{"id":26240,"date":"2026-09-21T16:09:19","date_gmt":"2026-09-22T00:09:19","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/federal-agencies-warn-of-ongoing-plc-exploitation-against-critical-u-s-infrastructure\/"},"modified":"2026-09-21T16:09:19","modified_gmt":"2026-09-22T00:09:19","slug":"federal-agencies-warn-of-ongoing-plc-exploitation-against-critical-u-s-infrastructure","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/federal-agencies-warn-of-ongoing-plc-exploitation-against-critical-u-s-infrastructure\/","title":{"rendered":"Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure"},"content":{"rendered":"<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"815958323\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\">\n<div class=\"article-details\" role=\"heading\">\n<span class=\"article-details__bar\" role=\"img\"><\/span><\/p>\n<p class=\"article-details__display-tag\">Cyber Threats<\/p>\n<h1 class=\"article-details__title\">Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure<\/h1>\n<p class=\"article-details__description\">TrendAI\u2122 Research breaks down what changed in CISA\u2019s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.<\/p>\n<p class=\"article-details__author-by\">By: Jamal Bethea<\/p>\n<p>\t\t\t<time class=\"article-details__date\">Jul 23, 2026<\/time><br \/>\n<span>Read time:\u00a0<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words)\n\t<\/p>\n<div class=\"article-details__icons\">\n<!--Add This--><\/p>\n<div class=\"a2a_kit a2a_default_style\" data-a2a-icon-color=\"#717172\">\n<a class=\"a2a_dd addthis_link\" href=\"https:\/\/www.addtoany.com\/share\"><br \/>\n<img decoding=\"async\" alt=\"Share\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/share-more.svg\"\/><br \/>\n<\/a><br \/>\n<a class=\"a2a_button_print addthis_link\"><br \/>\n<img decoding=\"async\" alt=\"Print\" class=\"svg-icon\" src=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch\/resources\/img\/printer.svg\"\/><br \/>\n<\/a>\n<\/div>\n<p><!--Add to Folio--><\/p>\n<div class=\"add-to-folio tooltip\">\n<span class=\"icon-folio-thin\"><\/span><\/p>\n<div class=\"right\">\n<p>Save to Folio<\/p>\n<p><i><\/i>\n<\/div>\n<\/div>\n<p><!--Subscribe--><\/p>\n<div class=\"subscribe\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"research-layout-divider\"\/>\n<main class=\"main--content col-xs-12 col-lg-8 col-lg-push-2\"><\/p>\n<div>\n<\/div>\n<div class=\"richText\">\n<\/div>\n<div class=\"image\">\n<\/div>\n<div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">Key takeaways<\/span><\/h1>\n<ul>\n<li><span class=\"rte-red-bullet\">Multiple federal agencies updated their joint CISA advisory, warning that attackers manipulated operator displays so personnel couldn\u2019t visually detect anything was amiss on their screens.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The attackers scanned the internet for exposed PLCs and connected using legitimate engineering software, the same way an authorized technician would.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The July 2026 update widens the manufacturer scope beyond Rockwell Automation \/ Allen-Bradley to include Schneider Electric and Siemens equipment, and adds detection guidance for malicious changes hidden in shared, reusable code modules.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Unlike a similar but largely disruption-free campaign in 2023, this ongoing activity has caused confirmed operational disruption and financial loss for some affected organizations.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Targeted sectors include government facilities, water systems, and energy infrastructure across the U.S.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">The TrendAI Vision One\u2122 platform detects and blocks the indicators of compromise (IoCs) associated with this activity, listed at the end of this entry.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p>Six federal agencies have just updated an advisory about ongoing attacks on the equipment that physically runs U.S. critical infrastructure, including city services, water plants, and power facilities. The advisory, first issued in April 2026 and revised on July 22, warns that attackers are actively targeting these systems.\u00a0<\/p>\n<p>The activity involves attackers scanning the internet for exposed industrial control systems (ICS) and connecting to them using legitimate engineering software, the same way an authorized technician would.\u00a0Once inside, they alter the controllers\u2019 underlying logic, the instructions that tell the equipment what to do. In some cases, they also change what\u2019s shown on the operators\u2019 screens. The attacks are built specifically so the humans in the loop can\u2019t spot any anomalies on their screens.