SHIELD: ACTIVE // NETWORK SECURE

Critical Infrastructure Alert CISA Joint Advisory Warns of Iranian Cyber Attacks Targeting Industrial PLCs

Critical Infrastructure Alert: CISA Joint Advisory Warns of Iranian Cyber Attacks Targeting Industrial PLCs

Executive Summary

In a joint cybersecurity advisory (AA26-097A), CISA, the FBI, the NSA, and international allied cyber agencies issued an urgent alert warning that Iranian state-sponsored cyber actors are actively targeting and compromising Programmable Logic Controllers (PLCs) across critical infrastructure sectors. The campaign specifically targets operational technology (OT) assets in the water and wastewater management, energy, and healthcare sectors. Threat actors are exploiting internet-exposed PLCs and industrial modems configured with default administrative passwords, allowing them to manipulate operational control settings and disrupt critical physical processes.

Technical Breakdown of the Industrial Cyber Campaign

Advisory AA26-097A details the specific techniques, tools, and procedures (TTPs) deployed by Iranian cyber units against industrial control systems (ICS):

1. Exploitation of Internet-Exposed OT Hardware

Threat actors utilize specialized search engines (such as Shodan and Censys) to scan for publicly accessible industrial control equipment, specifically targeting:

* Unitronics Vision Series PLCs: Compact PLCs integrated with human-machine interface (HMI) screens used extensively in municipal water facilities.

* Schneider Electric / Modicon Cellular Routers & Modems: Edge communications modems used to relay telemetry from remote pumping stations.

2. Abuse of Default Administrative Credentials

The attackers bypass technical exploitation entirely by leveraging factory-default administrative credentials (e.g., default passwords such as 1111 or admin). Once authenticated to the PLC management portal:

* The actors alter logic control parameters, changing system pressure, chemical dosing, or valve state setpoints.

* They overwrite PLC firmware and display defacement messages on local HMI screens, rendering the physical controller unresponsive to local manual overrides.

3. Lateral Movement into Corporate IT

In several analyzed intrusions, threat actors used compromised OT cellular gateways as pivoting points to establish covert tunnels into internal corporate IT networks, exfiltrating network diagrams and SCADA system schematics.

Advisory Component

Details

Issuing Agencies

CISA, FBI, NSA, NCSC-UK, and International Allies

Advisory Identifier

CISA AA26-097A

Target Sectors

Water and Wastewater Systems, Energy, Manufacturing, Healthcare

Target Equipment

Unitronics PLCs, Schneider Electric Routers, Serial-to-Ethernet Gateways

Primary Attack Vector

Default Passwords on Internet-Exposed Industrial Devices

Operational Risks to Physical Infrastructure

Direct attacks against Industrial Control Systems (ICS) represent an elevated class of risk because cyber compromises manifest as physical operational failures. In municipal water systems, unauthorized setpoint manipulation can disrupt water filtration, damage physical pump hardware, or contaminate distribution supplies.

The reliance on legacy OT devices—many of which were designed decades ago without native encryption or multi-factor authentication—makes perimeter air-gapping and credential hygiene imperative.

Recommendations and Mitigations

Industrial asset owners and OT engineers must enforce robust defensive measures across all control networks:

1. Remove PLCs and HMIs from the Public Internet: Immediately disconnect all PLCs, HMIs, and SCADA gateways from direct internet exposure. Place necessary remote management interfaces behind secure OT firewalls.

2. Change All Factory-Default Passwords: Audit every industrial device on the network and replace default administrative credentials with complex, unique passphrases.

3. Implement OT Network Micro-Segmentation: Isolate Operational Technology (OT) networks from corporate Information Technology (IT) networks using strict demilitarized zones (DMZs) and industrial firewalls.

4. Enforce Out-of-Band Physical Setpoint Verification: Deploy mechanical safety controls and physical relief valves that operate independently of software PLC commands to prevent physical over-pressurization or chemical over-dosing.

Category: Cyber Security Intelligence