CISA has identified a campaign in which Iran-linked hackers exploited Rockwell programmable logic controllers (PLCs) to compromise U.S. critical infrastructure systems. According to the advisory, attackers modified HMI (human-machine interface) and SCADA (supervisory control and data acquisition) data to disable shutdown and alarm logic—a deliberate degradation of safety systems that allowed equipment to enter unsafe operating states while operators remained unaware.
The technical method is precise: investigators found that attackers used legitimate engineering tools from affected manufacturers, hosted on third-party rented systems, to extract PLC project files. Remote access was maintained through Dropbear SSH installed on victim modems. This combination of access methods—leveraging trusted manufacturer tools alongside persistence mechanisms—indicates a deliberate, sustained intrusion posture rather than rapid smash-and-grab activity.
Why this matters: Disabling alarm and shutdown logic doesn't just hide problems; it fundamentally breaks the fail-safe model that industrial control systems depend on. Operators cannot respond to threats they don't see. Equipment designed to stop when dangerous conditions are detected instead continues operating. In power generation, water treatment, chemical processing, or manufacturing environments, this creates cascading risk: a single malfunction that should trigger automatic shutdown could instead propagate across interconnected systems.
The use of manufacturer-approved tools is particularly significant. It suggests attackers either obtained legitimate credentials, exploited trusted supply chains, or identified gaps in tool access controls. This approach reduces detection friction compared to deploying custom malware.
What to watch: Future indicators of escalation include reports of unplanned equipment outages where safety systems failed to activate, unexpected SCADA data anomalies in operational environments, and discovery of additional Dropbear instances across critical infrastructure networks. The fact that this campaign echoes earlier Iranian operations suggests this is a capability they intend to reuse.

