Water and wastewater systems are increasingly targeted as strategic gray-zone assets because exposed OT, weak credentials, and poor IT/OT segmentation make them easy to compromise while carrying outsized public-health and political consequences. Iran, Russia, and China each use these intrusions differently—signaling and retaliation, disruptive hybrid pressure, or quiet pre-positioning—while incidents in the United States and Europe show how low-complexity access can still create fear, disruption, and leverage. #CyberAv3ngers #VoltTyphoon #CyberArmyofRussiaReborn #Unitronics #RockwellAutomation #AllenBradley #Sandworm #CARR
Keypoints
- Water and wastewater systems are attractive gray-zone targets because they are strategically important yet often poorly defended.
- Common weaknesses include internet-facing HMIs and PLCs, weak or default passwords, shared accounts, legacy systems, and poor IT/OT segmentation.
- Iran-linked activity has focused on exposed PLCs and HMI/SCADA compromise, including CyberAv3ngers operations against Unitronics and other control devices.
- Russia-aligned actors have demonstrated direct manipulation of water infrastructure, including municipal overflow in Texas and dam floodgate control in Norway.
- China’s Volt Typhoon campaign emphasizes stealthy pre-positioning inside U.S. critical infrastructure, including water and wastewater networks.
- Incidents in Poland, Arkansas City, Minot, and other locations show that even non-state or unattributed activity can force operators into manual fallback modes.
- The most likely future risk is persistent low-level access and intermittent disruption rather than a large, destructive “cyber Pearl Harbor.”
MITRE Techniques
- [T0883 ] Internet Accessible Device – Exposed PLCs and internet-facing ICS were used as entry points into water systems (‘accessed publicly exposed PLCs’ / ‘internet-exposed ICS used as access path’).
- [T0885 ] Commonly Used Port – Iranian activity used OT communications ports such as 44818, 2222, 102, 502, and SSH on 22 (‘used OT ports including 44818, 2222, 102, 502, and SSH on 22’).
- [T1219 ] Remote Access Software – Dropbear SSH was deployed to maintain remote access (‘deployed Dropbear SSH for remote access’).
- [T1565 ] Stored Data Manipulation – Attackers interacted with project files and altered HMI/SCADA display data (‘interacted with project files and altered HMI / SCADA display data’).
- [T1078 ] Valid Accounts – Weak or default credential abuse was inferred across PLC/HMI compromises (‘default / weak credential abuse against PLCs’ / ‘weak/default passwords’).
- [T1491 ] Defacement – Unitronics HMI/PLC screens were defaced with pro-CyberAv3ngers messaging (‘HMI/PLC defacement messaging in Unitronics activity’).
- [T1133 ] External Remote Services – Russian-aligned actors likely accessed exposed industrial interfaces and remote control paths (‘likely access through remote industrial interfaces / exposed remote control paths’).
- [T1046 ] Network Service Discovery – Exposed water-control interfaces were likely scanned and enumerated (‘assessed scanning / discovery of exposed water-control interfaces’).
- [T1489 ] Service Stop – Water-system process controls were manipulated to cause overflow and floodgate events (‘manipulation of water-system process controls resulting in overflow / floodgate events’).
- [T1113 ] Screen Capture – Claim videos showed HMI manipulation through screen recordings (‘claim videos showed screen recordings of HMI manipulation’).
- [T1190 ] Exploit Public-Facing Application – Volt Typhoon compromised exposed edge devices and public-facing infrastructure (‘compromise of exposed edge devices and public-facing infrastructure’).
- [T1047 ] Windows Management Instrumentation – WMIC was used for process creation and credential-access workflows (‘WMIC execution for process creation and credential-access workflows’).
- [T1003.003 ] OS Credential Dumping: NTDS – Attackers attempted extraction of ntds.dit and registry hives (‘attempted extraction of ntds.dit and registry hives’).
- [T1090 ] Proxy – netsh portproxy was used for forwarding and covert access (‘netsh portproxy used for forwarding / covert access’).
- [T1059.001 ] PowerShell – Native PowerShell was used in living-off-the-land activity (‘native PowerShell use in LOTL activity’).
- [T1087 ] Account Discovery – Volt Typhoon performed account and environment enumeration (‘account and environment enumeration’).
- [T1018 ] Remote System Discovery – Network and host reconnaissance was conducted (‘network and host reconnaissance’).
- [T1021 ] Remote Services – Lateral movement occurred through compromised internal environments (‘movement through compromised internal environments’).
- [T1560 ] Archive Collected Data – Collected data was staged and compressed, including 7z examples (‘staging and compression of collected data, including 7z examples’).
- [T1562 ] Impair Defenses – Low-noise native tooling was used to evade EDR visibility (‘avoidance of EDR visibility through native tooling and low-noise operations’).
Indicators of Compromise
- [IP address ] Iranian-affiliated PLC communications infrastructure and related OT access activity – 135.136.1[.]133, 185.82.73[.]162, and 6 more IPs
- [Network ports ] OT and remote-access traffic used in Iranian PLC targeting – TCP/44818, TCP/2222, TCP/102, and 3 more ports
- [Tool names ] Remote access and engineering tools observed in Iranian operations – Dropbear SSH, Studio 5000 Logix Designer
- [File/artifact names ] Rockwell project files targeted for extraction or manipulation – .ACD project files, ntds.dit
- [Defacement text ] CyberAv3ngers HMI message used in Unitronics defacement – “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is CyberAv3ngers legal target.”
- [Actor / group names ] Russia-linked disruption persona and propaganda artifacts – Cyber Army of Russia Reborn (CARR), Sandworm
- [Operational artifacts ] Evidence of water-system manipulation and public claims – Telegram claim videos, HMI screen recordings
- [Process-control behavior ] Physical manipulation in water infrastructure incidents – water-level / stop-level manipulation, floodgate opening
- [Native Windows tools ] Volt Typhoon living-off-the-land activity – wmic, ntdsutil.exe, netsh interface portproxy, and PowerShell
- [Credential/artifact files ] Data targeted for domain credential extraction – ntds.dit, SYSTEM registry hive, SECURITY registry hive
- [Host paths ] Staging locations mentioned in Volt Typhoon reporting – C:WindowsTemp, C:UsersPublic