\u00a0<\/p>\n<p>The joint advisory, <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\" target=\"_blank\">AA26-097A<\/a>, is cosigned by the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Environmental Protection Agency (EPA), the Department of Energy, and U.S. Cyber Command. It warns that nation-state and advanced persistent threat (APT) actors are actively exploiting internet-facing programmable logic controllers (PLCs) across U.S. government services, water systems, and energy infrastructure.\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">What is a PLC and why is this physical?<\/span><\/h1>\n<p>A PLC is a specialized, ruggedized industrial device built to run the control logic that operates physical equipment. It replaced the banks of hardwired electromechanical relays that once did this job, swapping fixed wiring for logic that can be reprogrammed. It\u2019s what opens the valve, starts the pump, holds the pressure, and trips the breaker.<\/p>\n<p>A PLC runs its control logic on the device itself, so it drives the physical process with or without a network connection. What makes the ongoing activity possible is that many are also reachable over a network, and that reach is what the attackers exploit.<\/p>\n<p>Two other terms significant to this incident are the following:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Project file: The blueprint that tells the controller how to operate. On Rockwell Automation \/ Allen-Bradley equipment, it\u2019s a binary .ACD file, built in Studio 5000 Logix Designer, that stores much more than the logic alone: the ladder logic plus the tag database, I\/O and controller configuration, and overall program structure. In simple terms, it holds rules like \u201cif pressure exceeds the limit, close the valve,\u201d but it captures the whole operating setup, not just individual rules.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Human-machine interface (HMI): The screens operators watch to see what the equipment is doing and to control it.<\/span><\/li>\n<\/ul>\n<p>Held together, these three make the core of the ongoing exploitation easy to describe: The attackers reach the controllers, copy the blueprint, and change what the humans see. A real industrial environment is far more than these three pieces\u2014it includes mechanical processes that no PLC controls and steps that still depend on people\u2014but this narrow slice is exactly what the attackers manipulate.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">How this differs from the 2023 attacks<\/span><\/h1>\n<p>In November 2023, a group affiliated with the Iranian IRGC Cyber Electronic Command (IRGC-CEC), known as CyberAv3ngers (also tracked as Hydro Kitten, Shahid Kaveh Group, and Storm-0784), <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-335a\" target=\"_blank\">compromised at least 75 PLCs<\/a> in U.S. water facilities. Those devices were running default credentials, so it was a simple problem with a simple fix: Change the password.<\/p>\n<p>Short of formally naming the same group, the federal agencies describe activity in the ongoing attacks that is consistent with the 2023 attacks. The current exploitation is more sophisticated in three specific ways:\u00a0<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Better tooling: Instead of default passwords, the actors use Rockwell\u2019s own Studio 5000 Logix Designer, legitimate engineering software with working credentials. From the network\u2019s point of view, the connection looks like a solid job done by a technician.\u00a0<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Wider scope: The advisory\u2019s original April 2026 publication centered on Rockwell Automation \/ Allen-Bradley CompactLogix and Micro850 controllers. The July 2026 update widens that scope to include Schneider Electric and Siemens PLCs, along with other brands.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Real consequences: The 2023 campaign was largely disruption-free, whereas the ongoing exploitation has produced confirmed operational disruption and financial loss for some victim organizations.<\/span><\/li>\n<\/ul>\n<p>The advisory update also flags a quieter but serious risk: malicious changes hidden inside reusable code modules, shared blocks of logic dropped into many PLC programs at once. Because a tampered module carries its changes into every process that reuses it, a single edit can spread across an entire operation. That turns an operator\u2019s own engineering library, full of trusted configuration standards and specs, into a supply-chain problem, which is exactly what the update\u2019s new detection guidance is meant to catch. \u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">No vulnerability required<\/span><\/h1>\n<p>Traffic tied to the ongoing activity showed up on five ports:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">22 (SSH)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">102 (ISO-TSAP, primarily used by Siemens STEP 7 and the S7comm protocol, though other protocols such as ICCP also run over it)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">502 (Modbus TCP)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">2222 (EtherNet\/IP implicit messaging, runs over UDP for time-critical I\/O)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">44818 (EtherNet\/IP explicit messaging, TCP only, used for configuration and diagnostics; primarily associated with Rockwell Automation \/ Allen-Bradley, though other vendors such as Wago use it too)<\/span><\/li>\n<\/ul>\n<p>None of that traffic depends on a software bug. The threat actors scan for internet-exposed PLCs and connect to them the same way a legitimate engineer would. That is an architectural weakness, not a patchable one, because these controllers are deployed without sufficient network segmentation, authentication gating, or remote-access hardening. Public scan data from Shodan shows more than <a href=\"https:\/\/www.shodan.io\/search?query=tag%3Aics+%21tag%3Ahoneypot\" target=\"_blank\">74,000 ICS devices<\/a> directly reachable from the open internet today\u2014down from a level that held <a href=\"https:\/\/trends.shodan.io\/search?query=tag%3Aics+%21tag%3Ahoneypot#overview\" target=\"_blank\">around 120,000<\/a> for much of the period since 2017\u2014and many still run default or no credentials at all.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">Security recommendations<\/span><\/h1>\n<p>Defending against these attacks is largely a matter of configuration and access control, so it requires no new hardware or lengthy procurement cycle and can begin immediately. The steps below move from what to do this week, to what to fix this quarter, to what the industry itself owes operators and organizations.\u00a0<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b>What to do this week<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Remove PLCs from direct internet exposure. <\/b><span style=\"font-weight: normal;\">Route all remote access through a secure gateway or jump host with multifactor authentication (MFA), and ensure cellular modems used for field connectivity are authenticated and logged.<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Use physical mode switches where available. <\/b><span style=\"font-weight: normal;\">Set hardware key switches to RUN and only move to PROGRAM or REMOTE during active, supervised maintenance windows. On some controllers, the switch position can still be overridden by a network command, so it works best as one layer alongside removing internet exposure and gating remote access.<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Search logs for the published indicators.<\/b> <span style=\"font-weight: normal;\">Query firewall, intrusion detection system, and network monitoring logs for the advisory IP addresses on ports 22, 102, 502, 2222, and 44818, with attention to traffic from overseas hosting providers.\u00a0<\/span><\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b>What to fix this quarter<\/b><\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Enable programming protection on software key switches. <\/b><span style=\"font-weight: normal;\">Rockwell operators should follow the current <a href=\"https:\/\/www.rockwellautomation.com\/en-us\/trust-center\/security-advisories.html\" target=\"_blank\">SD1771 guidance<\/a>; Siemens operators should <a href=\"https:\/\/cert-portal.siemens.com\/operational-guidelines-industrial-security.pdf\" target=\"_blank\">configure protection<\/a> in TIA Portal.<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Back up PLC logic and configurations offline, and test restores. <\/b><span style=\"font-weight: normal;\">Store backups on secured physical media, separate from the network the PLC lives on.<\/span><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Harden beyond the immediate response. <\/b><span style=\"font-weight: normal;\">Enforce MFA on all operational technology (OT) remote access, block unnecessary OT ports at the perimeter, disable unused services like Telnet and default web interfaces, and monitor continuously for configuration changes against a known-good baseline.<\/span><\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b>Pushing accountability to vendors<\/b><\/p>\n<p>The advisory doesn\u2019t put all of this on operators. It presses manufacturers directly: Ship products that don\u2019t expose administrative interfaces to the internet by default, support MFA (including phishing-resistant methods), and stop charging extra fees for the basic security features that a product needs to run safely. Organizations <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/secure-demand-priority-considerations-operational-technology-owners-and-operators-when-selecting\" target=\"_blank\">buying industrial equipment<\/a> should make these firm conditions of purchase and get them written into the contract.