CISA Widens Its Iranian PLC Warning to Siemens and Schneider, and Names Safety Logic as the Target
An advisory first published in April was updated on 22 July to cover three controller manufacturers instead of one. The technique it describes involves no vulnerability and no patch.
Joint advisory AA26-097A, “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure,” was updated on 22 July, expanding its scope from Rockwell Automation equipment to include Schneider Electric, Siemens “and potentially other branded/manufactured PLCs.” The models named, per SecurityWeek’s reading of the document, are the Rockwell CompactLogix and Micro850, the Schneider Modicon M340 (BMX P34) and the Siemens S7-1200 series. The sectors listed as having suffered operational disruption and financial loss are Government Services and Facilities, Water and Wastewater Systems, and Energy. The most specific line in the document concerns an FBI investigation at an unnamed US critical-infrastructure victim, where an actor used legitimate vendor configuration software to push a malicious project file to a controller. The file, in CISA’s own wording, “retained ladder logic for downstream function” while adding logic that “overrode specific instruction sets responsible for maintaining safe operating parameters.”
The technical framing matters more than the vendor list. Burns & McDonnell’s 1898 & Co. notes the activity maps to ICS ATT&CK techniques for internet-accessible devices and commonly used ports — exposure and legitimate tooling, not a software flaw — and OffSeq’s summary is explicit that the advisory specifies no patch. WaterISAC’s member notice says the update adds Exfiltration Over C2 Channel (T1041), describing vendor configuration software run from leased infrastructure to pull project files out. CISA names no group for the 2026 activity, noting only its resemblance to a campaign begun in November 2023 by CyberAv3ngers, described as affiliated with the IRGC Cyber Electronic Command and tracked elsewhere as Hydro Kitten, Storm-0784 and Bauxite. The Register places the current phase as running since March.
Assessment: Read the calendar before the content. This is an update to an April document, itself building on advisories dating to late 2023, and much of the 23–25 July coverage — including CISA’s own freshness stamp — will read as a fresh warning about a fresh campaign. It is neither. What is new is the manufacturer scope, and that is the part with implications outside the United States: Siemens and Schneider controllers are deployed far more widely in Europe and the Gulf than Rockwell. No ENISA, NCSC, UAE or Saudi parallel advisory had appeared as of Sunday. Two things to watch: whether the unnamed victim surfaces through a utility disclosure, and whether Treasury’s reported addition as co-author — a department that does not normally co-sign detection guidance — precedes designations.