惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
博客园_首页
Google DeepMind News
Google DeepMind News
博客园 - Franky
The GitHub Blog
The GitHub Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Recent Announcements
Recent Announcements
A
About on SuperTechFans
博客园 - 【当耐特】
博客园 - 三生石上(FineUI控件)
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
罗磊的独立博客
IT之家
IT之家
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
Jina AI
Jina AI
腾讯CDC
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns Eight in 10 UK Manufacturers Hit by Cyber Incident in a Year
Iran‑Backed Threat Actors Hit US CNI Providers via Intern...
Phil Muncaster · 2026-04-08 · via www.infosecurity-magazine.com

Iranian-affiliated hackers have been attacking US critical national infrastructure (CNI) providers since last month, causing operational disruption and financial loss, the US government has revealed.

A Cybersecurity and Infrastructure Security Agency (CISA) advisory on April 7 said the threat actors were targeting internet-facing operational technology (OT) assets including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. 

So far, the sectors targeted have been government services and facilities (including local municipalities), water and wastewater systems (WWS), and energy.

“Due to the widespread use of these PLCs and the potential for additional targeting of other branded OT devices across critical infrastructure, the authoring agencies recommend US organizations urgently review the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) in this advisory for indications of current or historical activity on their networks, and apply the recommendations listed in the mitigations section to reduce the risk of compromise,” the advisory noted.

Read more on Iranian CNI attacks: Researchers Discover Malware Used by Nation-States to Attack Industrial Systems.

The advanced persistent threat (APT) group has been observed “maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays,” according to CISA. The PLCs apparently manage a wide variety of industrial processes.

They are using “configuration software” such as Rockwell Automation’s Studio 5000 Logix Designer to create an “accepted connection” to targeted PLCs, via overseas IP addresses and third-party hosted infrastructure.

Inbound malicious traffic may come on ports 44818, 2222, 102, 22, or 502, with port 22 attacks involving the deployment of Dropbear Secure Shell (SSH) software on victim endpoints for remote access.

Actions For CNI Firms to Take

The advisory urged US CNI providers to:

  • Use secure gateways and firewalls to protect PLCs from direct internet exposure
  • Query available logs for the IOCs provided in the advisory
  • Check available logs for suspicious traffic on the ports associated with OT devices, especially if they originate overseas
  • Place the physical mode switch on the controller of Rockwell Automation devices into the run position. And contact the FBI, CISA, NSA or other authoring agencies for guidance if the organization has already been targeted

The campaign follows a Handala attack on US medtech firm Stryker in March which wiped tens of thousands of devices.

It also follows a similar campaign in 2023 when Iran’s Islamic Revolutionary Guard Corps (IRGC) struck US water plants running PLCs manufactured by Israeli firm Unitronics.

Experts Weigh In

Ross Filipek, CISO at Corsica Technologies, argued that the new campaign didn’t happen in a vacuum.

“Years of high-profile infrastructure incidents have shown the world two things. First, that many operational technology environments still have internet reachable interfaces and remote access paths that were never meant to be permanent,” he continued.

“Second, that even limited disruptions can create outsized chaos, from emergency response strain to financial loss and reputational damage. Each successful or even partially successful campaign lowers the barrier for the next one, and emboldens actors to move from nuisance level defacement into real operational interference.”

Exabeam VP of AI strategy and security research, Steve Povolny, said CNI firms operating OT should assume increased reconnaissance, credential harvesting and opportunistic attempts to exploit systems during the US campaign in Iran.

“Visibility gaps between IT and OT telemetry remain one of the most persistent weaknesses I see across critical infrastructure operators. Teams should prioritize passive network monitoring for control protocols, enforce strict segmentation between enterprise and control zones, validate remote access pathways, and confirm that engineering workstations and vendor maintenance channels are tightly controlled and logged,” he added.

“Just as important, incident response plans must explicitly account for loss of control system integrity, not just loss of data confidentiality. However, I fear it may be too late for much of this to have short-term impact.”