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<p><b>Validating continuously<\/b><\/p>\n<p>When the intrusion method involves legitimate software and valid credentials, a point-in-time assessment reveals almost nothing about whether an environment stays protected next month. The advisory\u2019s own recommendation is to validate these controls continuously, rather than check them once. Knowing what\u2019s reachable from the internet into the OT environment and confirming that segmentation is enforced rather than assumed is the whole difference between reading the advisory and acting on it.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/span><\/h1>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\" target=\"_blank\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/a> provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI\u2122 Research, and TrendAI Vision One\u2122 Threat Intelligence Feed in the <a href=\"https:\/\/www.trendaisecurity.com\/en\/platform\" target=\"_blank\">TrendAI Vision One\u2122<\/a> platform.<\/p>\n<p><b>Emerging Threats:\u00a0<\/b><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence_insights?name=Federal%20Agencies%20Warn%20of%20Ongoing%20PLC%20Exploitation%20Against%20Critical%20US%20Infrastructure\" target=\"_blank\"><u>Federal Agencies Warn of Ongoing PLC Exploitation Against Critical US Infrastructure<\/u><\/a><\/p>\n<p><b>TrendAI Vision One\u2122 Intelligence Reports (IoC Sweeping)\u00a0<\/b><\/p>\n<p><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence?intrusionSet=Federal%20Agencies%20Warn%20of%20Ongoing%20PLC%20Exploitation%20Against%20Critical%20US%20Infrastructure\" target=\"_blank\">Federal Agencies Warn of Ongoing PLC Exploitation Against Critical US Infrastructure<\/a><\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><b style=\"font-family: adobe-clean , Helvetica , Arial , sans-serif;\"><span class=\"body-subhead-title\">TrendAI Vision One\u2122 XDR Data Explorer App\u00a0<\/span><\/b><\/h1>\n<p>Customers using TrendAI Vision One\u2122 can use the XDR Data Explorer App to match the malicious indicators covered in this blog article against data in their own environments for hunting purposes.<\/p>\n<p><b>CyberAv3ngers C&amp;C infrastructure connections<\/b><\/p>\n<p><span class=\"blockquote\">eventSubId:201 AND dst:(&#8220;185.82.73.175&#8221; OR &#8220;141.11.164.153&#8221; OR &#8220;175.110.121.42&#8221; OR &#8220;175.110.121.39&#8221; OR &#8220;175.110.121.107&#8221; OR &#8220;185.225.17.225&#8221; OR &#8220;79.133.46.209&#8221; OR &#8220;88.80.150.199&#8221; OR &#8220;88.80.150.200&#8221; OR &#8220;88.80.150.202&#8221; OR &#8220;185.82.73.162&#8221; OR &#8220;185.82.73.164&#8221; OR &#8220;185.82.73.165&#8221; OR &#8220;185.82.73.167&#8221; OR &#8220;185.82.73.168&#8221; OR &#8220;185.82.73.170&#8221; OR &#8220;185.82.73.171&#8221; OR &#8220;135.136.1.133&#8221;)<\/span><\/p>\n<p><b>CyberAv3ngers C&amp;C DNS resolution<\/b><\/p>\n<p><span class=\"blockquote\">eventSubId:301 AND hostName:(*tylarion867mino.com* OR *ocferda.com*)<\/span><\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div>\n<h1><span class=\"body-subhead-title\"><br \/>\n Indicators of compromise<\/span><\/h1>\n<p>The indicators of compromise (IoCs) listed below are sourced from CISA. These are detected and blocked by the TrendAI Vision One\u2122 platform.<\/p>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<p><b>URLs and IP addresses<\/b><\/p>\n<p><center><\/p>\n<table border=\"1\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><b>IoC<\/b><\/td>\n<td style=\"text-align: center;\"><b>Detection<\/b><\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]175<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>141.11.164[.]153<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>175.110.121[.]42<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>175.110.121[.]39<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>175.110.121[.]41<\/td>\n<td>38 &#8211; Computers\/Internet<\/td>\n<\/tr>\n<tr>\n<td>175.110.121[.]107<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>192.142.54[.]79<\/td>\n<td>38 &#8211; Computers\/Internet<\/td>\n<\/tr>\n<tr>\n<td>84.200.205[.]165<\/td>\n<td>38 &#8211; Computers\/Internet<\/td>\n<\/tr>\n<tr>\n<td>185.225.17[.]225<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>79.133.46[.]209<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>88.80.150[.]199<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>88.80.150[.]200<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>88.80.150[.]202<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]162<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]164<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]165<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]167<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]168<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]170<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>185.82.73[.]171<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>135.136.1[.]133<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>ocferda[.]com<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>uuokhhfsdlk[.]tylarion867mino[.]com<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<tr>\n<td>tylarion867mino[.]com<\/td>\n<td>91 &#8211; C&amp;C server<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/center>\n<\/div>\n<\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<p><b>File hashes<\/b><\/p>\n<p><center><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><b>IoC<\/b><\/td>\n<td style=\"text-align: center;\"><b>Detection<\/b><\/td>\n<\/tr>\n<tr>\n<td>366e435a1ea0f597deb6ebe7c0c5acdb6e8b33eb<\/td>\n<td>Backdoor.Linux.IOCONTROL.CIGBCBF<\/td>\n<\/tr>\n<tr>\n<td>95bd07b4400095acdafce05888da27228d7d07ca<\/td>\n<td>Trojan.Win64.MALPDB.A<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/center>\n<\/div>\n<\/div>\n<\/div>\n<section class=\"tag--list\">\n<div class=\"tag--list-title\">Tags<\/div>\n<div class=\"tag--list-tags\">\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:article-type\/latest-news\">Latest News<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:medium\/article\">Articles, News, Reports<\/a><br \/>\n<span class=\"tag--list-separator\" role=\"separator\">|<\/span><br \/>\n<a class=\"tag--list-anchor\" href=\"\/en_us\/research.html?category=trend-micro-research:threats\/cyber-threats\">Cyber Threats<\/a>\n<\/div>\n<\/section>\n<p><\/main><br \/>\n<sidebar class=\"sidebar--left col-xs-12 col-lg-2 col-lg-pull-8\"><\/p>\n<h3 class=\"article-authors__title\">\n<p>\t\tAuthors<\/p>\n<\/h3>\n<p><!-- \/* Show Trend Micro if we don't have any authors for this article *\/ --><\/p>\n<ul class=\"article-authors__list\">\n<li class=\"article-authors__list-items\">\n<div class=\"article-authors__wrapper\" role=\"contentinfo authors profile\">\n<p class=\"article-authors__list-items__name\">Jamal Bethea<\/p>\n<p class=\"article-authors__list-items__position\">Product Manager<\/p>\n<\/div>\n<\/li>\n<\/ul>\n<div class=\"article-authors__btn-wrapper\" role=\"button\">\n<a class=\"article-authors__button\" href=\"mailto:tm_research@trendmicro.com\" id=\"article-authors-contact-us-button\" target=\"target\"><br \/>\n\t\tContact Us<br \/>\n\t<\/a>\n<\/div>\n<p><\/sidebar><br \/>\n<sidebar class=\"sidebar--right col-xs-12 col-lg-2\"><\/p>\n<div class=\"sidebar--wrapper\" role=\"contentinfo sidebar\">\n<div class=\"row-1\" role=\"contentinfo related articles\">\n<div class=\"related--articles\" role=\"contentinfo related articles\">\n<h3 class=\"related--articles-title\">Related Articles<\/h3>\n<ul class=\"related--articles-items\">\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/24\/c\/unveiling-earth-kapre-aka-redcurls-cyberespionage-tactics-with-t.html\"><br \/>\n\t\t\t\t\tUnveiling Earth Kapre aka RedCurl\u2019s Cyberespionage Tactics With Trend Micro MDR, Threat Intelligence<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/22\/h\/secure-access-service-edge-sase-security-company.html\"><br \/>\n\t\t\t\t\tA Secure Access Service Edge (SASE) Guide for Leaders<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<li class=\"related--articles-item\">\n<a class=\"related--articles-item-anchor\" href=\"\/en_us\/research\/26\/g\/open-secure-ai-alliance.html\"><br \/>\n\t\t\t\t\tWhy the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility<br \/>\n\t\t\t\t<\/a>\n<\/li>\n<\/ul>\n<\/div>\n<div class=\"archived--link\">\n<div class=\"archived--link-text\">\n<a href=\"\/en_us\/research.html\"><br \/>\n\t\t\t\tSee all articles<br \/>\n\t\t\t<\/a>\n<\/div>\n<div class=\"archived--link-icon\">\n<a href=\"\/en_us\/research.html\"><br \/>\n<span class=\"icon-chevron-right\"><\/span><br \/>\n<\/a>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p><\/sidebar><br \/>\n<\/article>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cyber ThreatsFederal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. InfrastructureTrendAI\u2122 Research breaks down what changed in CISA\u2019s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.By: Jamal BetheaJul 23, 2026Read time:(words)Save to FolioKey takeawaysMultiple federal agencies updated their joint CISA advisory, warning that attackers manip<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32777],"tags":[],"class_list":["post-26240","post","type-post","status-publish","format-standard","hentry","category-trend-micro"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26240"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26240\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26240"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}