CyberAv3ngers: IRGC-Affiliated PLC Exploitation Across U.S. Critical Infrastructure
RedSheep Reports | August 21, 2026
Multiple federal agencies are warning that an IRGC-affiliated threat group is actively exploiting programmable logic controllers (PLCs) across U.S. critical infrastructure, including water systems, energy facilities, and government installations [1][2]. The joint advisory AA26-097A, originally published April 7, 2026 and substantially updated July 22, 2026, documents confirmed operational disruption and financial loss at victim organizations [2]. The group, tracked as CyberAv3ngers (also Storm-0784, Bauxite, Hydro Kitten, Mr. Soul, UNC5691, Soldiers of Solomon, and the Shahid Kaveh Group), has been active against these targets since at least early 2026, with attacker infrastructure dating to January 2025 [1][4].
This is not the group's first campaign against ICS environments. But the current activity represents a material escalation in both capability and impact compared to their 2023 operations against Unitronics PLCs [4].
Threat Actor Background
CyberAv3ngers is assessed by the U.S. government to operate as a persona for Iran's IRGC Cyber-Electronic Command (IRGC-CEC) [1][4]. In February 2024, the U.S. Treasury sanctioned six IRGC-CEC officials for directing CyberAv3ngers operations, including Hamid Reza Lashgarian, head of IRGC-CEC [4]. The State Department offered up to $10 million through the Rewards for Justice program for information on CyberAv3ngers' activities and personnel [4].
The group's operational history shows a clear progression [4]:
- 2020 to 2022: Propagandistic claims of Israeli infrastructure disruption with no technical evidence.
- October 2023 to January 2024: Compromised Unitronics Vision Series PLCs, predominantly in U.S. water facilities, by exploiting default credentials on internet-exposed devices [2][4].
- 2024 to 2025: Deployed IOCONTROL, a custom Linux-based malware platform targeting IoT/OT devices (IP cameras, fuel management systems, routers) using MQTT over TLS to blend with legitimate traffic [4].
- March 2026 to present: Active exploitation of Rockwell Automation, Schneider Electric, and Siemens PLCs across U.S. critical infrastructure.
The shift from Unitronics to Rockwell Automation was first identified by Unit 42 in late March 2026. They track the activity cluster as CL-STA-1128 and assess with moderate confidence that the attacker installed Rockwell Automation's FactoryTalk software on virtual private server (VPS) infrastructure to enable exploitation [3]. As of April 2026, Cortex Xpanse scanning observed Rockwell Automation or Allen-Bradley SCADA devices, including FactoryTalk services and various PLCs, on 5,600 IP addresses globally [3].
Healthcare and Medical OT Relevance
The advisory identifies government facilities, water systems, and energy infrastructure as targeted sectors [2]. Healthcare is not explicitly named in the current advisory. However, Red Sheep assesses that hospital and clinic OT environments are a relevant area of concern based on the following factors. Many healthcare facilities operate building automation systems (BAS), HVAC controllers, medical gas monitoring, and pharmacy automation that rely on PLCs from the affected manufacturers (Rockwell, Schneider, Siemens). Medical IoT devices, including infusion pump management systems and laboratory automation equipment, frequently share network segments with industrial controllers. Organizations operating in the military health system, TRICARE network, and federal healthcare should treat this advisory as directly applicable to their OT and medical IoT environments.
What Changed in the July 2026 Update
The April advisory focused primarily on Rockwell Automation and Allen-Bradley PLCs. The July 22 revision made three significant changes [1][2]:
- Expanded manufacturer scope. The advisory now covers Schneider Electric and Siemens equipment and explicitly notes that other manufacturers may also be targeted [2].
- New detection guidance for Add-On Instructions (AOIs). The update added specific guidance for detecting malicious changes hidden in reusable code modules within Rockwell Automation PLC programs [1][2]. CyberAv3ngers developed and deployed custom ladder logic code, replacing valid ladder logic with malicious code that continues to be observed in victim environments [1].
- Confirmed operational impact. Unlike the 2023 campaign, which was largely disruptive without causing lasting damage, this activity has resulted in confirmed operational disruption and financial loss [2].
The advisory was co-authored by the FBI, CISA, NSA, EPA, Department of Energy, U.S. Cyber Command's Cyber National Mission Force (CNMF), and the Department of the Treasury [1].
Initial Access and Reconnaissance
Attackers scan the internet for exposed PLCs running outdated software or with weak access controls [2]. Unit 42 observed approximately 300,000 services daily associated with Rockwell Automation or Allen-Bradley devices since April 8, 2026 [3]. The attack surface is large and well-mapped.
Once a target is identified, the attackers connect using legitimate engineering software, the same way an authorized technician would [2]. Unit 42's analysis suggests the group installed FactoryTalk, Rockwell's own suite of industrial automation tools, on VPS infrastructure specifically for this purpose [3].
Manipulation of Operator Displays
After gaining access, the attackers manipulate operator displays so personnel cannot visually detect that anything is wrong on their HMI screens [2]. The actual state of the physical process and what the operator sees become decoupled. In safety-critical environments (water treatment, power generation, medical facility systems), this is a direct threat to human safety.
Malicious Ladder Logic and AOI Tampering
The group deploys custom ladder logic code, replacing valid PLC programming with malicious code [1]. The July update specifically calls out the use of Add-On Instructions (AOIs), which are shared, reusable code modules within Rockwell Automation environments [1][2]. Engineers typically trust AOIs implicitly because they are inherited and reused across projects. Hiding malicious logic in these modules is effective tradecraft because standard code review processes often skip them.
