
Iranian 'CyberAv3ngers' Escalate Attacks on U.S. Water Systems via Unitronics PLC Exploitation
Intelligence indicates a surge in Iranian-linked activity targeting U.S. water systems. Recent breaches exploit default credentials in Unitronics PLCs, prompting urgent federal warnings.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- North America
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
Over the past 48 hours, Encrygma intelligence has tracked a significant escalation in cyber operations targeting U.S. critical infrastructure, specifically within the Water and Wastewater Systems (WWS) sector. These attacks, attributed to Iranian-affiliated threat actors, have successfully compromised Programmable Logic Controllers (PLCs) in multiple states, including recent reports from Pennsylvania and Texas. The primary objective appears to be the disruption of operations and the delivery of political messaging. While no immediate threat to water safety has been confirmed, the unauthorized access to control systems represents a critical risk to national security and public health. This activity follows a series of alerts from the FBI and CISA regarding the vulnerability of Israeli-made technology in American infrastructure.
Threat Analysis
The current campaign is linked to the Iranian Revolutionary Guard Corps (IRGC)-affiliated group known as 'CyberAv3ngers' (also tracked as part of the APT35/Charming Kitten cluster). This group has shifted its focus from purely information operations to active interference with Operational Technology (OT). The timing of these attacks coincides with heightened geopolitical tensions in the Middle East, suggesting a retaliatory motive. Unlike traditional espionage, these operations are 'loud' and intended to be noticed, utilizing defaced PLC screens to broadcast anti-Israel and anti-U.S. sentiment. The group specifically targets entities using equipment manufactured by Israeli companies, viewing them as legitimate targets in the ongoing digital conflict.
Technical Details
The attackers are specifically targeting Unitronics Vision series PLCs, which are widely used in small-to-medium-sized water utilities. The primary vector is the exploitation of devices exposed to the public internet with default manufacturer credentials (specifically port 20256). Once access is gained, the actors deploy a simple but effective script to overwrite the PLC's logic, causing the device to stop its normal functions and display a graphic message: 'You have been hacked, down with Israel. Every equipment made in Israel is CyberAv3ngers target.' Technical analysis of the recent August 7 breaches shows the use of residential proxies to mask the origin of the traffic, complicating traditional IP-based blocking. The actors are also utilizing automated scanners to identify the 'Unitronics' string in HTTP headers of internet-facing devices.
Attribution Assessment
Encrygma assesses with high confidence that these operations are conducted by actors supported by the Iranian government. The infrastructure used in the latest wave of attacks overlaps significantly with previous IRGC-linked campaigns identified by Several states report cyberattacks as spy agencies suspect Iran targeting water. Furthermore, the specific targeting of Israeli-made technology aligns with the strategic objectives of Iranian state-sponsored groups seeking to undermine Israeli economic interests and their global supply chain footprint. The TTPs (Tactics, Techniques, and Procedures) match those described in recent CISA advisories regarding Iranian-affiliated APTs.
Implications
The successful compromise of WWS infrastructure demonstrates a persistent vulnerability in the U.S. water sector, which is often underfunded and lacks dedicated cybersecurity personnel. While the current impact is limited to operational downtime and defacement, the ability to manipulate PLCs could theoretically be extended to altering chemical dosing or water pressure, leading to kinetic consequences. This campaign serves as a proof-of-concept for more destructive future operations and highlights the risks inherent in the global technology supply chain.
Recommendations
Organizations operating OT environments must immediately audit their internet-facing assets. Key recommendations include: 1. Change all default passwords on PLCs and HMI interfaces immediately to complex, unique strings. 2. Implement Multi-Factor Authentication (MFA) for all remote access to the OT network. 3. Disconnect PLCs and other control devices from the public internet; if remote access is required, utilize a secure VPN with strict access controls and logging. 4. Update PLC firmware to the latest versions to patch known vulnerabilities. 5. Monitor for unusual traffic on port 20256 and other common OT ports, and implement network segmentation to isolate critical control systems from the corporate IT environment.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Intelligence Alert: Escalating Nation-State Exploitation of Edge Infrastructure in Q3 2026

China-Linked APT Group QTFY Escalates Targeting of Global Military and Critical Infrastructure

