US: Iran-linked hackers target Siemens, Schneider, Rockwell PLCs

U.S. agencies warned Iran-linked hackers are using vendor programming tools to exfiltrate and alter PLC project files on Siemens, Schneider Electric and Rockwell devices.
U.S. federal agencies updated a cybersecurity advisory on July 22 saying Iran-linked hackers have been targeting programmable logic controllers from Siemens, Schneider Electric and Rockwell Automation. The attackers used vendor programming software to download, exfiltrate and modify PLC project files and change control logic at critical infrastructure sites.
The first advisory was published in early April and focused on disruptive attacks against operational technology in the government services, energy, and water and wastewater sectors. The July update adds Schneider and Siemens to the list of affected vendors and notes that devices from other manufacturers may also be targeted.
The advisory reports the attackers modified ladder logic, disabled shutdown and alarm routines, and altered data shown on human-machine interfaces and SCADA displays. In one U.S. victim case, FBI investigators found configuration software was used to download a malicious project file to a PLC. Analysis showed the project file kept downstream ladder logic but added instructions that overrode specific instruction sets responsible for maintaining safe operating parameters.
Investigators identified targeted devices including Rockwell Automation CompactLogix and Micro850 controllers, Schneider Electric Modicon M340 (BMX P34) PLCs, and Siemens S7-1200 series controllers. The advisory lists targeted network ports 44818, 2222, 102, 502 and 22.
Attackers connected to vulnerable PLCs through manufacturers’ programming software and via leased third-party-hosted infrastructure, then extracted and exfiltrated project files before modifying or deleting logic. The vendor tools named in the alert include Rockwell Studio 5000 Logix Designer, Schneider EcoStruxure Control Expert and Siemens TIA Portal.
The advisory attributes many campaigns to Iran-linked advanced persistent threat actors using hacktivist personas. It cites groups such as CyberAv3ngers and a newer group known as Handala, which claimed responsibility for disruptive incidents this year, including an attack on a medical-technology firm and a claimed intrusion at a water utility where the utility reported finding no evidence of activity in its OT environment.
The update adds technical indicators and detection guidance for defenders. It warns that attacker techniques have expanded beyond internet-exposed, poorly secured devices to include operations that use vendor development tools and third-party infrastructure.
Recommended actions include reviewing remote access configurations, limiting exposure of programming ports to the internet, monitoring for unexpected project-file transfers, and verifying the integrity of PLC logic and HMI displays. The advisory also recommends coordinating with law enforcement and cyber response agencies when malicious activity is observed.





