100

What should defenders do about Iranian-affiliated PLC targeting?. Build a multi-section brief covering the threat, affected internet-exposed PLC scope, observed access paths, ports 44818, 2222, 102, 502, and 22, ATT&CK techniques, and defender actions. Include a mitigation priority table that separates immediate exposure reduction, log review, project file validation, Rockwell AOI checks, and vendor hardening guidance.

Iranian-Affiliated Targeting of Internet-Exposed PLCs

CISA warns that Iranian-affiliated cyber actors have been exploiting internet-connected PLCs across U.S. critical infrastructure, with activity observed in Government Services and Facilities, Water and Wastewater Systems, and Energy. The advisory focuses on affected PLC scope, the access paths and ports used, the ATT&CK techniques mapped in the text, and the defender actions CISA says should be prioritized.[1][2][3]

The operational concern is not just exposure, but weak perimeter and lifecycle controls: the actors used foreign-based IP addresses, leased third-party hosted infrastructure, and manufacturers' PLC programming software to reach misconfigured, internet-facing devices. CISA also says organizations should review historical activity before taking blocking actions so they do not lose evidence of past compromise.[4][5]

Affected PLC Scope and Observed Access Paths

The advisory says the targeted environment included Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens PLCs, and potentially other PLCs, across multiple U.S. critical infrastructure sectors.[6]

  • Affected scope: devices in Government Services and Facilities, Water and Wastewater Systems, and Energy were explicitly called out.[7]
  • Access paths: the actors used foreign-based IP addresses, leased third-party hosted infrastructure, and manufacturers' PLC programming software to connect to misconfigured PLCs.[8]
  • Ports: malicious inbound traffic targeted PLC devices on ports 44818, 2222, 102, and 502, and modems on port 22.[9]
  • Indicators: CISA and the FBI provide listed IP addresses for historical log review before blocking or other response actions.[10][11]

Taken together, the access pattern suggests opportunistic exploitation of exposed OT services and vendor tooling rather than a single protocol-only campaign. The advisory's port list points defenders to industrial Ethernet, vendor-specific PLC services, and modem SSH exposure as the main places to look first.[12][13]

Mapped ATT&CK Techniques in the Advisory

CISA explicitly maps several techniques in the advisory text, including T0883 for initial access, T0885 for command and control, T1219 for remote access through Dropbear SSH on modems, T1041 for exfiltration of device project files, and T1565 for modification and deletion of project file logic and display data.[14]

  • T0883 and T0885 frame the core intrusion path and post-access control observed in the advisory.[15]
  • T1219 is tied to remote access through Dropbear SSH on modems, which aligns with the advisory's mention of port 22 exposure on modems.[16][17]
  • T1041 and T1565 reflect post-exploitation actions against PLC project files and display data, including extraction, modification, and deletion of logic.[18][19]

Defender Actions and Mitigation Priority

CISA and the authoring agencies recommend immediate exposure reduction, historical log review, validation of PLC project files, focused Rockwell checks for reusable code modules and Add-On Instructions, and vendor support engagement for mitigation and investigation help.[20][21]

PriorityActionWhy it matters
1Immediate exposure reduction: restrict direct internet access and apply advisory mitigations.[22]Reduces the chance that misconfigured PLCs remain reachable from hostile infrastructure.[23][24]
2Log review: query logs for the listed IP addresses before blocking them.[25]Preserves evidence of historical targeting and may reveal compromise before containment actions erase visibility.[26][27]
3Project file validation: inspect PLC project files for malicious interactions, logic changes, and HMI/SCADA display manipulation.[28]CISA says the actors modified and deleted logic and manipulated display data after project file extraction.[29]
4Rockwell AOI checks: examine reusable code modules and Add-On Instructions in Rockwell Automation PLC programs.[30]The advisory specifically expands guidance to detect malicious changes in reusable code modules.[31]
5Vendor hardening guidance: follow prior vendor guidance for Rockwell Automation, Schneider Electric, and Siemens, and apply secure-by-design and secure-by-default principles.[32]Hardening reduces repeat exposure across common PLC platforms and makes opportunistic attacks harder at scale.[33]

If a site discovers an affected internet-accessible device, CISA says to take additional technical measures to evaluate compromise risk and activate incident response plans. The agency also advises contacting the authoring agencies and the relevant vendors through existing support channels for assistance.[34][35]

Bottom Line

The threat is broad but concrete: Iranian-affiliated actors were reaching internet-exposed PLCs across multiple critical infrastructure sectors, using exposed OT ports, vendor software, and third-party infrastructure. Defenders should prioritize exposure reduction, retrospective log hunting, and validation of PLC project files and Rockwell-specific logic modules, while following vendor hardening guidance to reduce repeat compromise.[36][37][38][39][40][41]