On 27 July 2026 Trend Micro released a detailed threat report titled Ongoing PLC Exploitation Against Critical U.S. Infrastructure. The advisory, jointly issued by the FBI, CISA, NSA, EPA, DOE and U.S. Cyber Command, warns that nation‑state actors are actively scanning the internet for exposed programmable logic controllers (PLCs) across federal facilities, water treatment plants and power utilities. By leveraging legitimate engineering tools and valid credentials, attackers manipulate PLC logic, alter operator displays and stealthily introduce malicious changes that evade human detection.
Unlike the 2023 campaign that primarily exploited default passwords on a limited set of Rockwell Automation devices, the current threat is broader, more sophisticated and has already caused confirmed operational disruptions and financial losses. The July update expands the scope to include Schneider Electric and Siemens PLCs, identifies new tactics such as malicious changes hidden in reusable code modules, and provides concrete detection guidance.
Key Takeaways
- Attackers manipulate operator displays so personnel cannot visually detect anomalies.
- Scanning for internet‑exposed PLCs is performed on ports 22, 102, 502, 2222 and 44818 using legitimate engineering software.
- The advisory now covers Schneider Electric and Siemens devices in addition to Rockwell Automation/Allen‑Bradley.
- Real operational impact has been observed; some victims incurred financial loss.
What is a PLC and Why it Matters
A PLC is a ruggedized industrial device that runs the control logic for physical equipment. It replaces hardwired relays with reprogrammable software, controlling valves, pumps, breakers, etc. PLCs often run their logic locally, but many are also reachable over a network, creating an attack surface that can be exploited if not properly segmented.
Three core concepts:
- Project file: The binary blueprint (.ACD for Rockwell) containing ladder logic, tag database and configuration.
- Human‑Machine Interface (HMI): Screens operators use to monitor and control processes.
- Reusable code modules: Shared blocks of logic that can propagate malicious changes across multiple PLCs.
Differentiating 2023 from 2026 Attacks
The 2023 incidents, tied to the Iranian IRGC‑CEC group (CyberAv3ngers), exploited default credentials on 75 water facility PLCs. The remediation was simple: change passwords.
In contrast, the 2026 threat:
- Uses legitimate engineering tools (Studio 5000 Logix Designer) and valid credentials, making traffic appear as legitimate maintenance activity.
- Targets a wider range of manufacturers.
- Causes real disruptions and financial damage.
No Vulnerability Required
The attackers rely on architectural weaknesses: PLCs exposed to the internet without segmentation or strong authentication. Public scans show over 74,000 industrial control devices reachable from the open internet.
Security Recommendations
This Week:
- Remove direct internet exposure; route all remote access through secure gateways with MFA.
- Enable physical mode switches where available and use them to restrict programming/remote modes to supervised windows.
- Search logs for traffic on ports 22, 102, 502, 2222, 44818 directed at advisory IP addresses or overseas hosting providers.
This Quarter:
- Enable programming protection on Rockwell and Siemens key switches as per vendor guidance.
- Back up PLC logic offline and test restores; store backups on secured physical media separate from the network.
- Enforce MFA for all OT remote access, block unnecessary OT ports at perimeter, disable unused services like Telnet or default web interfaces, and monitor continuously for configuration changes against a known‑good baseline.
Vendor Accountability:
- Manufacturers should ship products that do not expose administrative interfaces to the internet by default.
- Support MFA (including phishing‑resistant methods) without extra fees for essential security features.
- Organizations purchasing industrial equipment must make these conditions of purchase explicit and include them in contracts.
Continuous Validation:
- Because attackers use legitimate software and valid credentials, a one‑time assessment is insufficient.
- Continuously verify that segmentation is enforced and that only authorized devices are reachable from the internet.
Indicators of Compromise (IoCs)
The advisory lists IP addresses and domain names linked to Command & Control servers, as well as file hashes for known backdoors. TrendAI Vision One™ detects and blocks these indicators; organizations can use its XDR Data Explorer App to hunt for them in their own environments.
- IP range: 185.82.73.* (various sub‑addresses)
- Domain names: ocferda.com, tylarion867mino.com
- File hashes: 366e435a1ea0f597deb6ebe7c0c5acdb6e8b33eb and 95bd07b4400095acdafce05888da27228d7d07ca
By implementing the short‑term mitigations, strengthening configuration controls, holding vendors accountable, and validating defenses continuously, organizations can mitigate the risk of PLC exploitation and protect critical U.S. infrastructure from further disruption.

