Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion.
The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned by the FBI, CISA, NSA, EPA, the Department of Energy, and U.S. Cyber Command.
Attackers scan the internet for exposed PLCs and connect using legitimate engineering software the same way an authorized technician would, then alter controller logic and, in some cases, falsify what appears on operator screens.
Hackers Exploit Industrial PLCs
This activity has already caused confirmed operational disruption and financial loss for some victims, a sharp escalation from the largely disruption-free 2023 campaign against Unitronics PLCs that relied on default passwords.
Trend Micro stated that the July update expands beyond Rockwell Automation and Allen-Bradley CompactLogix and Micro850 controllers to include Schneider Electric and Siemens equipment.
It also adds detection guidance for malicious changes hidden inside reusable code modules, meaning a single tampered logic block can silently propagate across an entire operation through shared engineering libraries.
The updated mitigations specifically call for validating project files running on PLCs for unauthorized changes and ensuring service providers are informed of the active threat.
Targeted sectors include government facilities and local municipalities, water and wastewater systems, and energy infrastructure. Malicious traffic tied to the campaign has been observed on five ports: 22 (SSH), 102 (ISO-TSAP/Siemens S7comm), 502 (Modbus TCP), 2222 and 44818 (EtherNet/IP).
Because the intrusions use valid credentials and legitimate software rather than exploiting a software flaw, this is described as an architectural weakness rather than a patchable vulnerability, since Shodan data still shows tens of thousands of ICS devices directly reachable from the open internet.
Organizations are urged to act immediately by removing PLCs from direct internet exposure and routing all remote access through a secured gateway with multifactor authentication.
Where available, physical mode switches should be set to RUN rather than PROGRAM or REMOTE outside supervised maintenance windows, and defenders should search firewall and intrusion detection logs for the advisory’s published IP indicators on ports 22, 102, 502, 2222, and 44818.
Over the coming quarter, operators should enable programming protection through vendor-specific guidance, such as Rockwell’s SD1771 standard or Siemens TIA Portal configuration, and maintain offline, tested backups of PLC logic separate from the production network.
The advisory also presses manufacturers to ship products that do not expose administrative interfaces to the internet by default, to support phishing-resistant MFA.
Because the intrusion method relies on legitimate software and valid credentials rather than a software bug, agencies stress that organizations must validate these controls continuously rather than through a one-time compliance check.
IOCs
| IoC | Detection |
| 185.82.73[.]175 | 91 – C&C server |
| 141.11.164[.]153 | 91 – C&C server |
| 175.110.121[.]42 | 91 – C&C server |
| 175.110.121[.]39 | 91 – C&C server |
| 175.110.121[.]41 | 38 – Computers/Internet |
| 175.110.121[.]107 | 91 – C&C server |
| 192.142.54[.]79 | 38 – Computers/Internet |
| 84.200.205[.]165 | 38 – Computers/Internet |
| 185.225.17[.]225 | 91 – C&C server |
| 79.133.46[.]209 | 91 – C&C server |
| 88.80.150[.]199 | 91 – C&C server |
| 88.80.150[.]200 | 91 – C&C server |
| 88.80.150[.]202 | 91 – C&C server |
| 185.82.73[.]162 | 91 – C&C server |
| 185.82.73[.]164 | 91 – C&C server |
| 185.82.73[.]165 | 91 – C&C server |
| 185.82.73[.]167 | 91 – C&C server |
| 185.82.73[.]168 | 91 – C&C server |
| 185.82.73[.]170 | 91 – C&C server |
| 185.82.73[.]171 | 91 – C&C server |
| 135.136.1[.]133 | 91 – C&C server |
| ocferda[.]com | 91 – C&C server |
| uuokhhfsdlk[.]tylarion867mino[.]com | 91 – C&C server |
| tylarion867mino[.]com | 91 – C&C server |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

