Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024.

CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024.

Scheduled Pinned Locked Moved Uncategorized
iran
7 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ifin@infosec.exchangeI This user is from outside of this forum
    ifin@infosec.exchangeI This user is from outside of this forum
    ifin@infosec.exchange
    wrote last edited by
    #1

    CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. Has anyone seen recent evidence of this? None was provided from CISA, and we'd love independent confirmation.

    kiddcutty@infosec.exchangeK nopatience@swecyb.comN ifin@infosec.exchangeI 3 Replies Last reply
    1
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
    • ifin@infosec.exchangeI ifin@infosec.exchange

      CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. Has anyone seen recent evidence of this? None was provided from CISA, and we'd love independent confirmation.

      kiddcutty@infosec.exchangeK This user is from outside of this forum
      kiddcutty@infosec.exchangeK This user is from outside of this forum
      kiddcutty@infosec.exchange
      wrote last edited by
      #2

      @ifin

      This was put out by CISA on April 7th. Attacks against Rockwell/Allen Bradley PLCs.

      Access Denied

      favicon

      (www.cisa.gov)

      ifin@infosec.exchangeI 1 Reply Last reply
      0
      • ifin@infosec.exchangeI ifin@infosec.exchange

        CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. Has anyone seen recent evidence of this? None was provided from CISA, and we'd love independent confirmation.

        nopatience@swecyb.comN This user is from outside of this forum
        nopatience@swecyb.comN This user is from outside of this forum
        nopatience@swecyb.com
        wrote last edited by
        #3

        @ifin There appears to have been some articles preceding the CISA advisory, and when viewed together may paint some sort of "capability" picture.

        2026-01-28: https://lab52.io/blog/black-industry-irgc-linked-offensive-ot-framework/

        2026-03-30: https://censys.com/blog/ics-iran-part-2-revisiting-exposure-of-previously-targeted-ics-devices/

        And a few more. I have not spent a significant amount of time exploring these in depth, but just some quick references to potentially relevant articles.

        ifin@infosec.exchangeI 1 Reply Last reply
        0
        • kiddcutty@infosec.exchangeK kiddcutty@infosec.exchange

          @ifin

          This was put out by CISA on April 7th. Attacks against Rockwell/Allen Bradley PLCs.

          Access Denied

          favicon

          (www.cisa.gov)

          ifin@infosec.exchangeI This user is from outside of this forum
          ifin@infosec.exchangeI This user is from outside of this forum
          ifin@infosec.exchange
          wrote last edited by
          #4

          @kiddcutty That's exactly the report we're trying to verify.

          1 Reply Last reply
          0
          • nopatience@swecyb.comN nopatience@swecyb.com

            @ifin There appears to have been some articles preceding the CISA advisory, and when viewed together may paint some sort of "capability" picture.

            2026-01-28: https://lab52.io/blog/black-industry-irgc-linked-offensive-ot-framework/

            2026-03-30: https://censys.com/blog/ics-iran-part-2-revisiting-exposure-of-previously-targeted-ics-devices/

            And a few more. I have not spent a significant amount of time exploring these in depth, but just some quick references to potentially relevant articles.

            ifin@infosec.exchangeI This user is from outside of this forum
            ifin@infosec.exchangeI This user is from outside of this forum
            ifin@infosec.exchange
            wrote last edited by
            #5

            @nopatience Thank you for these!

            The first is a measurement of exposure of OT of types previously attacked, not a report of current exploitation. The second is a report about a new attack tool available for sale. These are useful, but neither are confirmation of CISA's claim that:

            Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley.

            Note the present tense, as of 2026-04-07.

            tahomasoft@puget.socialT 1 Reply Last reply
            0
            • ifin@infosec.exchangeI ifin@infosec.exchange

              @nopatience Thank you for these!

              The first is a measurement of exposure of OT of types previously attacked, not a report of current exploitation. The second is a report about a new attack tool available for sale. These are useful, but neither are confirmation of CISA's claim that:

              Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley.

              Note the present tense, as of 2026-04-07.

              tahomasoft@puget.socialT This user is from outside of this forum
              tahomasoft@puget.socialT This user is from outside of this forum
              tahomasoft@puget.social
              wrote last edited by
              #6

              @ifin @nopatience I no longer work there, but USEPA may have corroborating information; as I understand it, the PLC targets are in drinking wand waste water systems; hence EPA’s potential involvement.

              1 Reply Last reply
              1
              0
              • System shared this topic
              • ifin@infosec.exchangeI ifin@infosec.exchange

                CISA is claiming that #Iran is once again targeting Programmable Logic Controllers (PLCs), similar to efforts in 2024. Has anyone seen recent evidence of this? None was provided from CISA, and we'd love independent confirmation.

                ifin@infosec.exchangeI This user is from outside of this forum
                ifin@infosec.exchangeI This user is from outside of this forum
                ifin@infosec.exchange
                wrote last edited by
                #7

                For the record, we have received independent confirmation of this activity.

                1 Reply Last reply
                1
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups