Iranian APT Hackers Target Siemens, Schneider, Rockwell ICS Devices
The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Schneider Electric, and Rockwell Automation at critical infrastructure organizations. Originally published in early April and revised on July 22, the advisory from federal agencies identifies intrusions into government services, energy, and water and wastewater sector environments, with attackers compromising internet-exposed programmable logic controllers (PLCs). The latest revision broadens the vendor list beyond Allen-Bradley/Rockwell devices and notes that PLCs from additional manufacturers may also be at risk.
The attackers are exploiting specific industrial hardware, including Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs, reaching them via TCP ports 44818, 2222, 102, 502, and 22. Using vendor programming environments such as Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert, and Siemens TIA Portal, the threat actors deploy malicious project files that retain legitimate ladder logic while injecting overrides that bypass safety thresholds. In one U.S. incident investigated by the FBI, the adversary downloaded a tampered project file to a PLC via configuration software, embedding add-on instructions that disabled critical shutdown and alarm logic. Operators monitoring human-machine interfaces (HMIs) and SCADA dashboards saw manipulated data, allowing systems to enter unsafe states without triggering alerts. Defenders can probe exposed assets with a port scanner to identify the very services these actors are abusing, while a WHOIS lookup on suspicious third-party infrastructure may reveal the leased hosting providers used as command-and-control relays.
Beyond the safety implications, the attackers exfiltrated PLC project files before modifying and deleting embedded logic, hampering recovery efforts and complicating forensic analysis. The Iranian government has increasingly masked these intrusions behind hacktivist personas, with CyberAv3ngers among the groups previously linked to disruptive operations against U.S. and Israeli OT networks. The updated advisory supplies new indicators of compromise (IoCs) and detection guidance tailored to OT defenders, urging operators to audit engineering workstations, validate project-file integrity, segment ICS networks from corporate IT, and monitor for anomalous vendor-software activity. For organizations reviewing broader exposure, a VPN/proxy detector can help identify whether outbound traffic from ICS environments is being routed through anonymizing services often favored by state-aligned intruders.