TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets

2026-04-08 · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
72%
“persistent threat ( apt ) group has been observed “ maliciously interacting with project files, and manipulating data displayed on hmi and scada displays, ” according to cisa. the plcs apparently manage a wide variety of industrial processes. they are using “ configuration softwa…”
T1204User Execution
36%
“persistent threat ( apt ) group has been observed “ maliciously interacting with project files, and manipulating data displayed on hmi and scada displays, ” according to cisa. the plcs apparently manage a wide variety of industrial processes. they are using “ configuration softwa…”
T1588.006Vulnerabilities
31%
“persistent threat ( apt ) group has been observed “ maliciously interacting with project files, and manipulating data displayed on hmi and scada displays, ” according to cisa. the plcs apparently manage a wide variety of industrial processes. they are using “ configuration softwa…”

Summary

CISA has revealed Iranian attacks causing disruption and financial loss at US critical infrastructure firms