Iranian Hackers Hit Siemens, Schneider Industrial Systems

▼ Summary
– Iranian cyber adversaries are targeting industrial control systems from Rockwell Automation, Allen-Bradley, Schneider Electric, and Siemens, with the FBI observing a malicious project file downloaded to a PLC at a US critical infrastructure organization.
– The attack involved manipulating HMI and SCADA displays to cause operational disruption and financial loss, with added logic overriding safe operating parameters while retaining downstream functions.
– The campaign, linked to Iran’s Islamic Revolutionary Guard Corps, targets PLCs across sectors like government, water, and energy, using configuration software on leased infrastructure to exfiltrate device project files.
– Security experts note the threat is becoming less product-dependent, focusing on common weaknesses across multiple OT environments, allowing attackers to reuse playbooks on exposed devices with weak access controls.
– Mitigation recommendations include removing PLCs from direct internet exposure, querying logs for indicators of compromise, and maintaining trusted backups and tested recovery procedures for critical infrastructure.
Iranian state-linked hackers are actively targeting industrial control systems from major manufacturers including Siemens, Schneider Electric, Rockwell Automation, and Allen-Bradley, according to a new advisory from the US Cybersecurity and Infrastructure Security Agency (CISA).
The July 22 update confirms that the FBI observed Iran-affiliated threat actors downloading a malicious project file to a programmable logic controller (PLC) at a US critical infrastructure organization. The attackers used configuration software to gain access and then manipulated data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, causing both operational disruption and financial losses.
Further forensic analysis revealed that the compromised project file retained the original ladder logic for downstream functions but added malicious logic that overrode safety-critical instruction sets. This effectively disabled the safeguards responsible for maintaining safe operating parameters within the victim’s environment.
This advisory follows an April warning about an ongoing Iranian cyber campaign targeting US critical infrastructure. That initial alert named Rockwell Automation and Allen-Bradley PLCs as primary targets, after attackers exploited reusable code modules within Rockwell PLC programs.
The July update expands the scope significantly. It confirms that the same advanced persistent threat (APT) actors are now also targeting PLCs from Schneider Electric and Siemens. The attackers are using legitimate configuration software , including Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert, and Siemens’ Totally Integrated Automation (TIA) Portal , on leased, third-party hosted infrastructure to exfiltrate device project files to threat-controlled servers.
CISA identified specific models under attack: Allen-Bradley’s CompactLogix and Micro850, Schneider Electric’s BMX P34 and Modicon M340, and Siemens’ S7-1200 series. The agency warned that PLCs from other manufacturers could also “potentially” be targeted.
While the advisory did not name a specific group, CISA noted that the campaign shares similarities with a November 2023 operation linked to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC CEC) . That group, commonly tracked as CyberAv3ngers, is also known as Bauxite, Hydro Kitten, the Shahid Kaveh Group, Soldiers of Solomon, Storm-0784, and UNC5691.
Nick Tausek, lead security automation architect at Swimlane, said the latest update moves the threat “beyond broad concern and into specific, actionable detail.” Security teams now have new indicators, targeted ports, affected device families, and concrete examples of attackers altering PLC logic or disabling critical safeguards.
Pete Luban, field CISO at AttackIQ, emphasized that the campaign shows Iranian cyber activity becoming less dependent on a single product and more focused on recurring weaknesses across operational environments. “By targeting controllers from several manufacturers, attackers can reuse the same playbook wherever exposed devices and weak access controls exist,” Luban said.
Tausek warned that the real challenge is getting intelligence into active workflows before attackers move again. “That’s hard to do when asset data, network alerts, threat intelligence, and incident procedures live in separate systems. Security teams may understand the threat, but still lose valuable time gathering context and determining which exposed devices require immediate attention,” he added.
CISA urged US critical infrastructure providers to take immediate mitigation steps. These include installing PLCs according to manufacturer guidelines and security best practices, removing PLCs from direct internet exposure via secure gateways and firewalls, and querying available logs for the provided indicators of compromise (IOCs) . Organizations should also check for suspicious traffic on ports commonly associated with OT devices, including 44818, 2222, 102, and 502. For Rockwell Automation devices, operators should place the physical mode switch on the controller into the run position.
Ross Filipek, CISO at Corsica Technologies, noted that the biggest challenge for affected organizations is that most cannot pause operations while investigating an incident. “Water utilities have to keep providing clean water. Energy providers have to maintain power and fuel availability. Local governments still need to support emergency services and public operations. Even a short disruption can force employees into slower manual processes, delay essential services, and create public safety concerns.”
He stressed that trusted backups of PLC logic, tested recovery procedures, and experienced responders are critical. “A single exposed controller may look like a local weakness. In critical infrastructure, it can become part of a much larger national security problem,” Filipek said.
(Source: Infosecurity Magazine)