CISA Updates Advisory on Iranian Cyber Actors Exploiting PLCs

This update re-emphasizes the ongoing threat.

Iran Cyber Mirsad Sarajlic
istock.com/mirsadsarajlic

The Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) has released an updated joint Cybersecurity Advisory entitled Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure.

This update re-emphasizes the ongoing threat from Iranian-affiliated advanced persistent threat (APT) actors targeting internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other brands/manufacturers. 

These attacks have resulted in operational disruptions and financial losses across multiple U.S. critical infrastructure sectors, including Government Services and Facilities, Water and Wastewater Systems, and Energy. Updates to advisory cover:

  • Expanded Targeting: The advisory now includes observed targeting of Schneider Electric and Siemens PLCs, in addition to Rockwell Automation/Allen-Bradley and potentially other branded/manufacturer devices.
  • Updated Technical Details: New information on threat actor tactics, including use of configuration software to exfiltrate device project files, and expanded details on targeted ports and device models.
  • Enhanced Mitigations: Additional recommendations for securing cellular modems, implementing isolated architectures, validating project files, and detecting malicious changes in reusable code modules (such as Add-On Instructions/AOIs).
  • New Indicators of Compromise (IOCs): Updated tables of internet protocol (IP) addresses and timeframes associated with Iranian-affiliated APT activity.

More information is available by reading the updated advisory and reviewing CISA’s Iran Threat Overview and Advisories.

More in Cybersecurity