Threat reportICS/SCADATL-2026-2961
OT Attacks on US Critical Infrastructure: Volt Typhoon Persistence and Iranian-Affiliated PLC Exploitation (Rockwell, Unitronics, Siemens S7)
OT Attacks on US Critical Infrastructure (TL-2026-2961), also tracked as AA26-097A, is a critical-severity ICS/SCADA threat, first published 2026-10-06. It is attributed to Volt Typhoon - G1017 (China, Iran) with medium confidence, affects Rockwell Automation Allen-Bradley CompactLogix / Micro850 / MicroLogix, references 1 CVE (CVE-2021-22681), maps to 9 MITRE ATT&CK techniques (T0893, T1003.003, T1021.001), and is covered by 9 detection rules and 12 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 2Volt Typhoon - G1017
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-2961
- Threat ID
- TL-2026-2961
- Also known as
- AA26-097A, AA26-231A, AA24-038A, Minnesota water utility attacks
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- Last reviewed
- Attribution
- Volt Typhoon - G1017, Cyber Av3ngers
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China, Iran
- Motivation
- DESTRUCTION
- Target sectors
- water-wastewater, energy, government administration, critical-manufacturing, chemical, food-agriculture, commercial-facilities, defense-industrial-base, communications, transport
- Target regions
- North America, united states of america, guam
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in OT Attacks on US Critical Infrastructure
Malware and tooling: IOControl, KV-Botnet, FRP - S1144, Fast Reverse Proxy (FRP), Mimikatz, Studio 5000 Logix Designer
How OT Attacks on US Critical Infrastructure works
Joint US government advisories (AA24-038A, AA26-097A updated 2026-07-22, AA26-231A) document multi-actor targeting of US critical-infrastructure OT: Volt Typhoon persistence of at least five years, Iranian-affiliated CyberAv3ngers manipulation of internet-exposed Rockwell/Allen-Bradley PLCs, and an unattributed AI-assisted reconnaissance campaign against Siemens S7 PLCs. Coordinated attacks on 30+ Minnesota water utilities on 2026-07-26/27 (seven states overall) caused loss of control, boil-water notices and forced manual operations.
This record consolidates the OT-focused activity summarized by GBHackers on 2026-10-06 and traces it to the primary government advisories.
Volt Typhoon (PRC state-sponsored, active since at least 2021): CISA/NSA/FBI advisory AA24-038A documents confirmed cases in which actors maintained footholds in victim IT environments for at least five years. Access is gained by exploiting public-facing network appliances (Fortinet, Ivanti, NETGEAR, Citrix, Cisco) and then sustained with valid administrator credentials and living-off-the-land binaries (vssadmin, ntdsutil, wmic, PowerShell, comsvcs.dll for LSASS dumping), RDP to domain controllers, Fast Reverse Proxy (FRP) and Mimikatz, with traffic proxied through compromised SOHO routers (KV Botnet). The activity is assessed as pre-positioning for lateral movement into OT assets for possible disruptive effects. Two SHA-256 hashes are attributed to Volt Typhoon in the GBHackers article.
Iranian-affiliated CyberAv3ngers (aka Shahid Kaveh Group, Storm-0784, UNC5691, Hydro Kitten; IRGC Cyber-Electronic Command): joint advisory AA26-097A (2026-04-07, updated 2026-07-22) by FBI, CISA, NSA, EPA, DOE and US Cyber Command describes exploitation of internet-facing Rockwell Automation/Allen-Bradley CompactLogix and Micro850 PLCs from overseas and leased infrastructure, using Rockwell's legitimate Studio 5000 Logix Designer to interact with project files and manipulate HMI/SCADA displays, causing operational disruption and, in some cases, financial loss. The 2026-07-22 update widened scope to Schneider Electric and Siemens PLCs, documented project-file exfiltration for the first time, and added detection guidance for manipulation of reusable code modules in PLC programs. Earlier activity includes the November 2023 compromise of 75+ Unitronics devices and the 2024 IOControl malware. Two further SHA-256 hashes are attributed to CyberAv3ngers in the GBHackers article. The article distinguishes earlier CyberAv3ngers activity from the 2026 campaign and does not support unqualified attribution of every 2026 incident.
Water-sector attacks: on 2026-07-26/27 a coordinated attack hit more than 30 community water systems in Minnesota (Braham, Plymouth, South St. Paul and Maple Plain publicly disclosed); at least seven states reported incidents. FBI/EPA reporting says internet-facing Rockwell MicroLogix 1100/1400 PLCs were accessed, with IP addresses and passwords changed to lock out operators, and in at least one case PLC project files/ladder logic were modified, which a password reset does not undo. Impacts included pressure loss and flooding at some sites, boil-water notices and sustained manual operation; Braham's water plant went offline. Undocumented vendor/integrator cellular modems were a noted exposure path. US agencies have not formally attributed the Minnesota attacks; Tenable assesses the pattern is consistent with CyberAv3ngers. Some vendor coverage associates CVE-2021-22681 (Rockwell Logix authentication bypass, CVSS 9.8) with this activity; other analysis notes MicroLogix 1100/1400 are not on that CVE's affected list, so the CVE is recorded as related context, not a confirmed exploit path.
