# OT Attacks on US Critical Infrastructure: Volt Typhoon Persistence and Iranian-Affiliated PLC Exploitation (Rockwell, Unitronics, Siemens S7)

> Joint US government advisories (AA24-038A, AA26-097A updated 2026-07-22, AA26-231A) document multi-actor targeting of US critical-infrastructure OT: Volt Typhoon persistence of at least five years, Iranian-affiliated CyberAv3ngers manipulation of internet-exposed Rockwell/Allen-Bradley PLCs, and an unattributed AI-assisted reconnaissance campaign against Siemens S7 PLCs. Coordinated attacks on 30+ Minnesota water utilities on 2026-07-26/27 (seven states overall) caused loss of control, boil-water notices and forced manual operations.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2961
- **ID:** TL-2026-2961
- **Severity:** CRITICAL
- **Category:** ICS_SCADA
- **Status:** ACTIVE
- **Actor:** Volt Typhoon - G1017 (China, Iran)
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-22681

## Description

This record consolidates the OT-focused activity summarized by GBHackers on 2026-10-06 and traces it to the primary government advisories.

Volt Typhoon (PRC state-sponsored, active since at least 2021): CISA/NSA/FBI advisory AA24-038A documents confirmed cases in which actors maintained footholds in victim IT environments for at least five years. Access is gained by exploiting public-facing network appliances (Fortinet, Ivanti, NETGEAR, Citrix, Cisco) and then sustained with valid administrator credentials and living-off-the-land binaries (vssadmin, ntdsutil, wmic, PowerShell, comsvcs.dll for LSASS dumping), RDP to domain controllers, Fast Reverse Proxy (FRP) and Mimikatz, with traffic proxied through compromised SOHO routers (KV Botnet). The activity is assessed as pre-positioning for lateral movement into OT assets for possible disruptive effects. Two SHA-256 hashes are attributed to Volt Typhoon in the GBHackers article.

Iranian-affiliated CyberAv3ngers (aka Shahid Kaveh Group, Storm-0784, UNC5691, Hydro Kitten; IRGC Cyber-Electronic Command): joint advisory AA26-097A (2026-04-07, updated 2026-07-22) by FBI, CISA, NSA, EPA, DOE and US Cyber Command describes exploitation of internet-facing Rockwell Automation/Allen-Bradley CompactLogix and Micro850 PLCs from overseas and leased infrastructure, using Rockwell's legitimate Studio 5000 Logix Designer to interact with project files and manipulate HMI/SCADA displays, causing operational disruption and, in some cases, financial loss. The 2026-07-22 update widened scope to Schneider Electric and Siemens PLCs, documented project-file exfiltration for the first time, and added detection guidance for manipulation of reusable code modules in PLC programs. Earlier activity includes the November 2023 compromise of 75+ Unitronics devices and the 2024 IOControl malware. Two further SHA-256 hashes are attributed to CyberAv3ngers in the GBHackers article. The article distinguishes earlier CyberAv3ngers activity from the 2026 campaign and does not support unqualified attribution of every 2026 incident.

Water-sector attacks: on 2026-07-26/27 a coordinated attack hit more than 30 community water systems in Minnesota (Braham, Plymouth, South St. Paul and Maple Plain publicly disclosed); at least seven states reported incidents. FBI/EPA reporting says internet-facing Rockwell MicroLogix 1100/1400 PLCs were accessed, with IP addresses and passwords changed to lock out operators, and in at least one case PLC project files/ladder logic were modified, which a password reset does not undo. Impacts included pressure loss and flooding at some sites, boil-water notices and sustained manual operation; Braham's water plant went offline. Undocumented vendor/integrator cellular modems were a noted exposure path. US agencies have not formally attributed the Minnesota attacks; Tenable assesses the pattern is consistent with CyberAv3ngers. Some vendor coverage associates CVE-2021-22681 (Rockwell Logix authentication bypass, CVSS 9.8) with this activity; other analysis notes MicroLogix 1100/1400 are not on that CVE's affected list, so the CVE is recorded as related context, not a confirmed exploit path.

Siemens S7 campaign: advisory AA26-231A (2026-08-19; NSA, CISA, FBI, DOE, EPA) describes unattributed reconnaissance and capability development against US-based Siemens S7-200/300/400/1200/1500 PLCs. Actors find exposed devices through Censys and ZoomEye, then use AI-generated Python scripts built on the open-source snap7.dll / python-snap7 libraries, disguised as monitoring tools, to speak S7comm over TCP/102 and read/write PLC memory, configuration and ladder logic. Sectors: Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, Commercial Facilities, Defense Industrial Base. The advisory publishes no IP or hash IOCs.

Defensive priorities: remove PLCs from direct internet exposure, broker remote access through monitored gateways with MFA, block TCP/102 at the perimeter, set PLC passwords and protection levels, keep tested offline controller backups, use physical run-mode switches, and monitor for unexpected engineering connections, S7comm from non-engineering hosts, and unauthorized program downloads.

## MITRE ATT&CK

- T1596.005 Search Open Technical Databases: Scan Databases
- T1587.004 Develop Capabilities: Exploits
- T1588.007 Obtain Capabilities: Artificial Intelligence
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1003.003 OS Credential Dumping: NTDS
- T1021.001 Remote Services: Remote Desktop Protocol
- T1090.003 Proxy: Multi-hop Proxy
- T0893 Data from Local System

## Sources

- [OT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes (GBHackers)](https://gbhackers.com/ot-systems-under-threat/)
- [CISA AA26-231A: Active Targeting of Siemens S7 PLCs](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a)
- [CISA AA26-097A: Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a)
- [Joint Advisory (update): Iranian-Affiliated Cyber Actors Exploit PLCs (IC3 PDF, 2026-07-22)](https://www.ic3.gov/CSA/2026/260722.pdf)
- [Joint Advisory: Iranian-Affiliated Cyber Actors Exploit PLCs (IC3 PDF, 2026-04-07)](https://www.ic3.gov/CSA/2026/260407.pdf)
- [CISA AA24-038A: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure (Volt Typhoon)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a)
- [NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs (Security Affairs)](https://securityaffairs.com/197566/ics-scada/nsa-cisa-fbi-doe-and-epa-warn-of-active-ai-assisted-attacks-on-siemens-s7-plcs.html)
- [CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks (Security Affairs)](https://securityaffairs.com/196453/ics-scada/cisa-urges-utilities-to-remove-internet-exposed-plcs-after-minnesota-attacks.html)
- [Tenable: Coordinated cyberattack on Minnesota water utilities](https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know)
- [Tenable: FAQ on the active threat to Siemens S7 Series PLCs](https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs)
- [Forescout: Minnesota water utility attacks reveal major OT security gaps](https://www.forescout.com/blog/minnesota-water-utility-attacks-reveal-major-ot-security-gaps/)
- [Avertium: Coordinated attack on Rockwell MicroLogix PLCs disrupts water systems across 7 states](https://www.avertium.com/flash-notices/coordinated-attack-on-rockwell-micrologix-plcs-disrupts-water-systems-across-7-states)
- [MITRE ATT&CK: Volt Typhoon (G1017)](https://attack.mitre.org/groups/G1017)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2961
