News Room
16
Share
Iranian-Linked CyberAv3ngers Expand Targeting to Oregon and New Jersey Water Utilities via Exposed PLC Interfaces
highCritical Infrastructure

Iranian-Linked CyberAv3ngers Expand Targeting to Oregon and New Jersey Water Utilities via Exposed PLC Interfaces

A coordinated cyber campaign attributed to Iranian-affiliated actors has expanded to water facilities in Oregon and New Jersey, exploiting internet-exposed PLCs to disrupt operations.

19 August 2026Last updated 20 August 20264 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
High
Actor Type:
APT
Geography:
North America
Confidence:
High Confidence
MITRE ID:
T0831
Source:
Mandiant
Read Time:
4 min

Executive Summary Over the last 48 hours, intelligence reports from Mandiant and CISA have confirmed a significant expansion of the Iranian-linked cyber campaign targeting U.S. water and wastewater systems. New victims have been identified in Oregon and New Jersey, following earlier breaches in Minnesota and Georgia. The actors, primarily associated with the CyberAv3ngers group, are exploiting publicly accessible Programmable Logic Controllers (PLCs) to manipulate water pressure and chemical dosing parameters. This escalation marks a critical shift in the threat landscape for municipal infrastructure, moving from simple defacements to active process manipulation. ## Threat Analysis The campaign represents a shift from opportunistic scanning to targeted disruption. While previous Iranian operations focused on public influence messaging, current activity involves direct interaction with Human-Machine Interfaces (HMIs) and SCADA environments. The actors are leveraging the lack of multi-factor authentication (MFA) and the direct internet exposure of industrial assets. Intelligence suggests that the actors are specifically searching for devices with default credentials or those running unpatched firmware. The threat is not limited to a single vendor, as the campaign has broadened to include multiple major industrial automation brands. ## Technical Details The primary TTP involves exploiting Port 44818 (EtherNet/IP) and Port 502 (Modbus). Affected hardware includes Rockwell Automation CompactLogix, Schneider Electric Modicon M340, and Siemens S7-1200 series. In the Oregon incident, attackers successfully modified PLC project files to disable safety alarms, a technique mapped to MITRE ATT&CK for ICS T0831 (Modify Controller Tasking). Forensic analysis of the New Jersey breach revealed the use of compromised engineering workstations to push unauthorized logic changes. The attackers utilized foreign-hosted IP addresses to establish persistent remote access via exposed management interfaces. ## Attribution Assessment High confidence attribution to Iranian-affiliated APTs, specifically CyberAv3ngers. This assessment is based on infrastructure overlaps with previous IRGC-linked operations and the specific targeting of Western infrastructure. The group has publicly claimed responsibility for several of these attacks on social media, though their technical capabilities in some instances have been exaggerated for psychological impact. However, the confirmed logic modifications in recent days indicate a maturing capability set. ## Implications The ability to alter PLC logic poses a direct threat to public safety. Beyond operational downtime, the manipulation of chemical levels in drinking water could lead to widespread health crises. This campaign underscores the critical vulnerability of municipal utilities that lack dedicated OT security teams. The economic impact of these disruptions, including emergency response and system remediation, is estimated to be in the millions for smaller municipalities. ## Recommendations 1. Immediately remove all PLCs and HMIs from direct internet exposure. 2. Implement hardware-based MFA for all remote access to engineering workstations. 3. Conduct a forensic audit of PLC project files to ensure logic integrity. 4. Block inbound traffic on ports 44818, 2222, 102, and 502 from non-authorized IP ranges. 5. Change all default passwords on OT assets and implement a robust patch management program for industrial controllers.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo