Skip to content
← RegistryDossier · 5 steps · 4 edges

HMI default credentials → operations disruption

Wonderware / iFix HMI exposed to the corporate network with vendor-default credentials. Operators see attacker-controlled values + commands sent to PLCs through legit channels.

Filed by AD Knowledge Base
§ Kill-chainDrag · zoom · scroll

§ Context

Assumed environment: foothold inside corporate IT. HMI server reachable from there. Credentials never rotated from vendor defaults / shared across sites.

§ Steps

  1. 01
    Issue commands via legit UIInitial Access
    T1078Valid Accounts
  2. 02
    Identify HMI server (Wonderware / iFix / Ignition)Discovery
    N-NMAP-INTERNALInternal Nmap Sweep
  3. 03
    Send dangerous setpoints to PLCsImpact
    OT-MODBUS-WRITEModbus TCP Write to PLC
  4. 04
    Vendor-default admin credentialsInitial Access
    OT-HMI-DEFAULTSHMI Default Credentials
  5. 05
    Suppress alarms / falsify operator viewImpact
    OT-SAFETY-OVERRIDESafety Instrumented System Override

§ References

§ Frequently asked

What is the "HMI default credentials → operations disruption" attack path?
Wonderware / iFix HMI exposed to the corporate network with vendor-default credentials. Operators see attacker-controlled values + commands sent to PLCs through legit channels. It chains 5 steps drawn from real-world offensive-security techniques.
What starting position does this attack require?
The first step is Issue commands via legit UI (T1078) — a initial access primitive. Assumed environment: foothold inside corporate IT.
What is the final impact of this kill-chain?
The final step lands on Suppress alarms / falsify operator view (OT-SAFETY-OVERRIDE), which falls under Impact. From here, an operator typically pivots into post-exploitation or maintains persistence.
How can defenders detect or prevent this attack?
Detection and prevention vary per step. Refer to each linked MITRE ATT&CK entry under "References" — every technique on that page lists defensive controls, detection telemetry, and known threat-actor usage.

§ Related dossiers