Insights, news, education and announcements from PolySwarm

Iranian PLC Exploitation Campaign Targets US Critical Infrastructure

Written by The Hivemind | Jul 27, 2026 6:18:15 PM

Verticals Targeted: Government, Water, Energy, Critical Infrastructure
Regions Targeted: US

Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the FBI, NSA, Department of Energy (DOE), Environmental Protection Agency (EPA), and US Cyber Command’s Cyber National Mission Force (CNMF), has released an update to a joint advisory warning that Iranian-affiliated threat actors are actively targeting internet-facing programmable logic controllers (PLCs) across multiple US critical infrastructure sectors. Rather than relying on sophisticated malware or zero-day exploits, the campaign focuses on exploiting exposed operational technology (OT) assets, manipulating PLC project files, and altering human-machine interface (HMI) and supervisory control and data acquisition (SCADA) displays to disrupt industrial operations.

Key Takeaways

  • Iranian-affiliated threat actors are exploiting internet-facing PLCs across US critical infrastructure to disrupt industrial operations.
  • Confirmed targets include the government services and facilities, water and wastewater systems, and energy sectors.
  • Rather than relying on custom malware, the actors leverage legitimate engineering software to modify PLC logic and manipulate HMI/SCADA displays.
  • The campaign uses the open-source Dropbear SSH utility to establish persistent remote access on compromised OT devices.

Background

According to the advisory, Iranian-affiliated advanced persistent threat (APT) actors have been exploiting internet-facing OT devices, particularly Rockwell Automation/Allen-Bradley PLCs, across multiple US critical infrastructure sectors. Targeted industries include government services and facilities, water and wastewater systems, and energy. The activity has resulted in malicious modification of PLC project files and manipulation of information displayed through HMI and SCADA systems, leading to operational disruption and financial losses in several incidents.

The authoring agencies note that the activity shares characteristics with previous operations attributed to CyberAv3ngers (also known as the Shahid Kaveh Group), an Iran linked threat actor associated with the Islamic Revolutionary Guard Corps (IRGC) Cyber Electronic Command. While the advisory stops short of formally attributing the current campaign to CyberAv3ngers, it highlights similarities in targeting and operational objectives.

The campaign demonstrates that nation-state actors continue to prioritize operational disruption over data theft when targeting industrial control systems (ICS). By leveraging internet-exposed PLCs and legitimate engineering tools, the actors can modify industrial processes without deploying large malware frameworks, reducing their operational footprint while increasing the potential for physical disruption. Organizations operating OT environments should prioritize reducing internet exposure, implementing network segmentation, and monitoring for unauthorized engineering activity.

Technical Analysis

Unlike many recent nation-state campaigns that rely heavily on custom malware or software vulnerabilities, this activity primarily exploits poor OT security practices. The actors target PLCs that are directly accessible from the public internet and use legitimate engineering software to establish authorized connections with industrial controllers. Once access is obtained, they manipulate PLC project files and alter data presented through HMI and SCADA interfaces, potentially causing operators to make incorrect decisions or disrupting industrial processes.

The advisory also references deployment of Dropbear, an open-source SSH server and client suite commonly used on embedded Linux systems. Rather than serving as malware itself, Dropbear provides persistent remote access following compromise, allowing operators to maintain administrative connectivity to affected OT devices. This reflects a broader trend in which threat actors increasingly abuse trusted administrative tools and legitimate software rather than relying exclusively on bespoke malware.

Current vs Historical Activity

This campaign reflects an evolution of previous Iranian OT operations rather than a fundamentally new capability. Earlier campaigns frequently combined destructive malware with disruptive objectives, whereas the current activity emphasizes direct manipulation of exposed industrial controllers using legitimate administrative functionality. This approach reduces development overhead while allowing attackers to achieve operational impact through misconfiguration, unauthorized engineering changes, and manipulation of operator interfaces.

The campaign also reinforces a longstanding concern within the OT community. Internet-exposed industrial assets remain one of the most attractive attack surfaces for nation-state adversaries. As IT and OT environments continue to converge, organizations that maintain publicly accessible control systems face increased risk from actors capable of leveraging readily available tools instead of sophisticated exploits.

Analyst Commentary

PolySwarm identified six samples associated with Dropbear, the SSH utility referenced throughout the advisory. Notably, two of those samples were first observed approximately six months before publication of the advisory, suggesting related artifacts were circulating prior to public disclosure of the campaign. This historical visibility demonstrates that while operational infrastructure may evade artifact-based intelligence platforms, malware and persistence utilities associated with OT intrusions can still provide valuable detection opportunities.

This campaign illustrates an important evolution in nation-state targeting of OT environments. While previous Iranian operations frequently drew attention for destructive malware or highly publicized attacks against industrial control systems, this campaign demonstrates that significant operational disruption no longer requires sophisticated custom malware. Instead, the actors achieve their objectives by exploiting internet-exposed PLCs, abusing legitimate engineering software, and leveraging trusted administrative tools already accepted within industrial environments.

The campaign reinforces a broader trend across the OT threat landscape. Rather than investing time and resources into developing custom implants that may be detected by endpoint security products, attackers are leveraging legitimate software, including engineering workstations, remote administration utilities, and open-source tools such as Dropbear, to blend into normal operational activity. As defenders improve malware detection capabilities, threat actors are shifting toward abusing trusted software and valid administrative workflows that generate fewer indicators of compromise while still providing persistent access and operational control.

From a defender's perspective, this significantly changes where detection efforts should be focused. Traditional IOC-based detection remains valuable, but organizations cannot rely solely on malware signatures or known malicious IP addresses to identify OT intrusions. Security teams should prioritize monitoring engineering workstations, unauthorized PLC programming events, unexpected configuration changes, and anomalous authentication activity within industrial networks. Behavioral detection, asset visibility, and configuration monitoring are becoming just as important as malware analysis in defending industrial environments.

The campaign also highlights a persistent security challenge that continues to plague critical infrastructure: internet-exposed industrial control systems. Public-facing PLCs remain attractive targets because they allow attackers to bypass traditional enterprise environments and interact directly with operational assets responsible for physical processes. Despite years of guidance from government agencies and equipment manufacturers, internet-accessible OT devices continue to provide nation-state actors with opportunities to achieve outsized operational impact using relatively straightforward intrusion techniques.

Looking forward, defenders should expect nation-state actors to continue favoring legitimate administrative utilities, trusted open-source software, and direct manipulation of industrial assets over increasingly detectable custom malware. This evolution places greater emphasis on operational visibility, secure remote access, continuous asset inventory, and anomaly detection within OT environments. Organizations that focus exclusively on malware prevention while neglecting exposure management and behavioral monitoring risk overlooking the very techniques that are becoming most prevalent in modern industrial intrusion campaigns.

IOCs

PolySwarm has multiple samples of Dropbear.

 

4f6eb44ebaa1de2e4913dc85b25854bca1f4d889d1fdf257b773dff82b08d043

6685fb1e02ae8e9e0227f699a678fd9fef34484aa6619c5835f58b062ed8c5e2

ea9eda3b60bc4bbab0d558cacf8f5fe24a1a8065d86b476bd7b10151e6883179

40d31f5c88b1fa2eeeac9dd1816a4b430bdc9ad3eb15b8f40da6b576ff1ede20

b90f268b5e7f70af1687d9825c09df15908ad3a6978b328dc88f96143a64af0f

64e8c5f675c44e13f24b0ff96175eca4b4d2271bd8256885b094af99d4f2ccfe

 

Click here to view all samples of Dropbear in our PolySwarm portal.

 

Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.

Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.