Threat reportICS/SCADATL-2026-2961

OT Attacks on US Critical Infrastructure: Volt Typhoon Persistence and Iranian-Affiliated PLC Exploitation (Rockwell, Unitronics, Siemens S7)

criticalACTIVE

OT Attacks on US Critical Infrastructure (TL-2026-2961), also tracked as AA26-097A, is a critical-severity ICS/SCADA threat, first published 2026-10-06. It is attributed to Volt Typhoon - G1017 (China, Iran) with medium confidence, affects Rockwell Automation Allen-Bradley CompactLogix / Micro850 / MicroLogix, references 1 CVE (CVE-2021-22681), maps to 9 MITRE ATT&CK techniques (T0893, T1003.003, T1021.001), and is covered by 9 detection rules and 12 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
1Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
2Volt Typhoon - G1017
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-2961

Threat ID
TL-2026-2961
Also known as
AA26-097A, AA26-231A, AA24-038A, Minnesota water utility attacks
Severity
CRITICAL
Status
ACTIVE
Category
ICS_SCADA
First published
Last reviewed
Attribution
Volt Typhoon - G1017, Cyber Av3ngers
Attribution confidence
MEDIUM
Nation-state nexus
China, Iran
Motivation
DESTRUCTION
Target sectors
water-wastewater, energy, government administration, critical-manufacturing, chemical, food-agriculture, commercial-facilities, defense-industrial-base, communications, transport
Target regions
North America, united states of america, guam
Detection rules
9
Indicators of compromise
12

Malware and tooling in OT Attacks on US Critical Infrastructure

Malware and tooling: IOControl, KV-Botnet, FRP - S1144, Fast Reverse Proxy (FRP), Mimikatz, Studio 5000 Logix Designer

How OT Attacks on US Critical Infrastructure works

Joint US government advisories (AA24-038A, AA26-097A updated 2026-07-22, AA26-231A) document multi-actor targeting of US critical-infrastructure OT: Volt Typhoon persistence of at least five years, Iranian-affiliated CyberAv3ngers manipulation of internet-exposed Rockwell/Allen-Bradley PLCs, and an unattributed AI-assisted reconnaissance campaign against Siemens S7 PLCs. Coordinated attacks on 30+ Minnesota water utilities on 2026-07-26/27 (seven states overall) caused loss of control, boil-water notices and forced manual operations.

This record consolidates the OT-focused activity summarized by GBHackers on 2026-10-06 and traces it to the primary government advisories.

Volt Typhoon (PRC state-sponsored, active since at least 2021): CISA/NSA/FBI advisory AA24-038A documents confirmed cases in which actors maintained footholds in victim IT environments for at least five years. Access is gained by exploiting public-facing network appliances (Fortinet, Ivanti, NETGEAR, Citrix, Cisco) and then sustained with valid administrator credentials and living-off-the-land binaries (vssadmin, ntdsutil, wmic, PowerShell, comsvcs.dll for LSASS dumping), RDP to domain controllers, Fast Reverse Proxy (FRP) and Mimikatz, with traffic proxied through compromised SOHO routers (KV Botnet). The activity is assessed as pre-positioning for lateral movement into OT assets for possible disruptive effects. Two SHA-256 hashes are attributed to Volt Typhoon in the GBHackers article.

Iranian-affiliated CyberAv3ngers (aka Shahid Kaveh Group, Storm-0784, UNC5691, Hydro Kitten; IRGC Cyber-Electronic Command): joint advisory AA26-097A (2026-04-07, updated 2026-07-22) by FBI, CISA, NSA, EPA, DOE and US Cyber Command describes exploitation of internet-facing Rockwell Automation/Allen-Bradley CompactLogix and Micro850 PLCs from overseas and leased infrastructure, using Rockwell's legitimate Studio 5000 Logix Designer to interact with project files and manipulate HMI/SCADA displays, causing operational disruption and, in some cases, financial loss. The 2026-07-22 update widened scope to Schneider Electric and Siemens PLCs, documented project-file exfiltration for the first time, and added detection guidance for manipulation of reusable code modules in PLC programs. Earlier activity includes the November 2023 compromise of 75+ Unitronics devices and the 2024 IOControl malware. Two further SHA-256 hashes are attributed to CyberAv3ngers in the GBHackers article. The article distinguishes earlier CyberAv3ngers activity from the 2026 campaign and does not support unqualified attribution of every 2026 incident.

Water-sector attacks: on 2026-07-26/27 a coordinated attack hit more than 30 community water systems in Minnesota (Braham, Plymouth, South St. Paul and Maple Plain publicly disclosed); at least seven states reported incidents. FBI/EPA reporting says internet-facing Rockwell MicroLogix 1100/1400 PLCs were accessed, with IP addresses and passwords changed to lock out operators, and in at least one case PLC project files/ladder logic were modified, which a password reset does not undo. Impacts included pressure loss and flooding at some sites, boil-water notices and sustained manual operation; Braham's water plant went offline. Undocumented vendor/integrator cellular modems were a noted exposure path. US agencies have not formally attributed the Minnesota attacks; Tenable assesses the pattern is consistent with CyberAv3ngers. Some vendor coverage associates CVE-2021-22681 (Rockwell Logix authentication bypass, CVSS 9.8) with this activity; other analysis notes MicroLogix 1100/1400 are not on that CVE's affected list, so the CVE is recorded as related context, not a confirmed exploit path.

Siemens S7 campaign: advisory AA26-231A (2026-08-19; NSA, CISA, FBI, DOE, EPA) describes unattributed reconnaissance and capability development against US-based Siemens S7-200/300/400/1200/1500 PLCs. Actors find exposed devices through Censys and ZoomEye, then use AI-generated Python scripts built on the open-source snap7.dll / python-snap7 libraries, disguised as monitoring tools, to speak S7comm over TCP/102 and read/write PLC memory, configuration and ladder logic. Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, Commercial Facilities, Defense Industrial Base. The advisory publishes no IP or hash IOCs.

Defensive priorities: remove PLCs from direct internet exposure, broker remote access through monitored gateways with MFA, block TCP/102 at the perimeter, set PLC passwords and protection levels, keep tested offline controller backups, use physical run-mode switches, and monitor for unexpected engineering connections, S7comm from non-engineering hosts, and unauthorized program downloads.

MITRE ATT&CK techniques used in TL-2026-2961

Collection

T0893 Data from Local System

Credential Access

T1003.003 OS Credential Dumping: NTDS

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1078 Valid Accounts

Command and Control

T1090.003 Proxy: Multi-hop Proxy

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1587.004 Develop Capabilities: Exploits; T1588.007 Obtain Capabilities: Artificial Intelligence

Reconnaissance

T1596.005 Search Open Technical Databases: Scan Databases

Affected products and versions in OT Attacks on US Critical Infrastructure

  • Rockwell Automation — Allen-Bradley CompactLogix / Micro850 / MicroLogix 1100 and 1400
    Vulnerable versions: Internet-exposed, weakly authenticated controllers
  • Siemens — SIMATIC S7-200 / S7-300 / S7-400 / S7-1200 / S7-1500
    Vulnerable versions: Internet-exposed controllers with S7comm on TCP/102 and outdated or unprotected configuration
  • Unitronics — Vision-series PLCs
    Vulnerable versions: Internet-exposed controllers with default credentials (2023 campaign)
  • Schneider Electric — Modicon M340 (BMX P34)
    Vulnerable versions: Internet-exposed controllers named in the 2026-07-22 AA26-097A update

Remediation for OT Attacks on US Critical Infrastructure

Patches

  • Apply Rockwell, Siemens and Schneider Electric vendor guidance; apply fixes for exposed network appliances exploited by Volt Typhoon

Immediate actions

  • Remove PLCs from direct internet exposure; inventory all internet-facing controllers
  • Block TCP/102 (S7comm) and restrict 44818, 502, 20000 at the perimeter
  • Change default credentials, enable PLC password protection and protection levels
  • Validate all external connections, including undocumented cellular modems

Workarounds

  • Disable PLC web servers and unneeded protocols
  • Limit simultaneous S7comm sessions
  • Enable TIA Portal know-how protection

Longer-term hardening

  • Broker remote OT access through monitored gateways with MFA and IP allowlisting
  • Segment OT from IT and deploy ICS-aware S7comm/EtherNet/IP monitoring
  • Maintain tested offline controller logic backups and rehearse manual operation
  • Use physical run-mode key switches to block remote program changes

CVEs associated with OT Attacks on US Critical Infrastructure

CVE-2021-22681

Weaknesses (CWE) in OT Attacks on US Critical Infrastructure

CWE-306, CWE-798

Timeline of OT Attacks on US Critical Infrastructure

  • Volt Typhoon (PRC state-sponsored) is active against US critical infrastructure from at least 2021; AA24-038A later documents footholds maintained for at least five years in some victim IT environments
  • CyberAv3ngers compromises 75+ internet-exposed Unitronics PLCs in an earlier campaign
  • CISA, NSA, FBI and partners publish AA24-038A on Volt Typhoon living-off-the-land persistence in critical infrastructure
  • FBI, CISA, NSA, EPA, DOE and US Cyber Command publish AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell/Allen-Bradley CompactLogix and Micro850 PLCs via Studio 5000 Logix Designer
  • AA26-097A updated: scope widened to Schneider Electric and Siemens PLCs, first documented project-file exfiltration, new detection guidance for manipulated reusable PLC code modules
  • Coordinated attacks on 30+ Minnesota community water utilities (26-27 July) and incidents in at least seven states; PLC passwords and IPs changed, causing pressure loss, flooding at some sites, boil-water notices and manual operation
  • CISA and FBI/EPA urge utilities to remove internet-exposed PLCs immediately; attribution not formally confirmed
  • NSA, CISA, FBI, DOE and EPA publish AA26-231A warning of AI-assisted reconnaissance and capability development against US Siemens S7 PLCs using snap7/python-snap7 over TCP/102
  • GBHackers reports on OT attacks that could disrupt military operations and physical processes, listing four SHA-256 hashes tied to Volt Typhoon and CyberAv3ngers

Sources cited for OT Attacks on US Critical Infrastructure

Detection coverage for TL-2026-2961

As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2961 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats