The first distributed cyberattack on multiple U.S. water systems indicates a coordinated Iranian campaign targeting programmable logic controllers, potentially linked through shared infrastructure or a systems integrator.
Attackers establish multiple persistence mechanisms and disable protective measures after intrusion; removing malware alone without investigating the entry point leads to renewed compromise.