CTIPilot

Schneider Electric Modicon M340

product · product:schneider-electric-modicon-m340

Coverage timeline
1
first 2026-07-24 → last 2026-07-24
Peak priority
notable
1 notable
Sources cited
3
2 hosts
Sections touched
1
active-threats
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below

Hunting pivots

Releases covered
Schneider Electric Modicon M340
ATT&CK techniques

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Impact TA0040

T1565Data Manipulation×1

Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.

Evidence: 2026-07-24/cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion · ATT&CK page ↗

Story timeline

  1. 2026-07-24US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
    active-threatsIran-linked PLC intrusions now hit Schneider and Siemens gear; the fix is exposure and integrity checking, not a patch

Where this entity is cited

  • active-threats1

Source distribution

  • cisa.gov2 (67%)
  • trendmicro.com1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Schneider Electric Modicon M340 (1)

2026-07-24 · view entry permalink →

NOTABLEexploitedNATOA2

US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection

Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury) updated joint advisory AA26-097A on 22 July 2026, first published in April 2026 on Iranian-affiliated exploitation of internet-connected, misconfigured programmable logic controllers (CISA, 2026-07-22). The update's substance is a widened scope and new detection guidance: targeting previously centred on Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers is now confirmed to include Schneider Electric Modicon M340 and Siemens S7-1200 series controllers, both with large installed bases across European water and energy utilities (CISA News, 2026-07-22). There is no underlying software CVE: the actors scan common ICS ports (44818/2222 EtherNet/IP, 102 Siemens S7comm, 502 Modbus TCP, and 22 for Dropbear SSH on victim modems), then connect using the manufacturers' own engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) run from leased infrastructure with credentials obtained from weakly-protected devices, and pull down device project files (Trend Micro, 2026-07-23). The current campaign manipulates control logic directly and has produced confirmed operational disruption and financial loss: the actors modify or delete PLC logic (including reusable Add-On Instructions) and manipulate HMI/SCADA display data to disable shutdown and alarm logic, letting systems enter unsafe states without operator notification (CISA News, 2026-07-22).

The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations.

CISA News 2026-07-22

Review project files running on PLCs for unauthorized changes. Use vendor-provided integrity checking tools and visually compare the running program to known good logic.

CISA / FBI / NSA / EPA / DoE / USCYBERCOM / Treasury (joint advisory AA26-097A, updated) 2026-07-22
threat24 Jul 04:36Zmulti-sourceOpen finding ↗