US warns of Iranian hackers targeting critical infrastructure
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,并且不要以“文章内容总结”或“这篇文章”这样的开头。首先,我得仔细阅读文章,理解其主要内容。 文章主要讲的是伊朗关联的黑客正在攻击美国关键基础设施组织的网络中暴露在互联网上的Rockwell/Allen-Bradley可编程逻辑控制器(PLCs)。这些攻击导致了财务损失和运营中断。美国多个机构联合发布了警告,建议采取措施防御,比如断开PLC与互联网的连接或使用防火墙保护。 接下来,我需要将这些信息浓缩到100字以内。重点包括:伊朗黑客、攻击目标、影响、建议措施。要注意用词简洁,避免冗余。 可能的结构是:伊朗黑客攻击美国关键基础设施的PLC,导致损失和中断。多机构警告,并建议采取防护措施。 检查字数是否符合要求,确保没有使用禁止的开头方式。最后,通读一遍确保流畅和准确。 </think> 伊朗关联的黑客正针对美国关键基础设施组织网络中暴露的Rockwell/Allen-Bradley PLC发起攻击,导致财务损失和运营中断。美国多机构联合警告此类活动已升级,并建议采取防护措施以应对威胁。 2026-4-7 18:15:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Iranian hackers

Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations.

The warning came earlier today in the form of a joint advisory authored by the FBI, CISA, NSA, the Environmental Protection Agency (EPA), Department of Energy (DOE), and the United States Cyber Command – Cyber National Mission Force (CNMF).

The authoring agencies said that these ongoing attacks have targeted organizations across multiple U.S. critical infrastructure sectors (including Government Services and Facilities, Water and Wastewater Systems, and Energy), and have resulted in financial losses and operational disruptions since March 2026.

Wiz

"The FBI assesses a group of Iranian-affiliated APT actors are targeting internet-exposed PLCs with the intent to cause disruptions—including maliciously interacting with project files, and manipulating data displayed on HMI and SCADA displays—to U.S. critical infrastructure organizations," the advisory warns.

"Iranian-affiliated APT targeting campaigns against U.S. organizations have recently escalated, likely in response to hostilities between Iran, and the United States and Israel."

"The FBI identified that this activity resulted in the extraction of the device's project file and data manipulation on HMI and SCADA displays," the U.S. agencies added.

A similar advisory issued in November 2023 warned that the CyberAv3ngers threat group, affiliated with the Iranian Government Islamic Revolutionary Guard Corps (IRGC), had been exploiting vulnerabilities in U.S.-based Unitronics operational technology (OT) systems.

Between November 2023 and January 2024, CyberAv3ngers hackers compromised at least 75 Unitronics PLC devices across multiple waves of cyberattacks, half of which were in WWS critical infrastructure networks.

To defend against such attacks, network defenders are advised to disconnect PLCs from the Internet or secure them using a firewall, scan logs for indicators of compromise shared in today's joint advisory, and check for suspicious traffic on OT ports (especially traffic originating from overseas hosting providers).

They should also implement multifactor authentication (MFA) for access to the OT network, keep PLCs up to date with the latest available firmware, disable all unused services and authentication methods (such as default authentication keys), and monitor network traffic for suspicious activity.

Last month, the Iranian-linked and pro-Palestinian Handala hacktivist group wiped approximately 80,000 devices on the network of U.S. medical giant Stryker, including employees' mobile devices and personal computers managed by the company.

The FBI also warned that Iranian hackers linked to the country's Ministry of Intelligence and Security (MOIS) are using Telegram in malware attacks.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/us-warns-of-iranian-hackers-targeting-critical-infrastructure/
如有侵权请联系:admin#unsafe.sh