IOCONTROL Malware
IOCONTROL is a custom ICS malware platform previously deployed by CyberAv3ngers [1]. It targets IoT and OT devices and uses MQTT over TLS for command and control, a protocol choice designed to blend with legitimate ICS network traffic [4]. The malware has been used against IP cameras, fuel management systems, and routers [4]. Defenders should note that MQTT traffic encrypted via TLS on unexpected hosts is an anomaly worth investigating.
Lateral Movement Considerations
The advisory documents the use of Dropbear SSH software to gain remote access to targeted systems [1]. Once inside an OT network, lateral movement to adjacent systems (HMIs, engineering workstations, historians, other PLCs on the same subnet) is straightforward, particularly in flat network architectures common in legacy OT environments. Defenders should watch for:
- Unexpected SSH sessions originating from or terminating at OT network segments
- New FactoryTalk or engineering software installations on hosts that should not have them
- Anomalous EtherNet/IP, Modbus, or S7comm traffic patterns between hosts
- PLC project file changes outside of scheduled maintenance windows
IOC Table
The following indicators are drawn directly from the advisory and associated reporting. Full STIX-formatted IOC packages (April 2026 and July 2026 sets) are available from CISA [1].
| Type | Value | Context | Source |
|---|---|---|---|
| IP | 185.82.73.175 |
Attacker infrastructure, Sep 2025 to Feb 2026 | [1] |
| IP | 141.11.164.153 |
Attacker infrastructure, Jan 2026 to Jul 2026 | [1] |
| IP | 175.110.121.42 |
Attacker infrastructure, Feb to Mar 2026 | [1] |
| IP | 175.110.121.39 |
Attacker infrastructure, Feb to Mar 2026 | [1] |
| IP | 175.110.121.41 |
Attacker infrastructure, Feb to Mar 2026 | [1] |
| IP | 175.110.121.107 |
Attacker infrastructure, Feb 2026 | [1] |
| IP | 192.142.54.79 |
Attacker infrastructure, May to Jun 2026 | [1] |
| IP | 84.200.205.165 |
Attacker infrastructure, May to Jun 2026 | [1] |
| IP | 185.225.17.225 |
Attacker infrastructure, Jun to Jul 2026 | [1] |
| IP | 79.133.46.209 |
Attacker infrastructure, Jul 2026 | [1] |
| IP | 88.80.150.199 |
Attacker infrastructure, Jul 2026 | [1] |
| IP | 88.80.150.200 |
Attacker infrastructure, Jul 2026 | [1] |
| IP | 88.80.150.202 |
Attacker infrastructure, Jul 2026 | [1] |
| IP | 185.82.73.162 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.164 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.165 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.167 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.168 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.170 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 185.82.73.171 |
Attacker infrastructure, Jan 2025 to Mar 2026 | [1] |
| IP | 135.136.1.133 |
Attacker infrastructure, Mar 2026 | [1] |
| Domain | tylarion867mino.com |
CyberAv3ngers C2 domain | [2] |
| Domain | ocferda.com |
CyberAv3ngers C2 domain | [2] |
| Domain | uuokhhfsdlk.tylarion867mino.com |
CyberAv3ngers C2 subdomain | [2] |
| Malware | IOCONTROL | Custom ICS malware, MQTT over TLS C2 | [1][4] |
| Filename | dropbear |
Dropbear SSH used for remote access | [1] |
ICS ATT&CK
| Technique ID | Name | Context |
|---|---|---|
| T0883 | Internet Accessible Device | Scanning for exposed PLCs [2] |
| T0885 | Commonly Used Port | Using legitimate engineering protocols and ports [2][3] |
| T0822 | External Remote Services | Use of FactoryTalk engineering software from external VPS infrastructure [3] |
| T0833 | Modify Control Logic | Replacement of valid ladder logic with malicious code, AOI tampering [1][2] |
| T0831 | Manipulation of View | Manipulation of operator displays to decouple HMI readings from actual process state [2] |
Enterprise ATT&CK
| Technique ID | Name | Context |
|---|---|---|
| T1021.004 | Remote Services: SSH | Dropbear SSH used for remote access to targeted systems [1] |
| T1071 | Application Layer Protocol | IOCONTROL uses MQTT over TLS for command and control [4] |
Network-Based Detection
Block or alert on connections to the IOC IP addresses listed above at the perimeter firewall. For OT environments, monitor for any outbound connections from PLC subnets, engineering workstations, or HMI systems to external IP addresses. Most PLCs should have zero outbound internet connectivity.
Splunk query for DNS resolution of known C2 domains:
index=dns (query="*tylarion867mino.com" OR query="*ocferda.com")
| stats count by src_ip, query, answer
Splunk query for connections to advisory IOCs:
index=firewall dest_ip IN ("185.82.73.175", "141.11.164.153", "175.110.121.42", "175.110.121.39", "175.110.121.41", "175.110.121.107", "192.142.54.79", "84.200.205.165", "185.225.17.225", "79.133.46.209", "88.80.150.199", "88.80.150.200", "88.80.150.202", "185.82.73.162", "185.82.73.164", "185.82.73.165", "185.82.73.167", "185.82.73.168", "185.82.73.170", "185.82.73.171", "135.136.1.133")
| stats count by src_ip, dest_ip, dest_port, action
Hunting for MQTT Anomalies
IOCONTROL uses MQTT over TLS for C2 [4]. Most enterprise and OT environments do not use MQTT (TCP 1883 or TLS-wrapped on 8883) outside of specific IoT deployments. Hunt for:
index=network_traffic dest_port IN (1883, 8883)
| stats count by src_ip, dest_ip, dest_port
| where NOT cidrmatch("<your_known_mqtt_broker_subnet>", dest_ip)
Any MQTT traffic to external destinations from OT or medical IoT segments warrants immediate investigation.
