On July 22, the US Cybersecurity and Infrastructure Security Agency (CISA) said the FBI observed Iran-affiliated cyber threat actors download a malicious project file to a targeted programmable logic controller (PLC) at a US-based critical infrastructure organization.
What CISA and the FBI observed
In an advisory update published July 22, CISA reported that the FBI had documented actors using legitimate configuration software to pull device project files from victim PLCs onto threat-actor-controlled infrastructure hosted on leased third‑party systems. The Bureau also saw manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays; CISA tied those manipulations to operational disruption and financial loss.
Analysis of one recovered project file, CISA said, showed that while ladder logic for downstream function was retained, the file added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim environment.
Software and technique: configuration suites used to exfiltrate project files
CISA identified the configuration suites observed in the activity by name: Rockwell Automation’s Studio 5000 Logix Designer, Schneider Electric’s EcoStruxure Control Expert and Siemens’ Totally Integrated Automation (TIA) Portal. The advisory said those tools were used on leased, third‑party hosted infrastructure to exfiltrate project files from PLC devices to infrastructure controlled by the threat actors.
Those project files — the agency wrote — can contain run-time logic and configuration that, if altered, may change how controllers enforce safety and operational limits.
Models and vendors specifically named
The update expanded the set of affected vendors and models beyond those named in an April advisory. CISA named specific PLC models targeted in the campaign: Allen‑Bradley CompactLogix and Micro850 PLCs, Schneider Electric BMX P34 and Modicon M340 models, and Siemens S7‑1200 series PLCs. The April advisory had already named Rockwell Automation and its Allen‑Bradley subsidiary as targets after detection of malicious changes in reusable code modules exploited within Rockwell PLC programs.
The agency also said PLCs of other brands could also “potentially” be targeted.
Historical linkage and suspected actor patterns
While CISA did not name a specific threat group in the July update, the agency noted the ongoing campaign bears similarities to a November 2023 operation that involved a group affiliated with the Islamic Revolutionary Guard Corps Cyber‑Electronic Command (IRGC CEC). That group is commonly known as ‘CyberAv3ngers’ and tracked under a range of names by cybersecurity companies, including Bauxite, Hydro Kitten, the Shahid Kaveh Group, Soldiers of Solomon, Storm‑0784 and UNC5691.
How CISA tells US critical infrastructure providers to respond
- Install PLCs consistent with manufacturers' guidelines and security best practices.
- Remove PLCs from direct internet exposure by placing them behind a secure gateway and firewall.
- Query available logs for the indicators of compromise (IOCs) provided in the advisory and check logs for suspicious traffic on ports associated with OT devices, including 44818, 2222, 102 and 502.
- For Rockwell Automation devices, place the physical mode switch on the controller into the run position.
For technologists and security teams working in government services, water and wastewater, and energy — sectors CISA previously identified as disrupted by the campaign — the update raises an immediate operational priority: inventory internet‑exposed PLCs and search historic logs for IOC traces tied to configuration‑tool access. For procurement and asset owners at facilities using the named models, the advisory makes clear that vendor‑recommended installation and network segmentation are not optional mitigations but active defenses against project‑file tampering that can change safety logic.
The July advisory reaffirms a core risk: adversaries are not limited to bespoke malware that directly controls physical processes, but can weaponize legitimate engineering tools and project files to modify device behavior. CISA’s guidance focuses on cutting off direct exposure, inspecting logs for telltale activity on known OT ports, and applying vendor configuration and physical‑mode steps that can reduce the opportunity for tampering. Whether those steps will deter actors using third‑party hosted infrastructure to stage exfiltration will depend on how quickly affected organizations can identify exposures and remediate them.
Original advisory: https://www.infosecurity-magazine.com/news/iran-hackers-siemen-schneider-ics/




