Malik Haidar has spent his career at the intersection of high-stakes industrial operations and the invisible digital battlefield. As a cybersecurity expert with a deep background in protecting multinational corporations, Malik doesn’t just look at code; he analyzes how a single line of malicious logic can disrupt an entire supply chain. His focus on integrating business strategy with intelligence-driven security makes him a leading voice in the fight against state-sponsored actors targeting the backbone of modern society. In this discussion, we explore the evolving threat landscape where Iranian APT groups are no longer just probing for entry, but are actively rewriting the rules of industrial safety. We cover the shift from simple internet exposure to the sophisticated manipulation of PLC project files, the psychological tactics of hacktivist personas like Handala, and the critical need for a proactive defense in sectors ranging from water treatment to energy production.
Recent findings indicate that adversaries are now modifying ladder logic in PLC project files to override safe operating parameters. How does this shift from simple access to active logic manipulation change the risk profile for a facility?
This transition represents a terrifying leap in adversary capability because it moves beyond mere disruption and into the realm of controlled, invisible sabotage. When an attacker modifies the ladder logic in a PLC—like the Siemens S7-1200 or Schneider Electric Modicon M340 series—they are essentially rewriting the “brain” of the machine to ignore its own safety limits. By using configuration software like Rockwell’s Studio 5000 Logix Designer or Siemens TIA Portal, these actors aren’t just flipping a switch; they are adding specific instructions that keep the process running even when it reaches a dangerous state. For an operator, the facility looks normal on the surface, but underneath, the critical shutdown and alarm logic have been silently disabled. This creates a scenario where a catastrophic failure could occur without a single red light flashing on the control room dashboard, turning the very systems designed to protect us into tools of destruction.
The FBI noted that attackers used specific ports like 44818 and 102 to connect to vulnerable devices via manufacturer programming software. What makes these entry points so attractive to state-sponsored actors?
These ports are essentially the front doors for industrial communication, and they are often left unlocked because they are essential for legitimate maintenance and programming. Port 44818 is synonymous with Rockwell’s EtherNet/IP, while port 102 is the gateway for Siemens S7 communication, and seeing these exposed to the internet is like leaving the keys to a power plant in the ignition. Iranian APT actors are leveraging leased third-party infrastructure to mask their location while they scan for these vulnerabilities, looking for Rockwell Automation CompactLogix or Micro850 devices that haven’t been properly segmented. Once they find an opening, they don’t need a complex exploit; they simply use the same manufacturer software that the engineers use to exfiltrate and then re-upload modified logic. It’s a clean, surgical approach that exploits the inherent trust we place in our engineering tools and the standard communication protocols that run our modern world.
Beyond the technical changes to the code, these attackers are manipulating HMI and SCADA displays to show false data. How does this “deception layer” impact the emotional and operational response during an active breach?
The psychological impact of “lying” HMI data is profound because it strips the human operators of their most basic tool: their sense of reality. When an attacker manipulates the data displayed on a human-machine interface, they are creating a digital mirage where everything looks “green” and within normal parameters, while the actual physical hardware is being pushed to its breaking point. It’s a sensory-deprivation tactic that prevents an engineer from reacting until it is far too late, often causing a feeling of helplessness once the true state of the facility is finally revealed. We saw this with groups like CyberAv3ngers and more recently with Handala; they want to create a sense of pervasive insecurity. It’s one thing to have a system go down, but it’s another thing entirely to realize you were watching a fake movie of a stable system while the real one was being systematically dismantled under your nose.
Groups like Handala and CyberAv3ngers often use hacktivist personas to claim high-profile successes, such as the alleged breach of California Water Service. What is the strategic goal behind using these personas for industrial attacks?
Using these hacktivist personas provides the Iranian government with a layer of plausible deniability while maximizing the terror felt by the civilian population. When a group like Handala claims they could have disrupted the water supply for a major utility, the goal isn’t just a technical win; it’s a strike at the heart of public trust in critical infrastructure. Even if the utility, like California Water Service, finds no evidence of activity in their OT environment, the mere claim creates a ripple of fear and forces a massive, expensive investigation. These personas allow the attackers to be loud and boastful, using highly disruptive attacks like the one on medical giant Stryker to build a reputation that precedes them. It’s a form of information warfare where the threat of what they could do is often just as damaging as the actual breach, forcing organizations to operate in a state of constant, exhausting high alert.
What is your forecast for the future of industrial control system security in light of these advancing threats?
I believe we are entering an era where “security through obscurity” is officially dead, and we will see a mandatory shift toward cryptographically signed firmware and project files as a standard, not an option. As actors continue to target ports 502, 2222, and 22 with increasing precision, the industry will have to move toward zero-trust architectures where every change to a PLC’s logic requires multi-factor authentication and an immutable audit trail. We will likely see a rise in AI-driven anomaly detection that doesn’t just look at network traffic, but actually validates the physical process against the digital logic to catch “silent” overrides before they manifest in reality. The battle will move deeper into the logic layer, and the organizations that survive will be those that treat their PLC code as their most sensitive intellectual property. The era of trusting that an air gap or a simple firewall will protect a Siemens or Schneider device is over; the future is about verifying every single instruction that reaches the machine floor.

