Iranian Actors Expose US Industrial Devices
Executive Summary
Iran-affiliated threat actors are actively targeting thousands of internet-exposed industrial devices across U.S. critical infrastructure.
The campaign focuses on exploiting Programmable Logic Controllers (PLCs) to disrupt operations in the energy and water sectors.
Key TTPs
- Initial Access: Actors scan for and connect to internet-facing PLCs, often using default credentials or exploiting weak passwords.
- Execution: Malicious actors use legitimate PLC software to connect to devices and manipulate project files and control logic.
Campaign Analysis
This campaign highlights a significant escalation in targeting OT environments, moving from simple defacements to direct manipulation of industrial processes.
The focus on widely-used Rockwell Automation PLCs demonstrates a calculated effort to maximize potential disruption to U.S. critical functions.
Targeting & Infrastructure
- Target Profile: U.S. critical infrastructure, including Water and Wastewater Systems (WWS), energy, and government facilities.
- Infrastructure: Thousands of internet-exposed Rockwell Automation PLCs, with many devices running end-of-life software.
Relevant Terms
- Programmable Logic Controller (PLC): A ruggedized industrial computer used to automate and control manufacturing processes, such as assembly lines, robotic devices, or water treatment facilities.
- Attack Surface: The total number of all possible entry points for an unauthorized user to access a system. In this case, it refers to PLCs connected directly to the internet.
Source: BleepingComputer
