
highCritical Infrastructure
Iranian-Linked CyberAv3ngers Expand Targeting to Oregon and New Jersey Water Utilities via Exposed PLC Interfaces
A coordinated cyber campaign attributed to Iranian-affiliated actors has expanded to water facilities in Oregon and New Jersey, exploiting internet-exposed PLCs to disrupt operations.
19 August 2026Last updated 20 August 20264 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- High
- Actor Type:
- APT
- Geography:
- North America
- Confidence:
- High Confidence
- MITRE ID:
- T0831
- Source:
- Mandiant
- Read Time:
- 4 min
Executive Summary Over the last 48 hours, intelligence reports from Mandiant and CISA have confirmed a significant expansion of the Iranian-linked cyber campaign targeting U.S. water and wastewater systems. New victims have been identified in Oregon and New Jersey, following earlier breaches in Minnesota and Georgia. The actors, primarily associated with the CyberAv3ngers group, are exploiting publicly accessible Programmable Logic Controllers (PLCs) to manipulate water pressure and chemical dosing parameters. This escalation marks a critical shift in the threat landscape for municipal infrastructure, moving from simple defacements to active process manipulation. ## Threat Analysis The campaign represents a shift from opportunistic scanning to targeted disruption. While previous Iranian operations focused on public influence messaging, current activity involves direct interaction with Human-Machine Interfaces (HMIs) and SCADA environments. The actors are leveraging the lack of multi-factor authentication (MFA) and the direct internet exposure of industrial assets. Intelligence suggests that the actors are specifically searching for devices with default credentials or those running unpatched firmware. The threat is not limited to a single vendor, as the campaign has broadened to include multiple major industrial automation brands. ## Technical Details The primary TTP involves exploiting Port 44818 (EtherNet/IP) and Port 502 (Modbus). Affected hardware includes Rockwell Automation CompactLogix, Schneider Electric Modicon M340, and Siemens S7-1200 series. In the Oregon incident, attackers successfully modified PLC project files to disable safety alarms, a technique mapped to MITRE ATT&CK for ICS T0831 (Modify Controller Tasking). Forensic analysis of the New Jersey breach revealed the use of compromised engineering workstations to push unauthorized logic changes. The attackers utilized foreign-hosted IP addresses to establish persistent remote access via exposed management interfaces. ## Attribution Assessment High confidence attribution to Iranian-affiliated APTs, specifically CyberAv3ngers. This assessment is based on infrastructure overlaps with previous IRGC-linked operations and the specific targeting of Western infrastructure. The group has publicly claimed responsibility for several of these attacks on social media, though their technical capabilities in some instances have been exaggerated for psychological impact. However, the confirmed logic modifications in recent days indicate a maturing capability set. ## Implications The ability to alter PLC logic poses a direct threat to public safety. Beyond operational downtime, the manipulation of chemical levels in drinking water could lead to widespread health crises. This campaign underscores the critical vulnerability of municipal utilities that lack dedicated OT security teams. The economic impact of these disruptions, including emergency response and system remediation, is estimated to be in the millions for smaller municipalities. ## Recommendations 1. Immediately remove all PLCs and HMIs from direct internet exposure. 2. Implement hardware-based MFA for all remote access to engineering workstations. 3. Conduct a forensic audit of PLC project files to ensure logic integrity. 4. Block inbound traffic on ports 44818, 2222, 102, and 502 from non-authorized IP ranges. 5. Change all default passwords on OT assets and implement a robust patch management program for industrial controllers.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News RoomRelated Intelligence

US Rewards $10M as Iranian Cyber Actors Target Critical Water and Energy Industrial Control Systems
05 Sep 2026

Global Ransomware Surge Hits Record High as Critical Infrastructure Resilience Initiatives Accelerate
15 Sep 2026

Escalating Cyber Threats to US Water Infrastructure: Handala Group and AI-Driven Defense Initiatives
14 Sep 2026
