Historical intelligence backfill. This assessment covers reporting originally published on 2026-04-08 and was added to the RWP archive on 2026-09-07.

Daily Top · OT

AA26-097A — they used Studio 5000 on internet PLCs. There was no CVE in the room

CISA/FBI/NSA/EPA/DOE/CYBERCOM, 7 April 2026. CompactLogix and Micro850 reached with Rockwell's own engineering software. Nozomi's next-day note is the defender translation: the manual was the exploit.

RWP Ventures · 2026-09-07 · event 2026-04-07 · 2 min read · priority 8.6

Bottom line up front

CONFIRMED Joint advisory AA26-097A, 7 April 2026 — Iran-affiliated APT activity against internet-facing Rockwell/Allen-Bradley PLCs (CompactLogix, Micro850) using legitimate Studio 5000 Logix Designer from leased overseas infrastructure. Ports called out include 44818, 2222, 102, 22, 502. Agencies: some victims had operational disruption and financial loss. Attribution in public tracking: IRGC-aligned set also named CyberAv3ngers / Storm-0784 / BAUXITE / UNC5691 / Shahid Kaveh — treat those aliases as REPORTED overlap, not a courtroom ID. Nozomi 8 April: this is not a product 0-day; it is an exposed engineering port. Ladder-logic / config changes: CONFIRMED as the agencies' observed technique. July 2026 advisory update expanding to Siemens/Schneider is a later seed — not this post. Distinct from the 31 July FBI/EPA seven-state MicroLogix PSA already in the archive.

Historical backfill of 8 April 2026 reporting; added 7 September 2026.

What happened

Actors logged into PLCs the way an integrator does, because the PLCs were on the internet.

Why it mattered

Your CVE program will not fire. Your "we patched Rockwell" slide will not fire. The control is: no engineering protocol on the public internet.

Who / what was affected

US critical infrastructure with exposed Allen-Bradley. Exposure counts in follow-on blogs (thousands of hosts) are third-party scans — REPORTED.

Technical context

Remove 44818/2222 from WAN. VPN + jump host for Studio 5000. Inventory CompactLogix/Micro850. Watch for unexpected project uploads.

Exploitation / threat status at the time

CONFIRMED joint advisory activity since at least March 2026.

REPORTED CyberAv3ngers alias mapping.

What defenders should have done

  1. Shodan yourself before they do.
  2. FactoryTalk/Studio 5000 only from managed engineering jump boxes.
  3. Tabletop: HMI values that no longer match the field.

RWP assessment

Confidence: High. This is the year's cleanest "OT access without malware" case.

Defensive actions

  1. Internet-facing PLC eradication program.
  2. Log engineering-software sessions.
  3. Read the July AA26-097A update as a sequel, not a rewrite of April.

Sources

  1. Nozomi Networks — These Iranian-affiliated attackers didn't need a zero-day
  2. CISA — AA26-097A Iranian-affiliated actors exploit PLCs across US critical infrastructure
  3. RISI — Iran-linked CyberAv3ngers Rockwell PLC campaign