Hunting for Dropbear SSH
The actors use Dropbear SSH for remote access [1]. Dropbear is a lightweight SSH implementation rarely found in enterprise environments. Hunt for:
- Process creation events where the binary name is
dropbear - SSH server banners containing "dropbear" in network traffic logs or Zeek/Bro SSH logs
- Unexpected SSH listeners on OT hosts (particularly PLCs with embedded Linux)
PLC Project File Integrity
Monitor for changes to PLC project files and AOIs outside of change management windows [1][2]. Rockwell Automation's FactoryTalk AssetCentre (if deployed) can log project file changes. Compare current AOI libraries against known-good baselines. Any AOI modification not tied to a documented change request should be treated as a potential compromise.
Sigma Rule: Dropbear SSH Process Execution
title: Dropbear SSH Binary Execution on OT Host
id: a3c7e2f1-9b84-4d3e-bf12-6e8a2c1d5f90
status: experimental
author: RedSheepSec
date: 2026/08/21
description: Detects execution of Dropbear SSH binary, which is uncommon in enterprise environments and has been used by CyberAv3ngers for remote access to ICS targets.
references:
- https://www.ic3.gov/CSA/2026/260722.pdf
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: '/dropbear'
condition: selection
falsepositives:
- Legitimate embedded Linux devices using Dropbear as default SSH server
level: high
tags:
- attack.lateral_movement
- attack.t1021.004
- attack.initial_access
Analysis
CyberAv3ngers has demonstrated a consistent pattern: they target the most easily exploitable devices in OT environments. Default credentials on Unitronics PLCs in 2023. Internet-exposed Rockwell controllers in 2026. The tradecraft is not sophisticated in the traditional sense. They walk through open doors using the same tools that legitimate engineers use [2][3].
The confirmed operational disruption and financial losses represent a real escalation from the 2023 campaign [2]. The expansion to Schneider Electric and Siemens equipment means this is not a single-vendor vulnerability problem. It is a systemic exposure issue: too many PLCs are internet-accessible, running outdated firmware, with inadequate authentication.
IOCONTROL appears to be the most technically capable tool in their known arsenal, based on available reporting. Using MQTT over TLS for C2 is a deliberate choice to evade detection in environments where IoT protocols are expected [4]. For healthcare facilities running building management systems, medical gas monitoring, or pharmacy automation on the same network segments as general IoT devices, this protocol blending is particularly dangerous.
Unit 42's observation of 5,600 IP addresses globally running Rockwell/Allen-Bradley SCADA services, and approximately 300,000 related services daily, gives a sense of the attack surface [3]. Even a small percentage of those being vulnerable creates a target-rich environment.
Red Sheep Assessment
Confidence: Moderate-High
The sources collectively point to a conclusion none of them state explicitly: CyberAv3ngers is likely conducting pre-positioning operations for destructive capability, not just disruptive access. The progression from propaganda (2020) to default credential exploitation (2023) to custom ICS malware (2024) to multi-vendor PLC exploitation with display manipulation (2026) follows what appears to be a deliberate capability development arc. The manipulation of operator displays is not a tactic optimized for data theft or espionage. It is designed to mask physical process manipulation, which is a prerequisite for causing physical damage while delaying incident response.
The multi-agency authorship of this advisory (including Treasury and Cyber Command's CNMF) signals that the U.S. government views this as a national security matter, not just a cybersecurity one [1]. Treasury's involvement, consistent with their 2024 sanctions against IRGC-CEC officials, suggests ongoing counter-threat finance operations running in parallel.
An alternative interpretation: this is coercive signaling by Iran, building visible capability to threaten critical infrastructure as geopolitical leverage without intending to cause mass disruption. The confirmed operational disruption and financial losses could be acceptable collateral from intelligence-gathering operations rather than intended effects. The group's history of propaganda-first operations supports this reading. But defenders cannot plan around assumed intent. The capability to cause physical harm exists and is being actively developed.
Healthcare OT environments deserve particular attention. Hospital BAS, medical gas systems, and pharmacy automation PLCs from the affected manufacturers are common. These systems are often managed by facilities teams rather than IT security, creating visibility gaps. The flat network architectures typical of older healthcare facilities make lateral movement from a compromised PLC to adjacent clinical systems a realistic scenario.
Defender's Checklist
- ▢[ ] Audit internet-facing PLC exposure. Use Shodan, Censys, or your ASM platform to identify any Rockwell (CompactLogix, Micro850), Schneider Electric, or Siemens PLCs accessible from the internet. Example Shodan queries:
product:"Rockwell",product:"Allen-Bradley",product:"CompactLogix","Schneider Electric" port:502,"Siemens S7" port:102. Remove all direct internet connectivity from PLCs immediately. This is the primary attack vector [2][3].
- ▢[ ] Ingest advisory IOCs into detection infrastructure. Load all IPs and domains from the IOC table above into your SIEM, firewall block lists, and DNS sinkhole. Query historical logs for the past 12 months against these indicators, as some infrastructure dates to September 2025 [1].
- ▢[ ] Baseline and monitor PLC project files and AOIs. Export current PLC programs and compare against known-good backups. Flag any AOI modifications not tied to documented change requests. Set up file integrity monitoring on engineering workstations that store project files [1][2].
- ▢[ ] Hunt for anomalous MQTT and SSH traffic in OT segments. Run the detection queries above for MQTT (ports 1883/8883) and Dropbear SSH. Any MQTT traffic from OT/medical IoT segments to external destinations is a high-priority finding [1][4].
- ▢[ ] Segment OT networks from IT and medical IoT. Per IEC 62443 zone/conduit models and NIST SP 800-82 Rev 3 guidance, ensure PLCs, HMIs, and engineering workstations are on isolated network segments with firewall rules restricting traffic to only necessary protocols and destinations. Verify that building automation and medical device networks do not share flat subnets with general-purpose IT systems.
References
[1] https://www.ic3.gov/CSA/2026/260722.pdf
[2] https://www.trendmicro.com/en_us/research/26/g/plc-exploitation.html
[3] https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/
[4] https://www.ampcuscyber.com/shadowopsintel/cyberav3ngers-targeting-the-us-water-utilities-ics/
Event Timeline
Timeline
Entity Relationships
Entity Graph (11 entities, 9 relationships)
Diamond Model
Diamond Model
Hunt Guide: CyberAv3ngers IRGC-Affiliated PLC Exploitation Across U.S. Critical Infrastructure
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If CyberAv3ngers (IRGC-CEC) is actively targeting our environment, we expect to observe network connections to known attacker infrastructure IPs/domains, DNS queries for C2 domains (tylarion867mino.com, ocferda.com), anomalous MQTT traffic over TLS (port 8883) from OT/IoT segments, Dropbear SSH binary execution or SSH banners on OT hosts, and unexpected FactoryTalk or engineering software installations on non-engineering workstations, detectable in firewall logs, DNS logs, Zeek/Corelight network metadata, Sysmon process creation logs, and endpoint detection telemetry.
Intelligence Summary: CyberAv3ngers, assessed by the U.S. government to operate as a persona for Iran's IRGC Cyber-Electronic Command (IRGC-CEC), is actively exploiting Rockwell Automation, Schneider Electric, and Siemens PLCs across U.S. critical infrastructure including water systems, energy facilities, and government installations, with confirmed operational disruption and financial loss. The group has escalated from exploiting default credentials on Unitronics PLCs (2023) to deploying custom IOCONTROL malware using MQTT over TLS for C2, replacing valid PLC ladder logic with malicious code including tampered Add-On Instructions (AOIs), manipulating operator HMI displays to mask physical process changes, and using Dropbear SSH for remote access. While healthcare is not explicitly named in the current advisory, hospital and clinic OT environments running building automation, HVAC, medical gas monitoring, and pharmacy automation PLCs from affected manufacturers are assessed as a relevant area of concern.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All network segments containing or adjacent to OT/ICS devices, including: PLC subnets (Rockwell/Allen-Bradley, Schneider Electric, Siemens), HMI and SCADA networks, engineering workstations, building automation systems (BAS/HVAC), medical IoT segments, and any network segments with medical gas monitoring, pharmacy automation, or laboratory automation equipment. Include perimeter firewall zones and DMZ segments that may provide internet access to OT environments.
- Timeframe: Minimum 12 months retrospective (August 2025 to present), covering the full range of attacker infrastructure activity dates. Some infrastructure dates to January 2025, so extend to 18 months if log retention permits. Ongoing continuous monitoring recommended given active campaign status.
- Priority Systems: Internet-facing PLCs and SCADA devices (highest priority), engineering workstations running FactoryTalk/RSLogix/Studio 5000, HMI systems, OT network gateways and jump hosts, building automation controllers (HVAC, medical gas, pharmacy automation), any Rockwell Automation CompactLogix/Micro850/Allen-Bradley devices, Schneider Electric Modicon PLCs, Siemens S7 PLCs, and IoT devices on shared network segments with industrial controllers.
MITRE ATT&CK Techniques
T1021.004 — Remote Services: SSH (Lateral Movement) [P1]
CyberAv3ngers uses Dropbear SSH software to gain remote access to targeted OT systems. Dropbear is a lightweight SSH implementation rarely found in enterprise environments, making its presence a strong anomaly indicator.
Splunk SPL:
index=sysmon EventCode=1 (Image="*dropbear*" OR OriginalFileName="*dropbear*" OR CommandLine="*dropbear*")
| stats count by Computer, Image, CommandLine, ParentImage, User
| sort -count
Elastic KQL:
process.name:"dropbear" OR process.executable:*dropbear* OR process.command_line:*dropbear*
Sigma Rule:
title: Dropbear SSH Binary Execution on OT Host
id: a3c7e2f1-9b84-4d3e-bf12-6e8a2c1d5f90
status: experimental
author: RedSheepSec
date: 2026/08/21
description: Detects execution of Dropbear SSH binary, which is uncommon in enterprise environments and has been used by CyberAv3ngers for remote access to ICS targets.
references:
- https://www.ic3.gov/CSA/2026/260722.pdf
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: '/dropbear'
condition: selection
falsepositives:
- Legitimate embedded Linux devices using Dropbear as default SSH server
level: high
tags:
- attack.lateral_movement
- attack.t1021.004
- attack.initial_access
Dropbear is legitimately used on some embedded Linux devices (e.g., IoT appliances, lightweight routers). Validate any hits against an inventory of authorized embedded devices. In OT environments, any SSH activity from PLC subnets is suspicious regardless of implementation. Also hunt for Dropbear SSH banners in Corelight SSH logs using the query in the IOC section.
T1071 — Application Layer Protocol (Command and Control) [P2]
IOCONTROL malware uses MQTT over TLS (typically port 8883, sometimes 1883) for command and control, deliberately chosen to blend with legitimate ICS/IoT network traffic. Any MQTT traffic from OT or medical IoT segments to external destinations is highly suspicious.
