Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026

Threat Intelligence Report: Nation-State Targeting of Water Systems 2024–2026
Water and wastewater systems are increasingly targeted as strategic gray-zone assets because exposed OT, weak credentials, and poor IT/OT segmentation make them easy to compromise while carrying outsized public-health and political consequences. Iran, Russia, and China each use these intrusions differently—signaling and retaliation, disruptive hybrid pressure, or quiet pre-positioning—while incidents in the United States and Europe show how low-complexity access can still create fear, disruption, and leverage. #CyberAv3ngers #VoltTyphoon #CyberArmyofRussiaReborn #Unitronics #RockwellAutomation #AllenBradley #Sandworm #CARR

Keypoints

  • Water and wastewater systems are attractive gray-zone targets because they are strategically important yet often poorly defended.
  • Common weaknesses include internet-facing HMIs and PLCs, weak or default passwords, shared accounts, legacy systems, and poor IT/OT segmentation.
  • Iran-linked activity has focused on exposed PLCs and HMI/SCADA compromise, including CyberAv3ngers operations against Unitronics and other control devices.
  • Russia-aligned actors have demonstrated direct manipulation of water infrastructure, including municipal overflow in Texas and dam floodgate control in Norway.
  • China’s Volt Typhoon campaign emphasizes stealthy pre-positioning inside U.S. critical infrastructure, including water and wastewater networks.
  • Incidents in Poland, Arkansas City, Minot, and other locations show that even non-state or unattributed activity can force operators into manual fallback modes.
  • The most likely future risk is persistent low-level access and intermittent disruption rather than a large, destructive “cyber Pearl Harbor.”

MITRE Techniques

  • [T0883 ] Internet Accessible Device – Exposed PLCs and internet-facing ICS were used as entry points into water systems (‘accessed publicly exposed PLCs’ / ‘internet-exposed ICS used as access path’).
  • [T0885 ] Commonly Used Port – Iranian activity used OT communications ports such as 44818, 2222, 102, 502, and SSH on 22 (‘used OT ports including 44818, 2222, 102, 502, and SSH on 22’).
  • [T1219 ] Remote Access Software – Dropbear SSH was deployed to maintain remote access (‘deployed Dropbear SSH for remote access’).
  • [T1565 ] Stored Data Manipulation – Attackers interacted with project files and altered HMI/SCADA display data (‘interacted with project files and altered HMI / SCADA display data’).
  • [T1078 ] Valid Accounts – Weak or default credential abuse was inferred across PLC/HMI compromises (‘default / weak credential abuse against PLCs’ / ‘weak/default passwords’).
  • [T1491 ] Defacement – Unitronics HMI/PLC screens were defaced with pro-CyberAv3ngers messaging (‘HMI/PLC defacement messaging in Unitronics activity’).
  • [T1133 ] External Remote Services – Russian-aligned actors likely accessed exposed industrial interfaces and remote control paths (‘likely access through remote industrial interfaces / exposed remote control paths’).
  • [T1046 ] Network Service Discovery – Exposed water-control interfaces were likely scanned and enumerated (‘assessed scanning / discovery of exposed water-control interfaces’).
  • [T1489 ] Service Stop – Water-system process controls were manipulated to cause overflow and floodgate events (‘manipulation of water-system process controls resulting in overflow / floodgate events’).
  • [T1113 ] Screen Capture – Claim videos showed HMI manipulation through screen recordings (‘claim videos showed screen recordings of HMI manipulation’).
  • [T1190 ] Exploit Public-Facing Application – Volt Typhoon compromised exposed edge devices and public-facing infrastructure (‘compromise of exposed edge devices and public-facing infrastructure’).
  • [T1047 ] Windows Management Instrumentation – WMIC was used for process creation and credential-access workflows (‘WMIC execution for process creation and credential-access workflows’).
  • [T1003.003 ] OS Credential Dumping: NTDS – Attackers attempted extraction of ntds.dit and registry hives (‘attempted extraction of ntds.dit and registry hives’).
  • [T1090 ] Proxy – netsh portproxy was used for forwarding and covert access (‘netsh portproxy used for forwarding / covert access’).
  • [T1059.001 ] PowerShell – Native PowerShell was used in living-off-the-land activity (‘native PowerShell use in LOTL activity’).
  • [T1087 ] Account Discovery – Volt Typhoon performed account and environment enumeration (‘account and environment enumeration’).
  • [T1018 ] Remote System Discovery – Network and host reconnaissance was conducted (‘network and host reconnaissance’).
  • [T1021 ] Remote Services – Lateral movement occurred through compromised internal environments (‘movement through compromised internal environments’).
  • [T1560 ] Archive Collected Data – Collected data was staged and compressed, including 7z examples (‘staging and compression of collected data, including 7z examples’).
  • [T1562 ] Impair Defenses – Low-noise native tooling was used to evade EDR visibility (‘avoidance of EDR visibility through native tooling and low-noise operations’).

Indicators of Compromise

  • [IP address ] Iranian-affiliated PLC communications infrastructure and related OT access activity – 135.136.1[.]133, 185.82.73[.]162, and 6 more IPs
  • [Network ports ] OT and remote-access traffic used in Iranian PLC targeting – TCP/44818, TCP/2222, TCP/102, and 3 more ports
  • [Tool names ] Remote access and engineering tools observed in Iranian operations – Dropbear SSH, Studio 5000 Logix Designer
  • [File/artifact names ] Rockwell project files targeted for extraction or manipulation – .ACD project files, ntds.dit
  • [Defacement text ] CyberAv3ngers HMI message used in Unitronics defacement – “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is CyberAv3ngers legal target.”
  • [Actor / group names ] Russia-linked disruption persona and propaganda artifacts – Cyber Army of Russia Reborn (CARR), Sandworm
  • [Operational artifacts ] Evidence of water-system manipulation and public claims – Telegram claim videos, HMI screen recordings
  • [Process-control behavior ] Physical manipulation in water infrastructure incidents – water-level / stop-level manipulation, floodgate opening
  • [Native Windows tools ] Volt Typhoon living-off-the-land activity – wmic, ntdsutil.exe, netsh interface portproxy, and PowerShell
  • [Credential/artifact files ] Data targeted for domain credential extraction – ntds.dit, SYSTEM registry hive, SECURITY registry hive
  • [Host paths ] Staging locations mentioned in Volt Typhoon reporting – C:WindowsTemp, C:UsersPublic


Read more: https://dti.domaintools.com/research/threat-intelligence-report-nation-state-targeting-of-water-systems-2024-2026