Six federal agencies have updated their joint cybersecurity advisory, warning of Iranian-affiliated threat actors exploiting internet-connected programmable logic controllers (PLCs) across U.S. The July update expands the manufacturer scope beyond Rockwell Automation and Allen-Bradley CompactLogix and Micro850 controllers, initially mentioned in April, to now include Schneider Electric and Siemens equipment. New detection guidance addresses malicious modifications hidden within shared, reusable code modules—a supply-chain risk where a single tampered module can propagate changes across an entire operational environment.
- Route remote access through secured, multi-factor authentication-gated gateways.
IoCs IoC Detection 185.82.73[. ]175 91 – C&C server 141.11.164[. ]153 91 – C&C server 175.110.121[.
]42 91 – C&C server 175.110.121[. ]39 91 – C&C server 175.110.121[. ]41 38 – Computers/Internet 175.110.121[. ]107 91 – C&C server 192.142.54[.
]79 38 – Computers/Internet 84.200.205[. ]165 38 – Computers/Internet 185.225.17[. ]225 91 – C&C server 79.133.46[. ]209 91 – C&C server 88.80.150[.
]199 91 – C&C server 88.80.150[. ]200 91 – C&C server 88.80.150[. ]202 91 – C&C server 185.82.73[. ]162 91 – C&C server 185.82.73[.
]164 91 – C&C server 185.82.73[. ]165 91 – C&C server 185.82.73[. ]167 91 – C&C server 185.82.73[. ]168 91 – C&C server 185.82.73[.
]170 91 – C&C server 185.82.73[. ]171 91 – C&C server 135.136.1[. ]133 91 – C&C server ocferda[. ]com 91 – C&C server uuokhhfsdlk[.]tylarion867mino[.
]com 91 – C&C server tylarion867mino[. ]com 91 – C&C server Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.












