Title: Increasing Threat from Iranian Cyber Actors: Updated Advisory Highlights Risks to U.S. Critical Infrastructure
In a significant escalation of cyber threats, six federal agencies have renewed an advisory alerting that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across critical infrastructure in the United States. This troubling development is characterized by the manipulation of human-machine interface (HMI) displays, making it increasingly difficult for operators to visually detect intrusions or tampering.
Originally issued in April 2023 and later updated on July 22, 2023, the advisory is co-signed by notable federal entities including the FBI, CISA, NSA, EPA, the Department of Energy, and U.S. Cyber Command. This collaborative effort underscores the gravity of the situation as it outlines potential risks to the nation’s critical systems.
The cyber actors target PLCs by scanning the internet for devices that lack adequate security measures. They connect using legitimate engineering software—essentially replicating the actions of authorized technicians—to alter controller logic. In some cases, they even manipulate what is displayed on operator screens, rendering the impact of their intrusion invisible to those responsible for monitoring and operating essential systems.
Historical Context and Current Threats
This malicious activity has already resulted in operational disruptions and financial losses for various victims. This situation marks a stark evolution from a mostly disruption-free campaign seen in 2023, where hackers primarily targeted Unitronics PLCs using default passwords. The July update from Trend Micro expands the list of targeted systems beyond Rockwell Automation and Allen-Bradley’s CompactLogix and Micro850 controllers to also include equipment from Schneider Electric and Siemens.
The most recent findings have highlighted the threat of changes hidden within reusable code modules. This means a single compromised logic block could silently propagate throughout an entire organization by leveraging shared engineering libraries, amplifying the risk of widespread disruption.
In response to these heightened threats, the updated advisory provides robust detection guidance aimed at identifying and mitigating unauthorized changes on PLC project files. Notably, it urges organizations to proactively inform service providers about these enduring threats.
Impacted Sectors and Technical Insights
The targeted sectors include a diverse array of critical infrastructures such as government facilities, municipal systems, and water and wastewater treatment plants, as well as energy infrastructure. Malicious traffic associated with this campaign has been detected on five specific ports: 22 (SSH), 102 (ISO-TSAP/Siemens S7comm), 502 (Modbus TCP), 2222, and 44818 (EtherNet/IP). This multi-port exploitation adds another layer of complexity to detecting and mitigating intrusions.
One of the unique challenges is that attackers are not exploiting conventional software vulnerabilities; instead, they are using valid credentials and legitimate software. This situation is characterized as an architectural weakness rather than a fixable vulnerability, as Shodan data has revealed that tens of thousands of Industrial Control Systems (ICS) devices remain reachable from the open internet.
Urgent Recommendations for Organizations
In light of these risks, federal agencies are urging organizations to take immediate action. They recommend removing PLCs from direct internet exposure and mandating that all remote access go through secure gateways equipped with multifactor authentication. Furthermore, where applicable, organizations should ensure physical mode switches are set to RUN instead of PROGRAM or REMOTE outside of supervised maintenance windows.
Cybersecurity practitioners are also advised to scan firewall and intrusion detection logs for the published IP indicators associated with the threat. This proactive monitoring can help organizations identify potential intrusions before they lead to significant operational disruptions.
As organizations move forward, they should enable programming protection in accordance with vendor-specific guidance, such as Rockwell’s SD1771 standard or Siemens TIA Portal configuration. Additionally, maintaining offline, tested backups of PLC logic, separate from production networks, is crucial for ensuring business continuity in the event of a cyber incident.
Call for Better Industry Standards
The advisory also emphasizes the responsibility of manufacturers to design products that do not expose administrative interfaces to the internet by default. Enhancements like supporting phishing-resistant multifactor authentication can significantly bolster security measures across critical infrastructures. Given the reliance on legitimate software and credentials for intrusions, federal agencies stress the importance of continuous validation of these security controls instead of treating them as a one-time compliance check.
As the landscape of cyber threats continues to evolve, it is imperative for organizations to remain vigilant and responsive to emerging risks in their operational environments.

