← Back to Daily Briefing (#ICS)

IRGC-linked threat actor "Cyber Av3ngers" is targeting U.S. critical infrastructure by exploiting internet-exposed Unitronics Programmable Logic Controllers (PLCs). Attackers leverage default credentials and exposed web interfaces to manipulate PLC logic and disrupt industrial control protocols, specifically targeting the water and wastewater sectors across 12 states. Impact includes operational downtime of up to 12 hours in municipalities such as Cape May and Childersburg. The campaign signals a shift toward kinetic operational disruption via the manipulation of Modbus and proprietary Unitronics communication patterns, requiring immediate remediation of internet-facing OT assets.

  • Incident Overview: State-Sponsored Disruption

    • Coordinated campaign attributed to Iranian-linked entities (IRGC) targeting U.S. water and wastewater utilities.
    • Impact confirmed across 12 states, with high activity in New Jersey, Alabama, Minnesota, Utah, and Georgia.
    • Strategic shift from espionage/data theft to operational disruption intended to cause public alarm and demonstrate capability.
  • Attack Vector: OT Exposure & Exploitation

    • Primary vector is the exploitation of Unitronics PLCs directly exposed to the public internet.
    • Initial access achieved through the use of default administrative credentials or vulnerable web-based management interfaces.
    • Attackers manipulate PLC logic and industrial control protocols to interfere with physical water utility operations.
  • Operational Impact: Critical Infrastructure Downtime

    • Documented service outages of approximately 12 hours in specific municipalities, including Cape May, Woodbines, and Childersburg.
    • Strong correlation between the absence of network segmentation and successful compromise of OT environments.
    • Emerging evidence suggests the threat profile is expanding beyond water sectors into energy and government infrastructure.
  • Technical Indicators: IoCs and Detection

    • Identification of unauthorized Modbus traffic and proprietary Unitronics communication patterns.
    • IoCs include malicious IP addresses and command-and-control (C2) domains facilitating unauthorized PLC logins.
    • Detection focuses on anomalous login attempts to OT interfaces originating from non-standard geographic regions.
  • Defensive Actions: Mitigation & Remediation

    • Immediate decommissioning of all internet-facing PLCs and OT assets to eliminate the primary attack surface.
    • Mandatory update of all default passwords and implementation of complex, unique credentials for OT hardware.
    • Deployment of strict network segmentation and the use of secure VPNs for any required remote administrative access.

Related posts

  1. threatlabsnews.xcitium.com — Iran-Linked Water Attacks Now Confirmed in 12 States
  2. techcrunch.com — What we know about the alleged Iranian hacks on U.S. water utilities
  3. techjacksolutions.com — IRGC-Linked Campaign Hits Water Utilities Across 12 States: OT Exposure Drives Operational Impact
  4. Epa
  5. Darkreading
  6. Csis
  7. Facebook
  8. Rescana
  9. Sitepro
  10. Ksl
  11. Setechnical

LINK COPIED TO CLIPBOARD