On July 22, 2026, CISA, FBI, NSA, EPA, DOE, CNMF, and Treasury updated a joint advisory on Iranian attacks against programmable logic controllers (PLCs) directly connected to the internet. Alert AA26-097A documents an escalation from simple HMI interface defacement to silent overwriting of operational safety parameters in Rockwell Automation, Schneider Electric, and Siemens PLCs. The shift makes detection harder and raises the risk of physical impact on U.S. critical infrastructure.
- Seven U.S. government agencies confirm active exploitation of internet-exposed PLCs by APT actors affiliated with the IRGC CEC, with activity observed since March 2026.
- Mechanisms include downloading malicious project files that add ladder logic to overwrite operational safety instruction sets, combined with manipulation of data on HMI/SCADA displays.
- The July 2026 update expands scope from Rockwell Automation to Schneider Electric, Siemens, and potentially other vendors, adding detection for altered reusable code modules.
- The advisory documents operational disruptions and financial losses at some victims in the Government Services and Facilities, Water and Wastewater Systems, and Energy sectors.
From Defacement to Silent Operational Logic Modification
The technical evolution documented in the July 22, 2026 update signals a step-change in Iranian actors' capabilities. In one case examined by the FBI, APT actors downloaded a malicious project file to a Rockwell Automation PLC using standard configuration software. Analysis revealed the file retained the original ladder logic for downstream functions but added logic that overwrote specific instruction sets responsible for maintaining operational safety parameters in the victim's environment.
Simultaneously, actors manipulated data displayed on HMI interfaces and SCADA systems. The combination creates a dangerous condition: real physical parameters deviate from those shown to operators, delaying incident response and widening the window for equipment damage or service disruption.
The original advisory, published in April 2026, focused on Rockwell Automation/Allen-Bradley PLCs. The July update adds detection for malicious changes in reusable code modules (Add-On Instructions, routines) within Rockwell programs and explicitly expands scope to Schneider Electric and Siemens PLCs, along with other potential vendors. The expansion indicates the techniques are transferable across platforms and do not depend on vulnerabilities specific to a single manufacturer.
Technical Indicators and Access Vectors
The advisory publishes indicators of compromise in STIX format with over 20 IPv4 addresses and MITRE ATT&CK for ICS patterns, including T0883 (Manipulate I/O Image), T0885 (Commonly Used Port), T0809 (Data Destruction), T1565.001 (Manipulate PLC Attributes), T1491.001 (Defacement Internal Message), T1041 (Exfiltration Over C2 Channel), T1219 (Remote Access Software). The presence of T1565.001 confirms PLC attribute modification as a documented technique, not a hypothesized one.
Four network ports have been identified for monitoring suspicious traffic from foreign hosting providers: 44818 (EtherNet/IP), 2222, 102 (S7), and 502 (Modbus). These ports correspond to the native industrial protocols of the targeted PLCs, suggesting that direct internet exposure of OT devices is the primary access vector, without need for zero-day vulnerabilities or sophisticated exploits.
The Dropbear malware family has been associated with the campaign in historical STIX files from April 2026, indicating the use of known remote access tools in the ICS threat landscape.
"In a few cases, this activity caused operational disruption and financial loss" — CISA Advisory AA26-097A, Impact section
Attribution and Geopolitical Context
The advisory identifies the actors as an APT group affiliated with the Cyber Electronic Command (CEC) of the Islamic Revolutionary Guard Corps (IRGC), previously known in connection with CyberAv3ngers or Shahid Kaveh Group activity. The distinction is significant: the advisory links the 2026 campaign to "Iranian-affiliated APT actors" and cites CyberAv3ngers as a historical reference for similar activity, but does not explicitly confirm it is the same operational group.
The historical CyberAv3ngers campaign, starting in November 2023, had compromised at least 75 Unitronics PLC devices. The 2026 advisory does not mention Unitronics among current targets, signaling a shift in focus toward vendors more prevalent in U.S. critical infrastructure.
A passage in the advisory directly links the escalation of targeting campaigns to ongoing hostility among Iran, the United States, and Israel. The fragmentation of specific attribution and the nature of "affiliation" rather than confirmed identity leave room for a cautious reading: the Iranian CEC may serve as a container for multiple operational units with shared techniques but not necessarily centralized coordination.
Recommended Actions
Advisory AA26-097A lists priority actions for OT operators and integrators:
- Verify internet exposure of PLCs, HMIs, and other OT devices: the advisory underscores that direct internet connection is the enabling condition for the attack. Remove public exposure where not strictly necessary.
- Monitor traffic on ports 44818, 2222, 102, 502 for connections from foreign hosting providers, using the STIX IOCs published by CISA for integration into detection systems.
- Implement periodic reviews of PLC project files, with hash or known-version comparison, to identify additions of ladder logic or modifications to reusable code modules.
- Validate data displayed on HMI/SCADA by cross-referencing with independent readings from field sensors, to detect discrepancies indicating process manipulation.
Limits of the Dossier and What Is Not Documented
The advisory does not quantify the exact number of victims in the 2026 campaign, indicating only "several" victims in "multiple sectors." Financial losses are mentioned but not specified in amounts. No CVEs are assigned for the described techniques: the attack relies on manipulation of configuration files on already-accessible devices, not on exploitation of software vulnerabilities with an identifier. The duration of persistent access in victims before detection is not stated. The precise geolocation of IP indicators remains unspecified beyond the generic "foreign hosting providers."
The precise identity of the APT group beyond IRGC CEC affiliation is not explicitly confirmed: the overlap with CyberAv3ngers is presented as historical reference, not as verified operational identity of the group active in 2026.
Why Manipulating Safety Parameters Changes the Game
The difference between an attack that makes its presence visible and one that silently alters physical safety limits is the difference between vandalism and operational sabotage. Internet-exposed PLCs are not new; the awareness that state actors are modifying them to overwrite equipment protection parameters, rather than merely defacing screens, marks a normalization of physical risk in cyberspace.
For the water and energy sectors, where operational safety parameters protect both equipment and public health, the ability to manipulate these values without alerting operators represents a qualitative leap in the threat. The July 2026 update, with seven signatory agencies, reflects an assessment that this technical evolution warrants a coordinated institutional response, not just a technical alert.
Frequently Asked Questions
- Does this attack exploit a zero-day vulnerability in PLCs?
- No. The advisory describes exploitation of OT devices already connected to the internet through manipulation of project files and operational logic, not exploitation of specific software vulnerabilities with an assigned CVE.
- Is CyberAv3ngers confirmed as the group responsible for the 2026 campaign?
- No. The advisory cites CyberAv3ngers as a group historically affiliated with the IRGC CEC with similar activity, but attributes the 2026 campaign to "Iranian-affiliated APT actors" without confirming the specific operational identity.
- Why is the July 2026 update significant?
- It adds detection for altered reusable code modules in Rockwell Automation programs and explicitly expands scope to Schneider Electric and Siemens, indicating transferability of techniques across different platforms.
Sources
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a
- https://www.arcweb.com/blog/cisa-fbi-epa-us-government-partners-update-warning-iran-affiliated-threat-actors-targeting
- https://www.afcea.org/signal-media/cyber-edge/cisa-and-partners-revise-iranian-affiliated-plc-threat-advisory
- https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.xml
- https://www.cisa.gov/sites/default/files/2026-07/AA26-097A.stix_.json
- https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml
- https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.json
- https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/government-services-facilities-sector
Information verified against cited sources and current as of publication.