Splunk SPL:
index=corelight sourcetype=corelight_conn id_resp_p IN (1883, 8883)
| lookup dnslookup clientip as id_resp_h OUTPUT clienthost as dest_dns
| stats count values(id_resp_h) as dest_ips values(dest_dns) as dest_hostnames by id_orig_h, id_resp_p
| where NOT cidrmatch("10.0.0.0/8", id_resp_h) AND NOT cidrmatch("172.16.0.0/12", id_resp_h) AND NOT cidrmatch("192.168.0.0/16", id_resp_h)
| sort -count
Elastic KQL:
(destination.port:1883 OR destination.port:8883) AND NOT destination.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16)
Sigma Rule:
title: Outbound MQTT Traffic to External Destination from OT Segment
id: b4d8f3a2-1c95-4e7b-a623-9f1d4b8c7e20
status: experimental
author: RedSheepSec
date: 2026/08/21
description: Detects MQTT traffic (ports 1883/8883) to external IP addresses, which may indicate IOCONTROL malware C2 used by CyberAv3ngers. Most enterprise and OT environments do not use MQTT outside specific IoT deployments.
references:
- https://www.ic3.gov/CSA/2026/260722.pdf
- https://www.ampcuscyber.com/shadowopsintel/cyberav3ngers-targeting-the-us-water-utilities-ics/
logsource:
category: firewall
detection:
selection:
dst_port:
- 1883
- 8883
filter_internal:
dst_ip|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection and not filter_internal
falsepositives:
- Legitimate IoT devices communicating with authorized cloud MQTT brokers (e.g., AWS IoT Core, Azure IoT Hub)
- Cloud-based building management platforms using MQTT
level: high
tags:
- attack.command_and_control
- attack.t1071
Tune by excluding known authorized MQTT broker IPs. In healthcare environments, some medical IoT platforms may legitimately use MQTT — validate against asset inventory. Any MQTT traffic from PLC subnets or engineering workstations to external IPs is high-confidence malicious activity.
T0883 — Internet Accessible Device (Initial Access) [P2]
CyberAv3ngers scans the internet for exposed PLCs running outdated software or with weak access controls. Unit 42 observed approximately 300,000 services daily associated with Rockwell Automation or Allen-Bradley devices. The primary attack vector is internet-exposed PLCs.
Splunk SPL:
index=firewall-pan sourcetype="pan:traffic:aggregated" dest_port IN (44818, 2222, 502, 102)
| where action="allowed"
| stats count values(dest_ip) as target_ips by src_ip, dest_port
| where NOT cidrmatch("10.0.0.0/8", src_ip) AND NOT cidrmatch("172.16.0.0/12", src_ip) AND NOT cidrmatch("192.168.0.0/16", src_ip)
| sort -count
Elastic KQL:
destination.port:(44818 OR 2222 OR 502 OR 102) AND NOT source.ip:(10.0.0.0/8 OR 172.16.0.0/12 OR 192.168.0.0/16) AND event.action:"allowed"
Port 44818 is EtherNet/IP (Rockwell), 2222 is commonly used by Rockwell FactoryTalk, 502 is Modbus (Schneider Electric), and 102 is S7comm (Siemens). Inbound connections from external IPs to these ports indicate internet-exposed PLCs. This query should be run against perimeter firewall logs to identify any allowed inbound ICS protocol traffic.
T0822 — External Remote Services (Initial Access) [P2]
CyberAv3ngers installed FactoryTalk engineering software on VPS infrastructure to connect to target PLCs using legitimate engineering protocols, mimicking authorized technician access. Unit 42 assesses with moderate confidence that this was the method used.
Splunk SPL:
index=sysmon EventCode=1 (Image="*FactoryTalk*" OR Image="*RSLinx*" OR Image="*RSLogix*" OR Image="*Studio 5000*" OR CommandLine="*FactoryTalk*")
| stats count by Computer, Image, CommandLine, User, ParentImage
| sort -count
| eval note="Verify this host is an authorized engineering workstation"
Elastic KQL:
process.executable:(*FactoryTalk* OR *RSLinx* OR *RSLogix* OR *Studio5000*) OR process.command_line:(*FactoryTalk*)
Sigma Rule:
title: FactoryTalk or Rockwell Engineering Software Execution on Non-Engineering Host
id: c5e9a1b3-7d42-4f8e-9a16-3b2c5d8f1e70
status: experimental
author: RedSheepSec
date: 2026/08/21
description: Detects execution of Rockwell Automation FactoryTalk, RSLinx, RSLogix, or Studio 5000 engineering software. CyberAv3ngers installed FactoryTalk on VPS infrastructure to access target PLCs.
references:
- https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/
- https://www.ic3.gov/CSA/2026/260722.pdf
logsource:
category: process_creation
product: windows
detection:
selection:
Image|contains:
- 'FactoryTalk'
- 'RSLinx'
- 'RSLogix'
- 'Studio 5000'
condition: selection
falsepositives:
- Legitimate use on authorized engineering workstations
- Maintenance activities by OT engineers
level: medium
tags:
- attack.initial_access
- attack.t0822
Maintain a whitelist of authorized engineering workstations and users permitted to run ICS engineering software. Any execution on hosts not on that whitelist should trigger immediate investigation. Also check for new software installations via index=winconfig sourcetype=InstalledSoftware.
T0833 — Modify Control Logic (Impair Process Control) [P1]
CyberAv3ngers developed and deployed custom ladder logic code, replacing valid ladder logic with malicious code. The July 2026 advisory update specifically calls out tampering with Add-On Instructions (AOIs), which are shared reusable code modules that engineers typically trust implicitly. Standard code review processes often skip AOI verification.
Splunk SPL:
index= sourcetype= ("AOI" OR "Add-On Instruction" OR "ladder logic" OR "project download" OR "program change" OR ".ACD" OR ".L5X" OR ".L5K")
| stats count by _time, host, source, sourcetype, _raw |
|---|
| sort -_time |
**Elastic KQL:**
message:(AOI OR "Add-On Instruction" OR "ladder logic" OR "project download" OR ".ACD" OR ".L5X")
*This technique is difficult to detect with traditional IT security tooling. Primary detection relies on: (1) FactoryTalk AssetCentre logging PLC project file changes, (2) file integrity monitoring on engineering workstation project file directories, (3) OT-specific IDS solutions like Claroty or Nozomi that can baseline PLC configurations. Compare current AOI libraries against known-good baselines. Any AOI modification not tied to a documented change request should be treated as potential compromise.*
#### T0831 — Manipulation of View (Impair Process Control) [P2]
After gaining access, CyberAv3ngers manipulate operator displays so personnel cannot visually detect that anything is wrong on their HMI screens. The actual state of the physical process and what the operator sees become decoupled. This is assessed as a prerequisite for causing physical damage while delaying incident response.
**Splunk SPL:**
index=corelight sourcetype=corelight_conn id_resp_p=44818
| stats count dc(id_orig_h) as unique_sources by id_resp_h
| where unique_sources > 2 OR count > 1000
| sort -count
| eval note="High volume or multi-source EtherNet/IP traffic to PLC may indicate unauthorized access or display manipulation"
Elastic KQL:
destination.port:44818 AND event.dataset:"corelight.conn"
Detecting HMI manipulation typically requires OT-specific deep packet inspection solutions that can parse CIP, Modbus, and S7comm protocols. IT SOC tooling provides limited visibility into this technique. Coordinate with OT/facilities teams to establish baselines for normal HMI-to-PLC communication patterns.
T0885 — Commonly Used Port (Command and Control) [P2]
CyberAv3ngers use legitimate engineering protocols and ports (EtherNet/IP on 44818, Modbus on 502, S7comm on 102) to communicate with target PLCs, blending with normal ICS traffic and making detection based on port numbers alone ineffective.
Splunk SPL:
index=corelight sourcetype=corelight_conn id_resp_p IN (44818, 502, 102)
| stats count dc(id_resp_h) as unique_targets values(id_resp_h) as targets by id_orig_h, id_resp_p
| where unique_targets > 5
| sort -unique_targets
| eval note="Source scanning multiple ICS devices — possible reconnaissance or exploitation"
Elastic KQL:
destination.port:(44818 OR 502 OR 102) | stats cardinality(destination.ip) as unique_targets by source.ip
Focus on identifying new or unauthorized sources communicating with PLCs on ICS protocols. Baseline authorized engineering workstations and alert on any new sources. Watch for connections from non-OT subnets or VPN exit points.
Indicators of Compromise
| Type | Value | Context |
|---|---|---|
| ip | 185.82.73.175 |
CyberAv3ngers attacker infrastructure, active Sep 2025 to Feb 2026 |
| ip | 141.11.164.153 |
CyberAv3ngers attacker infrastructure, active Jan 2026 to Jul 2026 |
| ip | 175.110.121.42 |
CyberAv3ngers attacker infrastructure, active Feb to Mar 2026 |
| ip | 175.110.121.39 |
CyberAv3ngers attacker infrastructure, active Feb to Mar 2026 |
| ip | 175.110.121.41 |
CyberAv3ngers attacker infrastructure, active Feb to Mar 2026 |
| ip | 175.110.121.107 |
CyberAv3ngers attacker infrastructure, active Feb 2026 |
| ip | 192.142.54.79 |
CyberAv3ngers attacker infrastructure, active May to Jun 2026 |
| ip | 84.200.205.165 |
CyberAv3ngers attacker infrastructure, active May to Jun 2026 |
| ip | 185.225.17.225 |
CyberAv3ngers attacker infrastructure, active Jun to Jul 2026 |
| ip | 79.133.46.209 |
CyberAv3ngers attacker infrastructure, active Jul 2026 |
| ip | 88.80.150.199 |
CyberAv3ngers attacker infrastructure, active Jul 2026 |
| ip | 88.80.150.200 |
CyberAv3ngers attacker infrastructure, active Jul 2026 |
| ip | 88.80.150.202 |
CyberAv3ngers attacker infrastructure, active Jul 2026 |
| ip | 185.82.73.162 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.164 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.165 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.167 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.168 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.170 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 185.82.73.171 |
CyberAv3ngers attacker infrastructure, active Jan 2025 to Mar 2026 |
| ip | 135.136.1.133 |
CyberAv3ngers attacker infrastructure, active Mar 2026 |
| domain | tylarion867mino.com |
CyberAv3ngers C2 domain |
| domain | ocferda.com |
CyberAv3ngers C2 domain |
| domain | uuokhhfsdlk.tylarion867mino.com |
CyberAv3ngers C2 subdomain |
| filename | dropbear |
Dropbear SSH binary used by CyberAv3ngers for remote access to targeted OT systems |
IOC Sweep Queries (Splunk):
index=firewall-pan (src_ip="185.82.73.175" OR dest_ip="185.82.73.175") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="141.11.164.153" OR dest_ip="141.11.164.153") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="175.110.121.42" OR dest_ip="175.110.121.42") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="175.110.121.39" OR dest_ip="175.110.121.39") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="175.110.121.41" OR dest_ip="175.110.121.41") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="175.110.121.107" OR dest_ip="175.110.121.107") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="192.142.54.79" OR dest_ip="192.142.54.79") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="84.200.205.165" OR dest_ip="84.200.205.165") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.225.17.225" OR dest_ip="185.225.17.225") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="79.133.46.209" OR dest_ip="79.133.46.209") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="88.80.150.199" OR dest_ip="88.80.150.199") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="88.80.150.200" OR dest_ip="88.80.150.200") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="88.80.150.202" OR dest_ip="88.80.150.202") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.162" OR dest_ip="185.82.73.162") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.164" OR dest_ip="185.82.73.164") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.165" OR dest_ip="185.82.73.165") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.167" OR dest_ip="185.82.73.167") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.168" OR dest_ip="185.82.73.168") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.170" OR dest_ip="185.82.73.170") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="185.82.73.171" OR dest_ip="185.82.73.171") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=firewall-pan (src_ip="135.136.1.133" OR dest_ip="135.136.1.133") | stats count by src_ip, dest_ip, dest_port, action | sort -count
index=dns (query="*tylarion867mino.com" OR answer="*tylarion867mino.com") | stats count by src_ip, query, answer | sort -count
index=dns (query="*ocferda.com" OR answer="*ocferda.com") | stats count by src_ip, query, answer | sort -count
index=dns query="uuokhhfsdlk.tylarion867mino.com" | stats count by src_ip, query, answer | sort -count
index=sysmon EventCode=1 (Image="*dropbear*" OR CommandLine="*dropbear*") | stats count by Computer, Image, CommandLine, ParentImage, User | sort -count
YARA Rules
HUNT_CyberAv3ngers_Dropbear_SSH — Detects Dropbear SSH binary, a lightweight SSH implementation used by CyberAv3ngers for remote access to OT targets. Looks for characteristic Dropbear strings in binaries.
rule HUNT_CyberAv3ngers_Dropbear_SSH
{
meta:
author = "RedSheepSec"
description = "Detects Dropbear SSH binary used by CyberAv3ngers for ICS remote access"
reference = "https://www.ic3.gov/CSA/2026/260722.pdf"
date = "2026-08-21"
threat_actor = "CyberAv3ngers"
tlp = "white"
strings:
$s1 = "dropbear" ascii nocase
$s2 = "Dropbear SSH" ascii
$s3 = "dropbear_" ascii
$s4 = "DROPBEAR_PASSWORD" ascii
$s5 = "dropbearkey" ascii
$elf = { 7F 45 4C 46 }
condition:
$elf at 0 and 2 of ($s*)
}
HUNT_CyberAv3ngers_IOCONTROL_MQTT_Strings — Detects potential IOCONTROL malware based on MQTT protocol strings combined with ICS-related indicators. IOCONTROL is a custom Linux-based ICS malware using MQTT over TLS for C2.
rule HUNT_CyberAv3ngers_IOCONTROL_MQTT_Strings
{
meta:
author = "RedSheepSec"
description = "Hunts for potential IOCONTROL malware - custom ICS malware using MQTT over TLS for C2"
reference = "https://www.ic3.gov/CSA/2026/260722.pdf"
date = "2026-08-21"
threat_actor = "CyberAv3ngers"
tlp = "white"
strings:
$mqtt1 = "MQTT" ascii
$mqtt2 = "mqtt" ascii
$mqtt3 = "/mqtt" ascii
$c2_1 = "tylarion867mino.com" ascii nocase
$c2_2 = "ocferda.com" ascii nocase
$c2_3 = "uuokhhfsdlk" ascii nocase
$elf = { 7F 45 4C 46 }
condition:
$elf at 0 and (1 of ($mqtt*) and 1 of ($c2*))
}
Suricata Rules
SID 2026001 — Detects DNS query for CyberAv3ngers C2 domain tylarion867mino.com
alert dns $HOME_NET any -> any 53 (msg:"HUNT CyberAv3ngers C2 DNS Query - tylarion867mino.com"; dns.query; content:"tylarion867mino.com"; nocase; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026001; rev:1;)
SID 2026002 — Detects DNS query for CyberAv3ngers C2 domain ocferda.com
alert dns $HOME_NET any -> any 53 (msg:"HUNT CyberAv3ngers C2 DNS Query - ocferda.com"; dns.query; content:"ocferda.com"; nocase; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026002; rev:1;)
SID 2026003 — Detects outbound connection to CyberAv3ngers infrastructure 185.82.73.0/24 subnet
alert ip $HOME_NET any -> 185.82.73.0/24 any (msg:"HUNT CyberAv3ngers Infrastructure - 185.82.73.0/24"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026003; rev:1;)
SID 2026004 — Detects outbound connection to CyberAv3ngers infrastructure 175.110.121.0/24 subnet
alert ip $HOME_NET any -> 175.110.121.0/24 any (msg:"HUNT CyberAv3ngers Infrastructure - 175.110.121.0/24"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026004; rev:1;)
SID 2026005 — Detects outbound connection to CyberAv3ngers infrastructure 88.80.150.0/24 subnet
alert ip $HOME_NET any -> 88.80.150.0/24 any (msg:"HUNT CyberAv3ngers Infrastructure - 88.80.150.0/24"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026005; rev:1;)
SID 2026006 — Detects outbound MQTT over TLS (port 8883) from internal networks which may indicate IOCONTROL malware C2
alert tcp $HOME_NET any -> $EXTERNAL_NET 8883 (msg:"HUNT Potential IOCONTROL MQTT over TLS C2 Communication"; flow:to_server,established; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026006; rev:1;)
SID 2026007 — Detects outbound connection to CyberAv3ngers infrastructure IP 141.11.164.153
alert ip $HOME_NET any -> 141.11.164.153 any (msg:"HUNT CyberAv3ngers Infrastructure - 141.11.164.153"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026007; rev:1;)
SID 2026008 — Detects outbound connection to CyberAv3ngers infrastructure IP 192.142.54.79
alert ip $HOME_NET any -> 192.142.54.79 any (msg:"HUNT CyberAv3ngers Infrastructure - 192.142.54.79"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026008; rev:1;)
SID 2026009 — Detects outbound connection to CyberAv3ngers infrastructure IP 84.200.205.165
alert ip $HOME_NET any -> 84.200.205.165 any (msg:"HUNT CyberAv3ngers Infrastructure - 84.200.205.165"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026009; rev:1;)
SID 2026010 — Detects outbound connection to CyberAv3ngers infrastructure IP 185.225.17.225
alert ip $HOME_NET any -> 185.225.17.225 any (msg:"HUNT CyberAv3ngers Infrastructure - 185.225.17.225"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026010; rev:1;)
SID 2026011 — Detects outbound connection to CyberAv3ngers infrastructure IP 79.133.46.209
alert ip $HOME_NET any -> 79.133.46.209 any (msg:"HUNT CyberAv3ngers Infrastructure - 79.133.46.209"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026011; rev:1;)
SID 2026012 — Detects outbound connection to CyberAv3ngers infrastructure IP 135.136.1.133
