CISA and Partners Revise Iranian-Affiliated PLC Threat Advisory
After publishing a joint cybersecurity advisory in April on Iranian-affiliated cyber activity targeting internet-connected operational technology devices, the Cybersecurity and Infrastructure Security Agency (CISA), FBI, Environmental Protection Agency and other U.S. government partners provided an update Wednesday with additional guidance.
According to CISA’s press release, the agencies revised the “Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure” advisory to include ways U.S. organizations can detect and mitigate malicious changes in reusable code modules used within Rockwell Automation/Allen-Bradley programmable logic controller (PLC) programs. The revisions also reflect the targeting of Schneider Electric, Siemens and other manufactured PLCs.
CISA emphasized the importance of operational technology owners and operators restricting direct internet access to mitigate cyber threats.
“CISA has consistently warned critical infrastructure stakeholders that Iranian-affiliated threat actors are conducting a range of targeted cyber activity to include compromise unsecure internet-connected accounts and devices,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA and our partners urge organizations to review this updated advisory and implement recommended actions to protect against this Iranian-affiliated threat activity.”
The advisory outlines how Iranian threat actors have disrupted PLCs across many U.S. critical infrastructure sectors, including water, wastewater systems, energy and government facilities. The newly discovered techniques used by threat actors include downloading malicious project files, manipulating data on human machine interfaces and supervisory control and data acquisition displays, and exfiltrating files over remote, third-party command and control channels, all bypassing security alarms. According to the release, these activities have resulted in operational disruption and financial loss for affected organizations.
“Cybersecurity threats are a serious concern for our nation’s drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools and other critical sectors that rely on these lifeline services,” said EPA Assistant Administrator for Water Jess Kramer. “EPA is committed to ensuring safe water for all Americans, and strengthening cybersecurity is key. EPA encourages water systems to be vigilant, stay informed and work to adopt cybersecurity best practices.”
The agencies also updated their list of mitigations to help organizations reduce the risk of cyber attacks.
CISA and its partners are now advising companies to adhere to previously issued guidance from PLC manufacturers, strictly control network access to PLC devices, remove PLCs from direct internet exposure via secure gateway and firewall, consider implementing isolated architectures, change default passwords, monitor project files for unauthorized changes and inform service providers of active threats to internet-connected PLC devices.
“Iranian cyber actors continue to target U.S. critical infrastructure, and the FBI is committed to identifying, disrupting and imposing costs on those responsible,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Sharing timely, actionable intelligence is a critical part of that work. This advisory provides network defenders with the information they need to identify malicious activity, strengthen their defenses and reduce opportunities for Iranian cyber actors to disrupt the essential services Americans rely on.”
Comments