US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

The US government has updated a recent cybersecurity advisory describing Iran-linked attacks on critical infrastructure organizations, warning that hackers have been targeting industrial control systems (ICS) made by Siemens, Schneider Electric, and Rockwell Automation.

The advisory was initially published in early April, when federal agencies said Iranian hackers had been conducting disruptive attacks targeting operational technology (OT) devices at organizations in the government services and facilities, energy, and water and wastewater sectors. 

The authoring agencies said at the time that threat groups had hacked internet-exposed programmable logic controllers (PLCs), naming Allen-Bradley devices made by Rockwell Automation.

The hackers had used malicious PLC project files and manipulated the data displayed on human-machine interfaces (HMIs) and supervisory control and data acquisition (SCADA) systems.

The updated advisory, published on July 22, adds Schneider Electric and Siemens to the list of vendors whose PLCs have been targeted by Iranian APT actors and notes that devices from other companies may also be targeted.

In the case of one victim in the United States, FBI investigators discovered that the attacker had used configuration software to download a malicious project file to a PLC.

Advertisement. Scroll to continue reading.

“Analysis indicated the project file retained ladder logic for downstream function but added logic that overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment,” the updated advisory explains.

Investigators are aware of attacks against Rockwell Automation CompactLogix and Micro850, Schneider Electric Modicon M340 (BMX P34), and Siemens S7-1200 series PLCs.

The attacks targeted ports 44818, 2222, 102, 502, and 22, and the hackers connected to the vulnerable PLCs via manufacturers’ programming software and leased third-party-hosted infrastructure.

The vendor configuration software targeted by APTs includes Rockwell Automation Studio 5000 Logix Designer, Schneider Electric EcoStruxure Control Expert, and Siemens TIA Portal.

According to the updated advisory, the hackers extracted and exfiltrated PLC project files and then modified and deleted the logic in those files. The attackers included add-on instructions and manipulated data on HMI and SCADA displays. 

“Additionally, the changes disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies,” the advisory notes.

The advisory now includes new guidance for detecting malicious activity, as well as updated indicators of compromise (IoCs).

Iranian hacker groups targeting ICS/OT

The Iranian government has been using hacktivist personas to carry out many of the attacks targeting ICS/OT. The group named CyberAv3ngers made many headlines in the past years for its attacks on such systems.

A group named Handala has taken the lead this year, starting with a highly disruptive attack on the US medical technology giant Stryker

Last month, Handala claimed it could have disrupted the water supply after hacking systems owned by California Water Service (Cal Water). 

The hackers’ statements suggested they had gained deep access to ICS, but the water utility said it had found no evidence of activity in its OT environment. 

While cyber adversaries once focused primarily on exposed, poorly secured ICS, these latest findings demonstrate that their capabilities are steadily advancing, underscoring the need for organizations to maintain proactive, up-to-date defenses.

Related: Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks

Related: LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

Related: Iranian APT Targets Aviation, Software Companies With Updated Tools

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *