Seven agencies of the federal government on July 22 released an updated advisory that describes Iran-linked attacks on critical infrastructure.The agencies, which include the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and the U.S. Treasury, said the attackers were targeting devices made by leading operational technology (OT) manufacturers Siemens, Schneider Electric, and Rockwell Automation.As part of the advisory, the U.S. government offered the following guidance:“This story highlights one of the biggest problems I see in cybersecurity today,” said John Strand, owner at Black Hills Information Security. “Our attention span is too short. We spend a tremendous amount of time focused on ransomware and whatever the immediate crisis happens to be, while nation-state adversaries are quietly building long-term access into critical infrastructure.”Strand pointed out that the goal of adversaries like the Iranians isn’t to cause damage today: it’s to establish persistent access so they’re in position to act whenever the timing benefits them. For organizations that manage critical systems, Strand said the priority has to be compensating controls and network visibility.Teams should never expose OT systems to the internet, said Strand, but many of them are. Just as important, Strand said many of these devices can’t support modern EDR agents, which means defenders have to rely on strong network security.“That goes well beyond traditional firewalls, IDS, and IPS,” said Strand. “It requires continuous network threat hunting and behavioral analysis capable of identifying beaconing, command-and-control activity, and other subtle indicators of compromise before an attacker is ready to act.”Gunter Ollmann, chief technology officer at Cobalt, added that what stands out here isn't that PLCs got compromised: it's what the attackers did once they had access.“They didn't just disrupt operations, they specifically went after the safety logic, disabling the shutdown and alarm functions that are supposed to tell an operator something has gone wrong,” said Ollmann. “That's a deliberate choice to remove the safety net before touching the process itself, and it shows a level of ICS engineering knowledge that goes well beyond opportunistic hacking.”Ollmann said it’s also a reminder that OT security can't stop at network segmentation. These actors got in through vendor configuration software, the same tools engineers use for legitimate maintenance, and rode trusted infrastructure to get there.“If an organization is only watching for unauthorized access and not for unauthorized changes to project files and logic, this kind of manipulation can sit undetected for a long time,” said Ollmann. “The expansion from one PLC vendor to three in a single advisory update also tells us this isn't a one-off technique tied to a specific product. It's a repeatable playbook.”
- Install PLCs consistent with manufacturers' guidelines and security best practices.
- Remove PLCs from direct internet exposure via secure gateways and firewalls; work with IT/OT team members and/or integrators to perform this action.
- Query available logs for the provided indicators of compromise (IOCs) and check available logs for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102, and 502, especially traffic originating from foreign hosting providers.




