Executive Summary
In early 2026, the Iranian-affiliated cyber group CyberAv3ngers, linked to the Islamic Revolutionary Guard Corps (IRGC), launched a series of cyberattacks targeting U.S. critical infrastructure sectors, including water, energy, and local government facilities. The attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), such as CompactLogix and Micro850 models, to gain unauthorized access, manipulate data displayed on human-machine interfaces (HMIs), and disrupt operations. These incidents resulted in operational disruptions and financial losses for the affected organizations. (risidata.com)
This campaign underscores the escalating cyber threat posed by state-sponsored actors targeting industrial control systems (ICS) and operational technology (OT) environments. Organizations must prioritize securing internet-facing OT devices, implement robust access controls, and maintain up-to-date patch management to mitigate such risks.
Why This Matters Now
The CyberAv3ngers' attacks highlight the urgent need for organizations to secure internet-exposed operational technology devices, as state-sponsored cyber threats targeting critical infrastructure are escalating.
Attack Path Analysis
Iranian state-sponsored threat actors initiated the attack by exploiting unpatched vulnerabilities in public-facing applications, gaining unauthorized access to the target network. They then escalated privileges by leveraging credential theft tools like Mimikatz to obtain higher-level access. Utilizing Remote Desktop Protocol (RDP), the attackers moved laterally across the network to access critical systems. They established command and control channels using tools such as Fast Reverse Proxy (FRP) to maintain persistent access. Sensitive data was exfiltrated using FileZilla for file transfers. Finally, the attackers deployed ransomware, encrypting data and disrupting operations.
Kill Chain Progression
Initial Compromise
Description
Exploited unpatched vulnerabilities in public-facing applications to gain unauthorized access.
Related CVEs
CVE-2021-22681
CVSS 9.8An authentication bypass vulnerability in Rockwell Automation's Studio 5000 Logix Designer and RSLogix 5000 software allows unauthenticated remote attackers to gain unauthorized access to Logix controllers, potentially leading to manipulation of industrial processes.
Affected Products:
Rockwell Automation Studio 5000 Logix Designer – 21 and later
Rockwell Automation RSLogix 5000 – 16 through 20
Rockwell Automation CompactLogix – 1768, 1769, 5370, 5380, 5480
Rockwell Automation ControlLogix – 5550, 5560, 5570, 5580
Rockwell Automation DriveLogix – 5560, 5730, 1794-L34
Rockwell Automation Compact GuardLogix – 5370, 5380
Rockwell Automation GuardLogix – 5570, 5580
Rockwell Automation SoftLogix – 5800
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts: Default Accounts
Brute Force: Password Spraying
Phishing: Spearphishing Link
Remote Access Software
Application Layer Protocol: Web Protocols
Archive Collected Data: Archive via Utility
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity Pillar: Authentication
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Iranian hacktivist groups demonstrated capability to disrupt medical device manufacturers like Stryker, exploiting unpatched VPNs and default credentials in healthcare infrastructure.
Logistics/Procurement
GPS tracking platforms like Vyncs face direct targeting from Iranian state-sponsored groups, compromising fleet management and supply chain visibility across logistics operations.
Law Practice/Law Firms
Law firms with exposed programmable logic controllers or unpatched VPN systems represent appealing targets for Iranian hacktivist groups seeking easily exploitable vulnerabilities.
Utilities
Water utilities and power grids remain primary targets for Iranian-linked groups like Handala and Ababil, exploiting OT systems with default credentials and old vulnerabilities.
Sources
- Iran's Cyber Crosshairs Focus Beyond Critical Infrastructurehttps://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructureVerified
- Stryker cyberattack: Iranian group claims responsibility - 'Erased 200,000 systems, extracted 50 terabytes of data'https://www.livemint.com/news/us-news/stryker-cyberattack-iranian-group-handala-responsibility-erased-200000-systems-extracted-50-terabytes-of-data/amp-11773248213202.htmlVerified
- Stryker says it's restoring systems after pro-Iran hackers wiped thousands of employee deviceshttps://techcrunch.com/2026/03/17/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices/Verified
- Iran-linked group says it hacked US company in retaliation for Minab school bombinghttps://www.theguardian.com/world/2026/mar/12/iran-group-hack-medical-company-minab-schoolVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by enforcing strict segmentation and identity-based access controls, reducing the likelihood of unauthorized entry.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing strict identity-based access controls, reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been constrained by enforcing strict east-west traffic controls, reducing the reachability of critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could have been limited by enforcing consistent policies across multicloud environments, reducing unauthorized outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been constrained by enforcing strict egress policies, reducing unauthorized data transfers.
The attacker's ability to deploy ransomware could have been limited by reducing the blast radius through strict segmentation, potentially minimizing operational disruption.
Impact at a Glance
Affected Business Functions
- Order Processing
- Manufacturing
- Shipping
Estimated downtime: 15 days
Estimated loss: N/A
50 terabytes of data extracted, including potentially sensitive corporate information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust patch management to address vulnerabilities in public-facing applications.
- • Deploy credential theft detection tools to identify and mitigate unauthorized privilege escalation.
- • Enforce strict access controls and monitor RDP usage to prevent lateral movement.
- • Utilize command and control detection mechanisms to identify and block unauthorized communications.
- • Establish data loss prevention measures to monitor and control data exfiltration attempts.