Siemens S7 campaign: advisory AA26-231A (2026-08-19; NSA, CISA, FBI, DOE, EPA) describes unattributed reconnaissance and capability development against US-based Siemens S7-200/300/400/1200/1500 PLCs. Actors find exposed devices through Censys and ZoomEye, then use AI-generated Python scripts built on the open-source snap7.dll / python-snap7 libraries, disguised as monitoring tools, to speak S7comm over TCP/102 and read/write PLC memory, configuration and ladder logic. Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, Commercial Facilities, Defense Industrial Base. The advisory publishes no IP or hash IOCs.
Defensive priorities: remove PLCs from direct internet exposure, broker remote access through monitored gateways with MFA, block TCP/102 at the perimeter, set PLC passwords and protection levels, keep tested offline controller backups, use physical run-mode switches, and monitor for unexpected engineering connections, S7comm from non-engineering hosts, and unauthorized program downloads.
MITRE ATT&CK techniques used in TL-2026-2961
Collection
Credential Access
T1003.003 OS Credential Dumping: NTDS
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Defense Evasion
Command and Control
T1090.003 Proxy: Multi-hop Proxy
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
T1587.004 Develop Capabilities: Exploits; T1588.007 Obtain Capabilities: Artificial Intelligence
Reconnaissance
Affected products and versions in OT Attacks on US Critical Infrastructure
- Rockwell Automation — Allen-Bradley CompactLogix / Micro850 / MicroLogix 1100 and 1400
Vulnerable versions: Internet-exposed, weakly authenticated controllers - Siemens — SIMATIC S7-200 / S7-300 / S7-400 / S7-1200 / S7-1500
Vulnerable versions: Internet-exposed controllers with S7comm on TCP/102 and outdated or unprotected configuration - Unitronics — Vision-series PLCs
Vulnerable versions: Internet-exposed controllers with default credentials (2023 campaign) - Schneider Electric — Modicon M340 (BMX P34)
Vulnerable versions: Internet-exposed controllers named in the 2026-07-22 AA26-097A update
Remediation for OT Attacks on US Critical Infrastructure
Patches
- Apply Rockwell, Siemens and Schneider Electric vendor guidance; apply fixes for exposed network appliances exploited by Volt Typhoon
Immediate actions
- Remove PLCs from direct internet exposure; inventory all internet-facing controllers
- Block TCP/102 (S7comm) and restrict 44818, 502, 20000 at the perimeter
- Change default credentials, enable PLC password protection and protection levels
- Validate all external connections, including undocumented cellular modems
Workarounds
- Disable PLC web servers and unneeded protocols
- Limit simultaneous S7comm sessions
- Enable TIA Portal know-how protection
Longer-term hardening
- Broker remote OT access through monitored gateways with MFA and IP allowlisting
- Segment OT from IT and deploy ICS-aware S7comm/EtherNet/IP monitoring
- Maintain tested offline controller logic backups and rehearse manual operation
- Use physical run-mode key switches to block remote program changes
CVEs associated with OT Attacks on US Critical Infrastructure
Weaknesses (CWE) in OT Attacks on US Critical Infrastructure
Timeline of OT Attacks on US Critical Infrastructure
- Volt Typhoon (PRC state-sponsored) is active against US critical infrastructure from at least 2021; AA24-038A later documents footholds maintained for at least five years in some victim IT environments
- CyberAv3ngers compromises 75+ internet-exposed Unitronics PLCs in an earlier campaign
- CISA, NSA, FBI and partners publish AA24-038A on Volt Typhoon living-off-the-land persistence in critical infrastructure
- FBI, CISA, NSA, EPA, DOE and US Cyber Command publish AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell/Allen-Bradley CompactLogix and Micro850 PLCs via Studio 5000 Logix Designer
- AA26-097A updated: scope widened to Schneider Electric and Siemens PLCs, first documented project-file exfiltration, new detection guidance for manipulated reusable PLC code modules
- Coordinated attacks on 30+ Minnesota community water utilities (26-27 July) and incidents in at least seven states; PLC passwords and IPs changed, causing pressure loss, flooding at some sites, boil-water notices and manual operation
- CISA and FBI/EPA urge utilities to remove internet-exposed PLCs immediately; attribution not formally confirmed
- NSA, CISA, FBI, DOE and EPA publish AA26-231A warning of AI-assisted reconnaissance and capability development against US Siemens S7 PLCs using snap7/python-snap7 over TCP/102
- GBHackers reports on OT attacks that could disrupt military operations and physical processes, listing four SHA-256 hashes tied to Volt Typhoon and CyberAv3ngers
Sources cited for OT Attacks on US Critical Infrastructure
- OT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes (GBHackers)
- CISA AA26-231A: Active Targeting of Siemens S7 PLCs
- CISA AA26-097A: Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure
- Joint Advisory (update): Iranian-Affiliated Cyber Actors Exploit PLCs (IC3 PDF, 2026-07-22)
- Joint Advisory: Iranian-Affiliated Cyber Actors Exploit PLCs (IC3 PDF, 2026-04-07)
- CISA AA24-038A: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure (Volt Typhoon)
- NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs (Security Affairs)
- CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks (Security Affairs)
- Tenable: Coordinated cyberattack on Minnesota water utilities
- Tenable: FAQ on the active threat to Siemens S7 Series PLCs
- Forescout: Minnesota water utility attacks reveal major OT security gaps
- Avertium: Coordinated attack on Rockwell MicroLogix PLCs disrupts water systems across 7 states
- MITRE ATT&CK: Volt Typhoon (G1017)
Detection coverage for TL-2026-2961
As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2961 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.