Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)

Iran-Linked CyberAv3ngers (BAUXITE) Exploiting (TL-2026-1697), also tracked as AA26-097A Campaign, is a critical-severity ICS/SCADA threat scored CVSS 9.8, first published 2026-07-25. It is attributed to Cyber Av3ngers (Iran) with high confidence, affects Rockwell Automation CompactLogix / Micro850 controllers, references 1 CVE (CVE-2021-22681), maps to 17 MITRE ATT&CK techniques (T1005, T1021, T1041), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-1697

Threat ID
TL-2026-1697
Also known as
AA26-097A Campaign, Iran-Affiliated PLC Intrusion Campaign 2026
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
ICS_SCADA
First published
2026-07-25
Last reviewed
2026-07-25
Attribution
Cyber Av3ngers
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
water and wastewater systems, energy, government facilities and local municipalities
Target regions
united states of america
Detection rules
9
Indicators of compromise
23

Malware and tooling in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

Malware and tooling: Intune-enrolled-device wiper (Handala/Stryker, March 2026), Dropbear SSH, EcoStruxure Control Expert, RSLogix 5000, Studio 5000 Logix Designer, TIA Portal

An IRGC Cyber Electronic Command-affiliated actor tracked as CyberAv3ngers (Dragos: BAUXITE; Microsoft: Storm-0784; Mandiant: UNC5691) has, since at least March 2026, compromised internet-exposed Rockwell Automation, Schneider Electric, and Siemens PLCs across US Water and Wastewater Systems, Energy, and Government Facilities sectors, exfiltrating project files, tampering with ladder logic and Add-On Instructions, falsifying HMI/SCADA displays, and disabling shutdown/alarm functions. CISA, FBI, NSA, EPA, DoE, and US Cyber Command jointly issued advisory AA26-097A (April 7, 2026; updated July 22, 2026) documenting the campaign's central vulnerability, CVE-2021-22681 (CVSS 9.8, an unpatchable authentication-bypass in Rockwell Studio 5000/RSLogix 5000), expanding vendor scope, and adding detection guidance for malicious Add-On Instruction changes.

How Iran-Linked CyberAv3ngers (BAUXITE) Exploiting works

Since at least March 2026, an Iranian IRGC Cyber Electronic Command-affiliated actor publicly tracked as CyberAv3ngers — and overlapping substantially with Dragos-designated BAUXITE, Microsoft's Storm-0784, and Mandiant's UNC5691 — has conducted a sustained intrusion campaign against internet-exposed operational technology (OT) in the United States. The actor scans for and connects to Rockwell Automation/Allen-Bradley (CompactLogix, Micro850, and related Logix-family controllers), Schneider Electric (Modicon M340, BMX P34), and Siemens (SIMATIC S7-1200) programmable logic controllers reachable on commonly used OT ports — EtherNet/IP (44818), an alternate OT/configuration port (2222), Siemens S7comm/ISO-TSAP (102), and Modbus TCP (502) — as well as SSH (22) exposed via cellular modems. The predecessor to this campaign is CyberAv3ngers' November 2023 compromise of 75+ internet-exposed Unitronics PLCs using default credentials in the water sector.

The core technique-enabling vulnerability is CVE-2021-22681, a CVSS 9.8 authentication-bypass in Rockwell's RSLogix 5000 (v16-20) and Studio 5000 Logix Designer (v21+), caused by an insufficiently protected cryptographic key used to verify engineering-workstation-to-controller communication (CWE-522). Because the flaw is a design limitation rather than a patchable defect, Rockwell has stated it cannot be fully resolved via software update; CISA added it to the Known Exploited Vulnerabilities catalog on March 5, 2026 with a March 26, 2026 federal remediation deadline. Exploiting this bypass — or simply reaching devices left with default credentials or unrestricted internet exposure — lets the actor authenticate to Logix controllers as if it were a legitimate engineering workstation.

Once connected, the actor uses the vendors' own legitimate engineering software (Studio 5000 Logix Designer for Rockwell, EcoStruxure Control Expert for Schneider Electric, TIA Portal for Siemens) to extract PLC project files (Rockwell's .ACD format, containing ladder logic, Add-On Instructions, and configuration parameters), then modifies or deletes project logic — including reusable Add-On Instruction (AOI) code modules, per the July 22, 2026 advisory update's detection guidance — manipulates HMI/SCADA operator displays to mask true process state, and disables shutdown and alarm functions so that unsafe operational states persist without alerting operators. For persistent remote access, the actor deploys Dropbear, a lightweight open-source SSH server, on victim-adjacent infrastructure. Confirmed victims across the Water and Wastewater Systems, Energy, and Government Services and Facilities sectors have experienced real operational disruption and financial losses. A Censys scan around April 2026 identified 5,200+ internet-exposed Rockwell Automation controllers globally, roughly 3,900 of them in the United States, illustrating the scale of the attack surface.

CISA/FBI/NSA/EPA/DoE/US Cyber Command originally published joint advisory AA26-097A on April 7, 2026 with TTPs and 8 IP-address indicators of compromise tied to overseas hosting infrastructure. The July 22, 2026 update expanded the manufacturer scope beyond Rockwell to explicitly include Schneider Electric and Siemens, expanded the published machine-readable IOC set from 8 to 21 IP addresses, and added specific detection guidance for identifying malicious changes to reusable Rockwell Logix code modules (Add-On Instructions) by comparing running programs against known-good baselines.

This OT-focused campaign is occurring against the backdrop of a broader surge in Iran-affiliated offensive cyber activity following the February 2026 escalation of US-Iran-Israel military tensions. A related but operationally and attributionally distinct persona, Handala (also tracked as Void Manticore/Storm-0842/Banished Kitten, assessed with high confidence as MOIS-affiliated within the Banished Kitten ecosystem), has conducted separate, IT-focused destructive operations in the same period: a March 11, 2026 compromise of Stryker Corporation's Microsoft Intune administrator console that wiped roughly 200,000 enrolled devices across 79 countries (with ~50GB of data reportedly stolen), and a June 12, 2026 claimed breach of California Water Service (Cal Water) — publicly naming Bakersfield, Visalia, and Chico and claiming 5GB of exfiltrated billing data — which independent analysis found was limited to a GPS correction server and customer billing database, with no evidence of OT/ICS compromise. These incidents are documented here as corroborating context for the same Iran-aligned threat ecosystem's capability and escalating intent, not as direct evidence implicating CyberAv3ngers/BAUXITE in the Stryker or Cal Water intrusions.

MITRE ATT&CK techniques used in TL-2026-1697

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1046 Network Service Discovery

Defense Evasion

T1070 Indicator Removal

Command and Control

T1071 Application Layer Protocol; T1571 Non-Standard Port

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

command-and-control

T1219 Remote Access Tools

Impact

T1489 Service Stop; T1565 Data Manipulation

Resource Development

T1583 Acquire Infrastructure

Reconnaissance

T1592 Gather Victim Host Information; T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

  • Rockwell Automation — CompactLogix / Micro850 controllers
    Vulnerable versions: RSLogix 5000 v16-20; Studio 5000 Logix Designer v21 and later
    Fixed in: No complete software fix; compensating controls per Rockwell PN1550/SD1771 (network isolation, physical RUN-mode keyswitch, programming-protection key)
  • Rockwell Automation — ControlLogix / GuardLogix / Compact GuardLogix / SoftLogix / DriveLogix (CVE-2021-22681-affected families)
    Vulnerable versions: ControlLogix 5550/5560/5570/5580; GuardLogix 5570/5580; Compact GuardLogix 5370/5380; DriveLogix 5560/5730/1794-L34; SoftLogix 5800; CompactLogix 1768/1769/5370/5380/5480
    Fixed in: No complete software fix; compensating controls per Rockwell advisory
  • Schneider Electric — Modicon M340 / BMX P34 series PLCs
    Vulnerable versions: Internet-exposed Modicon M340 and BMX P34 controllers reachable via Modbus TCP/502
    Fixed in: Not disclosed in public reporting; vendor guidance is network isolation, EcoStruxure Control Expert access protection, and firmware updates
  • Siemens — SIMATIC S7-1200 series PLCs
    Vulnerable versions: Internet-exposed S7-1200 controllers reachable via S7comm/ISO-TSAP port 102
    Fixed in: Not disclosed in public reporting; vendor guidance is TIA Portal access protection and network isolation
  • Unitronics — Vision-series PLCs (predecessor 2023-2024 campaign)
    Vulnerable versions: Devices deployed with default/unchanged credentials
    Fixed in: Default-credential change enforced per post-2023 CISA guidance

Remediation for Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

Patches

  • No complete software patch exists for CVE-2021-22681 (Rockwell Studio 5000 Logix Designer / RSLogix 5000); apply Rockwell's compensating-control guidance (PN1550, SD1771, 2026)
  • Apply the latest available firmware to Schneider Electric Modicon M340/BMX P34 and Siemens SIMATIC S7-1200 controllers per current vendor security bulletins

Immediate actions

  • Remove all PLCs and OT devices from direct internet exposure; place behind a secure gateway/firewall requiring VPN access with multi-factor authentication
  • Query firewall and network logs against the 21 IP-address indicators published in the July 22, 2026 AA26-097A update (expanded from the original 8) across the applicable observation windows, vetting each address before taking blocking action
  • Set Rockwell Logix controller physical/keyswitch mode switches to RUN to block remote logic changes
  • Change all default and vendor-preset credentials on PLCs, HMIs, engineering workstations, and remote-access/cellular-modem equipment
  • Disable or firewall unused remote-access services (SSH/22, Telnet/23, VNC/5900, FTP/21) on OT-facing assets

Workarounds

  • Enable Rockwell Studio 5000/RSLogix programming-protection (software key-switch) to require authenticated engineering access
  • Enable Siemens TIA Portal access protection and Schneider EcoStruxure Control Expert application password protection
  • Validate PLC project files and Add-On Instructions against known-good baselines before returning controllers to RUN mode after any maintenance or engineering connection

Longer-term hardening

  • Segment OT networks from IT/corporate networks and from the public internet; disable direct-to-internet cellular-modem paths where operationally unnecessary
  • Deploy continuous OT network monitoring for anomalous engineering-workstation connections, project-file interactions, and protocol activity on ports 44818, 2222, 102, and 502
  • Establish and maintain offline, verified-good baselines of PLC ladder logic and Add-On Instructions to detect drift/tampering, per the July 2026 AA26-097A detection guidance
  • Enforce MFA and least-privilege access for all remote engineering, vendor-support, and third-party service-provider connections
  • Coordinate with PLC/HMI vendors (Rockwell Automation, Schneider Electric, Siemens) and sector ISACs (WaterISAC, E-ISAC) for updated IOC feeds and detection signatures

CVEs associated with Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

CVE-2021-22681

Weaknesses (CWE) in Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

CWE-522

Timeline of Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

  • CyberAv3ngers (later cross-tracked as Dragos BAUXITE, Microsoft Storm-0784, Mandiant UNC5691) emerges as an IRGC Cyber Electronic Command-affiliated persona, active since at least 2020 per Tenable and Dragos reporting.
  • CVE-2021-22681, a CVSS 9.8 authentication-bypass affecting Rockwell RSLogix 5000 (v16-20) and Studio 5000 Logix Designer (v21+), is disclosed; CISA publishes ICS advisory ICSA-21-056-03.
  • CyberAv3ngers compromises 75+ internet-exposed Unitronics PLCs in the US water sector using default credentials, establishing the technical and sectoral precedent for the current campaign.
  • US-Iran-Israel military tensions escalate, driving a broader surge in Iran-affiliated offensive cyber activity against US targets.
  • Confirmed compromises begin in the current campaign against internet-exposed Rockwell, Schneider Electric, and Siemens PLCs across US water, energy, and government-facilities sectors.
  • CISA adds CVE-2021-22681 to the Known Exploited Vulnerabilities catalog, setting a March 26, 2026 mandatory federal remediation deadline.
  • Pro-Iranian persona Handala (Void Manticore/Storm-0842/Banished Kitten) compromises Stryker Corporation's Microsoft Intune administrator console and wipes roughly 200,000 enrolled devices across 79 countries — a distinct, IT-focused operation within the same broader Iran-aligned threat ecosystem.
  • A Censys internet scan identifies 5,200+ internet-exposed Rockwell Automation controllers globally, approximately 3,900 of them located in the United States.
  • CISA, FBI, NSA, EPA, DoE, and US Cyber Command jointly publish the original AA26-097A advisory, detailing TTPs and 8 IP-address indicators of compromise for the PLC exploitation campaign.
  • Handala publicly claims a breach of California Water Service (Bakersfield, Visalia, Chico), publishing billing-system screenshots and claiming 5GB exfiltrated; independent analysis finds the intrusion limited to a GPS correction server and billing database with no OT/ICS impact.
  • CISA updates AA26-097A: expands manufacturer scope to explicitly include Schneider Electric and Siemens, adds detection guidance for malicious Add-On Instruction changes in Rockwell Logix programs, and expands the published machine-readable IOC set from 8 to 21 IP addresses.
  • SecurityAffairs reports on the updated advisory and the ongoing campaign, prompting this Threadlinqs Intelligence hunt entry.

Sources cited for Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

Threats related to Iran-Linked CyberAv3ngers (BAUXITE) Exploiting

Detection coverage for TL-2026-1697

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1697 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats