"The targeting of ports associated with other OT vendors' protocols suggests these actors are opportunistically targeting devices manufactured by companies other than Rockwell Automation/Allen‑Bradley, including Schneider Electric and Siemens," the US Cybersecurity and Infrastructure Security Agency (CISA) warned in an expanded advisory.
CISA broadens advisory beyond Rockwell Automation/Allen‑Bradley
CISA has expanded an earlier alert that initially focused on programmable logic controllers (PLCs) from Rockwell Automation/Allen‑Bradley. The updated advisory states that Iranian‑affiliated advanced persistent threat crews may also be probing devices from Schneider Electric, Siemens, "and potentially other branded/manufactured PLCs." The agency tied the activity to attempts to gain access to internet‑facing PLCs used to control and monitor industrial processes.
Observed tactics: open ports, Dropbear SSH, and project‑file theft
Authorities reported the attackers have been exploiting open ports on internet‑exposed devices. In one documented instance, the actors used Dropbear Secure Shell (SSH) software on victim modems to gain remote access through port 22. Once inside, attackers extracted device project files and modified or deleted logic, according to CISA's advisory.
Operational impact: disabling alarms and shutdown logic
CISA warned the changes made by intruders went beyond simple disruption. "Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies," the agency said. Authorities noted the activity resembled earlier PLC attacks by CyberAv3ngers (also known as the Shahid Kaveh Group), a crew linked to Iran's Islamic Revolutionary Guard Corps Cyber Electronic Command.
Context: an ongoing conflict and months of targeting
Authorities say the activity has been observed since March and that the conflict between the US and Iran is well into its fourth month. CISA emphasized the focus is principally on internet‑facing PLCs and that the adversaries appear opportunistic, scanning for ports associated with multiple operational technology vendors rather than limiting themselves to a single manufacturer.
What this means for technologists, service providers, and water and energy operators
- Technologists and security teams: Verify which PLCs are internet‑facing, inspect project files for unauthorized changes, and ensure default passwords are changed, as CISA recommends.
- Service providers: Be aware of targeted activity against PLCs and coordinate with customers to limit remote exposure of industrial equipment.
- Water and energy operators: Consider disconnecting PLCs from the public internet, implementing isolated architectures, and controlling network access to PLC devices to reduce the risk of remote tampering.
Practical mitigations CISA highlights
CISA reiterated earlier mitigations and added emphasis on organizational awareness. The agency recommended disconnecting PLCs from the public‑facing internet where possible, implementing isolated network architectures, and enforcing stricter access controls to PLC devices. Operators should check project files running on PLCs for unauthorized changes and ensure service providers are aware of threats targeting PLCs. Changing default passwords was also listed among the practical, immediate steps.
The advisory's expansion from a single vendor to multiple PLC makers frames a clear operational challenge: adversaries are scanning and exploiting exposed equipment across vendor boundaries, extracting project configurations and altering control logic that can silence alarms and disable safe shutdowns. The facts laid out by CISA leave an actionable ledger for operators to follow — and a pointed open question: which additional PLC manufacturers, if any, will be named in future alerts as the probes continue.




