Skip to content
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

Trendmicro July 24, 2026

TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.

By: Jamal Bethea Jul 23, 2026 Read time: ( words)

Six federal agencies have just updated an advisory ongoing attacks on the equipment that physically runs U.S. critical infrastructure, including city services, water plants, and power facilities. The advisory, first issued in April 2026 and revised on July 22, warns that attackers are actively targeting these systems.

The activity involves attackers scanning the internet for exposed industrial control systems (ICS) and connecting to them using legitimate engineering software, the same way an authorized technician would. Once inside, they alter the controllers’ underlying logic, the instructions that tell the equipment what to do. In some cases, they also change what’s shown on the operators’ screens. The attacks are built specifically so the humans in the loop can’t spot any anomalies on their screens.

The joint advisory, AA26-097A , is cosigned by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Environmental Protection Agency (EPA), the Department of Energy, and U.S. Cyber Command. It warns that nation-state and advanced persistent threat (APT) actors are actively exploiting internet-facing programmable logic controllers (PLCs) across U.S. government services, water systems, and energy infrastructure.

A PLC is a specialized, ruggedized industrial device built to run the control logic that operates physical equipment. It replaced the banks of hardwired electromechanical relays that once did this job, swapping fixed wiring for logic that can be reprogrammed. It’s what opens the valve, starts the pump, holds the pressure, and trips the breaker.

A PLC runs its control logic on the device itself, so it drives the physical process with or without a network connection. What makes the ongoing activity possible is that many are also reachable over a network, and that reach is what the attackers exploit.

Two other terms significant to this incident are the following:

Held together, these three make the core of the ongoing exploitation easy to describe: The attackers reach the controllers, copy the blueprint, and change what the humans see. A real industrial environment is far more than these three pieces—it includes mechanical processes that no PLC controls and steps that still depend on people—but this narrow slice is exactly what the attackers manipulate.

In November 2023, a group affiliated with the Iranian IRGC Cyber Electronic Command (IRGC-CEC), known as CyberAv3ngers (also tracked as Hydro Kitten, Shahid Kaveh Group, and Storm-0784), compromised at least 75 PLCs in U.S. water facilities. Those devices were running default credentials, so it was a simple problem with a simple fix: Change the password.

Short of formally naming the same group, the federal agencies describe activity in the ongoing attacks that is consistent with the 2023 attacks. The current exploitation is more sophisticated in three specific ways:

The advisory update also flags a quieter but serious risk: malicious changes hidden inside reusable code modules, shared blocks of logic dropped into many PLC programs at once. Because a tampered module carries its changes into every process that reuses it, a single edit can spread across an entire operation. That turns an operator’s own engineering library, full of trusted configuration standards and specs, into a supply-chain problem, which is exactly what the update’s new detection guidance is meant to catch.

Traffic tied to the ongoing activity showed up on five ports:

None of that traffic depends on a software bug. The threat actors scan for internet-exposed PLCs and connect to them the same way a legitimate engineer would. That is an architectural weakness, not a patchable one, because these controllers are deployed without sufficient network segmentation, authentication gating, or remote-access hardening. Public scan data from Shodan shows more than 74,000 ICS devices directly reachable from the open internet today—down from a level that held around 120,000 for much of the period since 2017—and many still run default or no credentials at all.

Defending against these attacks is largely a matter of configuration and access control, so it requires no new hardware or lengthy procurement cycle and can begin immediately. The steps below move from what to do this week, to what to fix this quarter, to what the industry itself owes operators and organizations.

What to fix this quarter

Pushing accountability to vendors

The advisory doesn’t put all of this on operators. It presses manufacturers directly: Ship products that don’t expose administrative interfaces to the internet by default, support MFA (including phishing-resistant methods), and stop charging extra fees for the basic security features that a product needs to run safely. Organizations buying industrial equipment should make these firm conditions of purchase and get them written into the contract.

Validating continuously

When the intrusion method involves legitimate software and valid credentials, a point-in-time assessment reveals almost nothing whether an environment stays protected month. The advisory’s own recommendation is to validate these controls continuously, rather than check them once. Knowing what’s reachable from the internet into the OT environment and confirming that segmentation is enforced rather than assumed is the whole difference between reading the advisory and acting on it.

TrendAI Vision One™ Threat Intelligence Hub provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI™ Research, and TrendAI Vision One™ Threat Intelligence Feed in the TrendAI Vision One™ platform.

Emerging Threats: Federal Agencies Warn of Ongoing PLC Exploitation Against Critical US Infrastructure

TrendAI Vision One™ Intelligence Reports (IoC Sweeping)

Federal Agencies Warn of Ongoing PLC Exploitation Against Critical US Infrastructure

Customers using TrendAI Vision One™ can use the XDR Data Explorer App to match the malicious indicators covered in this blog article against data in their own environments for hunting purposes.

CyberAv3ngers C&C infrastructure connections

eventSubId:201 AND dst:("185.82.73.175" OR "141.11.164.153" OR "175.110.121.42" OR "175.110.121.39" OR "175.110.121.107" OR "185.225.17.225" OR "79.133.46.209" OR "88.80.150.199" OR "88.80.150.200" OR "88.80.150.202" OR "185.82.73.162" OR "185.82.73.164" OR "185.82.73.165" OR "185.82.73.167" OR "185.82.73.168" OR "185.82.73.170" OR "185.82.73.171" OR "135.136.1.133")

CyberAv3ngers C&C DNS resolution

eventSubId:301 AND hostName:(*tylarion867mino.com* OR *ocferda.com*)

The indicators of compromise (IoCs) listed below are sourced from CISA. These are detected and blocked by the TrendAI Vision One™ platform.

URLs and IP addresses