Six federal agencies have updated a joint cybersecurity advisory warning that Iranian-affiliated threat actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. government facilities, water systems, and energy infrastructure.
The advisory, tracked as AA26-097A, was first published in April 2026 and revised on July 22, 2026, expanding its scope significantly.
The threat actors scan the internet for exposed PLCs and connect using legitimate engineering software, mirroring the workflow of an authorized technician rather than exploiting a software vulnerability.
Hackers Manipulate PLC Logic and Operator
Once inside, attackers alter controller logic and, in some cases, manipulate operator display screens so that human-machine interface (HMI) operators cannot detect anomalies in real time.
This activity is attributed to actors consistent with the IRGC-affiliated group previously identified in a 2023 campaign, though the current intrusions show markedly improved tradecraft.
The July update widens manufacturer scope beyond Rockwell Automation and Allen-Bradley CompactLogix and Micro850 controllers, initially named in April, to now include Schneider Electric and Siemens equipment.
New detection guidance also addresses malicious modifications hidden inside shared, reusable code modules a supply-chain-style risk where a single tampered module can propagate changes across an entire operational environment.
The 2023 intrusions, affecting Unitronics PLCs, relied on simple default-credential abuse and were largely disruption-free.
The 2026 activity is far more sophisticated: attackers use legitimate engineering software with valid, working credentials rather than default passwords, making connections appear indistinguishable from routine technician access.
Where the earlier campaign had a simple fix, changing passwords, this ongoing exploitation stems from an architectural weakness in network exposure and access control, and it has produced confirmed operational disruption and financial loss for some victim organizations.
Malicious traffic was observed across five ports commonly used in industrial protocols: 22 (SSH), 102 (ISO-TSAP/S7comm), 502 (Modbus TCP), 2222, and 44818 (EtherNet/IP).
Trend Micro notes that none of this traffic relies on an exploitable bug; the underlying issue is insufficient network segmentation and remote-access hardening rather than a patchable flaw.
Public scan data shows tens of thousands of ICS devices remain directly reachable from the open internet, many still running default or absent credentials.
Mitigations
CISA and co-signing agencies, including the FBI, NSA, EPA, Department of Energy, and U.S. Cyber Command, recommend immediate and near-term actions:
- Remove PLCs from direct internet exposure and route remote access through secured, MFA-gated gateways.
- Set physical mode switches to RUN status during normal operations, reserving PROGRAM/REMOTE for supervised maintenance.
- Search firewall and IDS logs for the advisory’s published IP indicators on the affected ports, with attention to overseas hosting providers.
The advisory also pushes accountability toward manufacturers, urging vendors to eliminate default internet-facing administrative interfaces and stop charging extra for baseline security features like MFA.
IOCs
| IoC | Detection |
| 185.82.73[.]175 | 91 – C&C server |
| 141.11.164[.]153 | 91 – C&C server |
| 175.110.121[.]42 | 91 – C&C server |
| 175.110.121[.]39 | 91 – C&C server |
| 175.110.121[.]41 | 38 – Computers/Internet |
| 175.110.121[.]107 | 91 – C&C server |
| 192.142.54[.]79 | 38 – Computers/Internet |
| 84.200.205[.]165 | 38 – Computers/Internet |
| 185.225.17[.]225 | 91 – C&C server |
| 79.133.46[.]209 | 91 – C&C server |
| 88.80.150[.]199 | 91 – C&C server |
| 88.80.150[.]200 | 91 – C&C server |
| 88.80.150[.]202 | 91 – C&C server |
| 185.82.73[.]162 | 91 – C&C server |
| 185.82.73[.]164 | 91 – C&C server |
| 185.82.73[.]165 | 91 – C&C server |
| 185.82.73[.]167 | 91 – C&C server |
| 185.82.73[.]168 | 91 – C&C server |
| 185.82.73[.]170 | 91 – C&C server |
| 185.82.73[.]171 | 91 – C&C server |
| 135.136.1[.]133 | 91 – C&C server |
| ocferda[.]com | 91 – C&C server |
| uuokhhfsdlk[.]tylarion867mino[.]com | 91 – C&C server |
| tylarion867mino[.]com | 91 – C&C server |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.