The US government has issued an updated advisory highlighting the persistent cybersecurity threat posed by Iranian actors targeting critical infrastructure. The advisory notes that industrial control systems (ICS) from Siemens, Schneider Electric, and Rockwell Automation are under attack.
Details of Cyber Attacks on Industrial Systems
Initially released in April, the advisory detailed how Iranian hackers targeted operational technology (OT) devices within sectors like government services, energy, and water management. These attacks involved internet-exposed programmable logic controllers (PLCs), specifically mentioning devices from Rockwell Automation.
The attackers employed malicious project files to disrupt human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems. The updated advisory now includes Siemens and Schneider Electric as additional targets.
Investigative Findings and Attack Techniques
In a particular case in the US, the FBI discovered that attackers had used configuration software to download harmful project files onto a PLC. These files altered ladder logic, overriding safety instructions in the affected environment.
The advisory identifies attacks targeting Rockwell Automation’s CompactLogix and Micro850, Schneider Electric’s Modicon M340, and Siemens’ S7-1200 series PLCs. Hackers accessed these systems through specific ports and utilized software like Rockwell’s Studio 5000 Logix Designer, Schneider’s EcoStruxure Control Expert, and Siemens’ TIA Portal.
Implications and Response Measures
The advisory emphasizes the hackers’ ability to extract and manipulate PLC project files, disrupting critical shutdown and alarm logic. This allowed unsafe conditions to go unnoticed by operators.
New guidance and updated indicators of compromise (IoCs) have been provided to help organizations detect and mitigate these threats. Cybersecurity experts stress the importance of maintaining robust defenses against these advancing capabilities.
Iranian Hacker Groups and Recent Activities
Iranian government-linked hacker groups, often using hacktivist personas, have been implicated in these attacks. Notable among these are CyberAv3ngers and Handala, the latter recently claiming responsibility for an attack on US medical technology firm Stryker.
Handala has also been linked to a purported disruption attempt on California Water Service’s systems, though the utility reported no evidence of activity. The evolving threat landscape highlights the need for vigilant, updated cybersecurity practices.
Related reports indicate ongoing Iranian cyber activities, including the use of modular command-and-control frameworks and targeting of sectors like aviation and software with sophisticated tools.
