US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury) updated joint advisory AA26-097A on 22 July 2026 — first published in April 2026 on Iranian-affiliated exploitation of internet-connected, misconfigured programmable logic controllers (CISA, 2026-07-22). The update's substance is a widened scope and new detection guidance: targeting previously centred on Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers is now confirmed to include Schneider Electric Modicon M340 and Siemens S7-1200 series controllers — both with large installed bases across European water and energy utilities (CISA News, 2026-07-22). There is no underlying software CVE: the actors scan common ICS ports (44818/2222 EtherNet/IP, 102 Siemens S7comm, 502 Modbus TCP, and 22 for Dropbear SSH on victim modems), then connect using the manufacturers' own engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) run from leased infrastructure with credentials obtained from weakly-protected devices, and pull down device project files (Trend Micro, 2026-07-23). The current campaign manipulates control logic directly and has produced confirmed operational disruption and financial loss: the actors modify or delete PLC logic — including reusable Add-On Instructions — and manipulate HMI/SCADA display data to disable shutdown and alarm logic, letting systems enter unsafe states without operator notification (CISA News, 2026-07-22).
The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations.
Review project files running on PLCs for unauthorized changes. Use vendor-provided integrity checking tools and visually compare the running program to known good logic.
Defender actions
- Baseline the running logic and Add-On Instructions on any internet-reachable Rockwell, Schneider Modicon M340 or Siemens S7-1200 PLC against a known-good copy, and alert on unauthorised changes — the actors disable shutdown/alarm interlocks so HMI displays mask unsafe states.
ATT&CK mapping
3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Reconnaissance TA0043
T1595Active Scanning
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Impact TA0040
T1565Data Manipulation
Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to affect a business process, organizational understanding, or decision making.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.