A joint cybersecurity advisory from CISA, FBI, NSA, EPA, and international partners including Israel's INCD, Canada's CCCS, and the UK's NCSC warns of continued malicious cyber activity by IRGC-affiliated APT actors operating under the persona "CyberAv3ngers," targeting Israeli-made Unitronics Vision Series programmable logic controllers (PLCs) and human-machine interfaces (HMIs) across critical infrastructure sectors worldwide.
The Campaign: Geopolitically Motivated OT Targeting
Beginning in November 2023, CyberAv3ngers began actively compromising Unitronics PLCs — commonly deployed in Water and Wastewater Systems (WWS) and used across energy, food and beverage manufacturing, transportation, and healthcare sectors. Compromised devices were defaced with the message: "You have been hacked, down with Israel. Every equipment 'made in Israel' is CyberAv3ngers legal target." The campaign targeted victims across multiple U.S. states and foreign countries, with the UK's NCSC specifically noting PLC targeting in Britain as part of a broader campaign against Israeli technology.
A critical operational security concern: the affected Unitronics PLCs may be rebranded and appear to originate from different manufacturers, complicating asset identification for defenders performing inventory audits.
Expanded TTPs: Beyond Defacement to Operational Disruption
The December 2024 advisory update revealed that the late 2023 campaign compromised additional Unitronics device types — including older PLC models not previously reported — and that threat actors developed custom ladder logic files tailored to each device type. The actors went beyond simple defacement, employing a set of operational disruption techniques including:
- Supplanting existing ladder logic with custom malicious versions.
- Renaming devices — likely to delay owner recognition and recovery access.
- Resetting firmware to older, more vulnerable software versions.
- Disabling upload and download functions to impede remediation.
- Changing default port numbers to frustrate network-level detection.
This level of access — with the ability to modify control logic on operational PLCs — means the actors could potentially cause physical effects on industrial processes and equipment, extending the threat well beyond a reputational defacement campaign into the realm of potential sabotage.
Risk to OT Environments
The authoring agencies assess that PLCs connected insecurely to the internet — particularly those retaining default or no passwords — represent the primary exposure vector. The advisory emphasizes that ICS/OT environments have historically lagged behind IT environments in basic security hygiene, and that PLCs accessible from the public internet without authentication controls present an unacceptable risk profile in the current threat environment. Recommended immediate actions include addressing internet-exposed OT devices, enforcing multi-factor authentication, implementing strong unique passwords, and auditing all PLCs for default or absent authentication credentials.