Iranian state-sponsored actors exploit industrial control system supply chain via Siemens, Schneider Electric, and Rockwell devices
US federal agencies have published updated advisory detailing techniques used by Iranian-linked threat actors to compromise programmable logic controllers from major industrial automation vendors, with direct implications for critical infrastructure security.
Affected
US federal agencies have issued an updated advisory documenting attack techniques deployed by Iranian state-sponsored actors against industrial control systems. This campaign specifically targets programmable logic controllers from three major vendors supplying critical infrastructure sectors including power generation, water treatment, and manufacturing. The threat actors are employing PLC-specific exploitation methods rather than generic network intrusion techniques, indicating a sophisticated understanding of industrial automation environments.
The attack chain likely involves initial network access through conventional means (phishing, credential compromise, supply chain vectors) followed by lateral movement to isolated operational technology networks. Once inside an ICS environment, the actors deploy techniques that interact directly with PLC firmware, configuration, or runtime state. This approach circumvents traditional IT security controls and creates a situation where network segmentation and firewall rules alone cannot prevent compromise of critical process control logic. The specificity of targeting these three vendors suggests either prior reconnaissance of target environments or a broad exploitation strategy that exploits common PLC architectures and exposed interfaces.
Organisations operating these platforms face a multi-layered threat. First, if deployed in direct-to-internet configurations or weakly segmented networks, systems could be compromised by automated scanning tools. Second, organisations with existing network footholds from prior breaches now face a second-stage exploitation vector. Third, even well-segmented environments may be vulnerable if they rely on shared engineering workstations, vendor support access, or supply chain connections that attackers can infiltrate. The advisory's technical details are critical for security teams to understand exactly which PLC models, firmware versions, or configuration approaches are exploitable.
Defenders should immediately: inventory all deployed PLC models and firmware versions from these three vendors; review network segmentation and access controls to PLC management interfaces; implement deep packet inspection rules for PLC communication protocols (Profinet, EtherNet/IP, Modbus); ensure PLC change control processes have human oversight; deploy anomaly detection focused on unusual PLC parameter modifications or program uploads. Organisations without direct visibility into PLC operations should contract specialist ICS security firms for assessment.
This campaign reflects a shift in state-sponsored ICS targeting toward operational disruption capabilities rather than pure reconnaissance. The maturity of these techniques and their targeting of specific industrial verticals suggests this activity is likely to persist and potentially expand to additional vendors. The attack surface remains difficult to patch in operational environments given the business-critical nature of these systems and the need to maintain uptime.
Sources