Iran Inside American PLCs: The IRGC Has Already Caused Real Damage to US Water and Energy Facilities
On April 7, 2026, six U.S. federal agencies — FBI, CISA, NSA, EPA, Department of Energy, and Cyber Command — published joint advisory AA26-097A with an unequivocal message: Iran-affiliated hackers have compromised programmable logic controllers (PLCs) in American critical infrastructure, causing real operational damage and financial losses. NERC confirmed it is actively monitoring the national electrical grid in coordination with DOE and the Electricity Subsector Coordinating Council.
CyberAv3ngers 2.0: From Unitronics Default Credentials to Rockwell Studio 5000
The advisory identifies the actor as affiliated with the IRGC Cyber Electronic Command (CEC), linking it to CyberAv3ngers (aka Shahid Kaveh Group) — the same group that compromised at least 75 Unitronics PLC devices using default credentials in November 2023. The 2026 campaign marks a dramatic qualitative leap: attackers now use third-party hosted infrastructure and legitimate industrial configuration software — specifically Rockwell Automation Studio 5000 Logix Designer — to create accepted connections to victim PLCs. The Iranians speak to American PLCs in their own language.
Advisory CISA AA26-097A is jointly signed by FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command. Attackers caused "operational disruption and financial loss" at multiple U.S. critical infrastructure organizations. NERC is actively monitoring the national grid.
Targets: Water, Energy, Government Services
Compromised PLCs were deployed across water and wastewater systems (WWS), the energy sector, and government services including municipalities. Target devices include Rockwell Automation CompactLogix and Micro850. The targeting of ports associated with other OT vendor protocols suggests attackers are also targeting Siemens S7 PLCs, expanding the attack surface across the entire industrial automation ecosystem.
- Water sector (WWS): treatment plants — chemical processes, pumps, valves
- Energy sector: power generation, distribution, substations
- Government services: municipalities and local administrations
- Devices: Rockwell CompactLogix, Micro850, potentially Siemens S7
- Target ports: 44818 (EtherNet/IP), 2222 (Rockwell), 102 (Siemens S7), 22 (SSH), 502 (Modbus)
Technical Anatomy: Studio 5000, Dropbear, and HMI Manipulation
Attackers used overseas-based IPs and third-party infrastructure with Studio 5000 Logix Designer to connect to victim PLCs. They extracted project files containing industrial process control logic and manipulated data displayed on HMI and SCADA displays. Manipulating an HMI means operators see false data: correct water levels when they are critical, normal temperatures when out of range. For persistence, attackers deployed Dropbear — a lightweight SSH implementation designed for embedded systems — on victim endpoints via port 22.
Target ports — 44818 (EtherNet/IP/CIP), 2222 (Rockwell), 102 (Siemens S7comm), 22 (SSH/Dropbear), 502 (Modbus) — indicate attackers are probing the entire spectrum of industrial protocols. Any organization with internet-facing PLCs on these ports should consider itself at immediate risk.
From the Middle East to Europe: Why This Campaign Matters Here
The same Rockwell and Siemens devices are the backbone of European industrial automation. TTPs developed against America work identically in Europe. The Waterfall Security Threat Report 2026 documents that nation-state and hacktivist attacks against critical infrastructure doubled, with Germany, the US, and Russia as the top victim geographies. Europe is not a future target — it is already an active one.
IOCs and Target Ports
- Port 44818: EtherNet/IP — Rockwell CIP protocol
- Port 2222: Rockwell Automation proprietary PLC configuration
- Port 102: Siemens S7comm — S7-300/400/1200/1500 communication
- Port 22: SSH — Dropbear for persistent remote access
- Port 502: Modbus TCP — universal SCADA/HMI protocol
- Software: Rockwell Automation Studio 5000 Logix Designer
- Persistence: Dropbear SSH server deployed on victim endpoints
- Full STIX IOCs available in CISA advisory AA26-097A
Operational Recommendations
- 1.Disconnect PLCs from the internet: no PLC should be directly reachable. Remote access must go through VPN with MFA, dedicated jump boxes, and continuous monitoring.
- 2.Block OT ports at the perimeter: ports 44818, 2222, 102, and 502 must never be externally accessible.
- 3.Audit Rockwell and Siemens devices: check all CompactLogix, Micro850, and Siemens S7 PLCs for unauthorized connections, project file modifications, and presence of Dropbear.
- 4.Monitor Studio 5000 connections: every connection must be logged and correlated with authorized activity.
- 5.Verify HMI/SCADA integrity: compare displayed data with independent measurements to identify display manipulation.
- 6.Rigorous IT/OT segmentation: OT network must be physically or logically separated with an industrial DMZ.
- 7.Manual fallback plan: every critical process must have tested manual operating procedures.
- 8.Threat hunting with CISA IOCs: use STIX indicators from AA26-097A to actively search for prior compromise.
Conclusion: Hybrid Warfare Has Reached the Valves and Transformers
Advisory AA26-097A marks a point of no return in Iranian hybrid warfare. The progression from Unitronics PLCs with default credentials (2023) to Rockwell Automation with Studio 5000 (2026) shows a rapidly maturing actor acquiring specific OT competencies. For Europe, the lesson is immediate: if Iran can compromise PLCs in the most technologically advanced nation, it can do so anywhere.
Primary sources: CISA Advisory AA26-097A (April 7, 2026), CyberScoop (April 8, 2026), Cybersecurity Dive (April 8, 2026), The Register (April 7, 2026), Defense One (April 2026), Utility Dive/NERC (April 2026), Security Affairs (April 2026), Picus Security (AA26-097A simulation analysis), Waterfall Security Threat Report 2026. STIX IOCs at cisa.gov.