separate, IT-focused destructive operatio
Target sectors: water and wastewater systems, energy, government facilities and local municipalities
Target regions: united states of america
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, CRITICAL, threat intelligence, cybersecurity, CVE-2021-22681, T1595, T1592, T1583, T1190, T1133, T1078, T1219, T1562, T1070, T1046