alert ip $HOME_NET any -> 135.136.1.133 any (msg:"HUNT CyberAv3ngers Infrastructure - 135.136.1.133"; reference:url,www.ic3.gov/CSA/2026/260722.pdf; classtype:trojan-activity; sid:2026012; rev:1;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Palo Alto Firewall Logs (index=firewall-pan) | T0883, T0885, T1071 | Required for IOC IP blocking/alerting and detecting inbound ICS protocol connections from external sources. Verify OT network segments route through monitored firewalls. |
| DNS Logs (index=dns) | T1071 | Required for C2 domain detection (tylarion867mino.com, ocferda.com). Ensure DNS resolution from OT network segments is logged. |
| Corelight/Zeek Network Metadata (index=corelight) | T1071, T0885, T0831, T1021.004 | Critical for detecting MQTT anomalies, ICS protocol traffic patterns, SSH banner analysis, and EtherNet/IP monitoring. Verify Corelight sensors have visibility into OT network segments. |
| Sysmon (index=sysmon) | T1021.004, T0822 | Required for process creation detection (Dropbear SSH, FactoryTalk). Verify Sysmon is deployed on engineering workstations and any Windows hosts on OT network segments. |
| CrowdStrike EDR (index=crowdstrike) | T1021.004, T0822 | Supplement Sysmon for process execution and network connection detection. Verify EDR coverage extends to engineering workstations. |
| Linux Audit Logs (index=linux-server) | T1021.004 | Required for detecting Dropbear SSH on Linux-based OT hosts. Many PLCs run embedded Linux where auditd may not be available — note this visibility gap. |
| OT-Specific IDS/Asset Monitoring (FactoryTalk AssetCentre, Claroty, Nozomi, Dragos) | T0833, T0831 | CRITICAL GAP: Detecting PLC logic changes and HMI manipulation requires OT-specific tooling that may not feed into Splunk. Coordinate with OT/facilities teams to determine if these tools are deployed and whether their logs can be ingested. |
| Software Inventory (index=winconfig) | T0822 | Use InstalledSoftware sourcetype to detect unauthorized FactoryTalk or engineering software installations. |
Recommendations
- IMMEDIATE: Ingest all 21 attacker infrastructure IPs and 3 C2 domains into firewall block lists, DNS sinkholes, and SIEM watchlists. Run retrospective searches across 12-18 months of firewall, DNS, and proxy logs against these indicators.
- IMMEDIATE: Audit all internet-facing ICS/SCADA exposure using Shodan/Censys queries (product:Rockwell, product:Allen-Bradley, product:CompactLogix, 'Schneider Electric' port:502, 'Siemens S7' port:102) and the organization's ASM platform. Remove all direct internet connectivity from PLCs — this is the primary attack vector.
- HIGH PRIORITY: Deploy Suricata rules (SIDs 2026001-2026012) on all network sensors, prioritizing OT network segment sensors and perimeter IDS/IPS.
- HIGH PRIORITY: Verify Corelight/Zeek sensor placement provides visibility into OT network segments. If OT segments are not monitored, request sensor deployment or SPAN port configuration to close this critical visibility gap.
- HIGH PRIORITY: Coordinate with OT/facilities engineering teams to export current PLC programs from all Rockwell, Schneider Electric, and Siemens PLCs and compare against known-good backups. Flag any Add-On Instruction (AOI) modifications not tied to documented change requests.
- MEDIUM PRIORITY: Maintain a whitelist of authorized engineering workstations permitted to run FactoryTalk, RSLinx, RSLogix, and Studio 5000. Alert on any execution of these tools on non-whitelisted hosts using the T0822 Sigma rule.
- MEDIUM PRIORITY: Validate OT network segmentation per IEC 62443 zone/conduit models. Verify PLCs, HMIs, and engineering workstations are on isolated segments with firewall rules restricting traffic to only necessary protocols and destinations. Confirm building automation and medical device networks do not share flat subnets with general-purpose IT systems.
- MEDIUM PRIORITY: Hunt for Dropbear SSH on all Linux hosts using the Sigma rule and Corelight SSH logs (search for SSH server banners containing 'dropbear'). Any Dropbear presence on enterprise hosts warrants investigation.
- ONGOING: Establish continuous monitoring for MQTT traffic (ports 1883/8883) from OT and medical IoT segments to external destinations. Any such traffic is a high-confidence indicator of IOCONTROL malware C2.
Sources
- CISA Joint Advisory AA26-097A (FBI, CISA, NSA, EPA, DOE, CNMF, Treasury) - PLC Exploitation Advisory
- Trend Micro Research - PLC Exploitation Analysis
- Unit 42 (Palo Alto Networks) - Iranian Cyberattacks 2026 / CL-STA-1128
- Ampcus Cyber ShadowOps Intel - CyberAv3ngers Targeting U.S. Water Utilities ICS