News Room
16
Share
Iranian 'CyberAv3ngers' Escalate Attacks on U.S. Water Systems via Unitronics PLC Exploitation
criticalState Cyber Warfare

Iranian 'CyberAv3ngers' Escalate Attacks on U.S. Water Systems via Unitronics PLC Exploitation

Intelligence indicates a surge in Iranian-linked activity targeting U.S. water systems. Recent breaches exploit default credentials in Unitronics PLCs, prompting urgent federal warnings.

08 August 2026Last updated 20 August 20264 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
Nation-State
Geography:
North America
Confidence:
High Confidence
Source:
Microsoft MSTIC
Read Time:
4 min

Executive Summary

Over the past 48 hours, Encrygma intelligence has tracked a significant escalation in cyber operations targeting U.S. critical infrastructure, specifically within the Water and Wastewater Systems (WWS) sector. These attacks, attributed to Iranian-affiliated threat actors, have successfully compromised Programmable Logic Controllers (PLCs) in multiple states, including recent reports from Pennsylvania and Texas. The primary objective appears to be the disruption of operations and the delivery of political messaging. While no immediate threat to water safety has been confirmed, the unauthorized access to control systems represents a critical risk to national security and public health. This activity follows a series of alerts from the FBI and CISA regarding the vulnerability of Israeli-made technology in American infrastructure.

Threat Analysis

The current campaign is linked to the Iranian Revolutionary Guard Corps (IRGC)-affiliated group known as 'CyberAv3ngers' (also tracked as part of the APT35/Charming Kitten cluster). This group has shifted its focus from purely information operations to active interference with Operational Technology (OT). The timing of these attacks coincides with heightened geopolitical tensions in the Middle East, suggesting a retaliatory motive. Unlike traditional espionage, these operations are 'loud' and intended to be noticed, utilizing defaced PLC screens to broadcast anti-Israel and anti-U.S. sentiment. The group specifically targets entities using equipment manufactured by Israeli companies, viewing them as legitimate targets in the ongoing digital conflict.

Technical Details

The attackers are specifically targeting Unitronics Vision series PLCs, which are widely used in small-to-medium-sized water utilities. The primary vector is the exploitation of devices exposed to the public internet with default manufacturer credentials (specifically port 20256). Once access is gained, the actors deploy a simple but effective script to overwrite the PLC's logic, causing the device to stop its normal functions and display a graphic message: 'You have been hacked, down with Israel. Every equipment made in Israel is CyberAv3ngers target.' Technical analysis of the recent August 7 breaches shows the use of residential proxies to mask the origin of the traffic, complicating traditional IP-based blocking. The actors are also utilizing automated scanners to identify the 'Unitronics' string in HTTP headers of internet-facing devices.

Attribution Assessment

Encrygma assesses with high confidence that these operations are conducted by actors supported by the Iranian government. The infrastructure used in the latest wave of attacks overlaps significantly with previous IRGC-linked campaigns identified by Several states report cyberattacks as spy agencies suspect Iran targeting water. Furthermore, the specific targeting of Israeli-made technology aligns with the strategic objectives of Iranian state-sponsored groups seeking to undermine Israeli economic interests and their global supply chain footprint. The TTPs (Tactics, Techniques, and Procedures) match those described in recent CISA advisories regarding Iranian-affiliated APTs.

Implications

The successful compromise of WWS infrastructure demonstrates a persistent vulnerability in the U.S. water sector, which is often underfunded and lacks dedicated cybersecurity personnel. While the current impact is limited to operational downtime and defacement, the ability to manipulate PLCs could theoretically be extended to altering chemical dosing or water pressure, leading to kinetic consequences. This campaign serves as a proof-of-concept for more destructive future operations and highlights the risks inherent in the global technology supply chain.

Recommendations

Organizations operating OT environments must immediately audit their internet-facing assets. Key recommendations include: 1. Change all default passwords on PLCs and HMI interfaces immediately to complex, unique strings. 2. Implement Multi-Factor Authentication (MFA) for all remote access to the OT network. 3. Disconnect PLCs and other control devices from the public internet; if remote access is required, utilize a secure VPN with strict access controls and logging. 4. Update PLC firmware to the latest versions to patch known vulnerabilities. 5. Monitor for unusual traffic on port 20256 and other common OT ports, and implement network segmentation to isolate critical control systems from the corporate IT environment.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo