Several government agencies in the United States have issued a joint cybersecurity advisory warning critical infrastructure organizations about hacker attacks targeting Siemens programmable logic controllers (PLCs).
According to the NSA, CISA, FBI, EPA, and DOE, the hackers are scanning the internet to identify exposed PLCs and developing exploits that could cause serious disruption to industrial processes. Other potential impacts include equipment damage, safety incidents affecting workers, compromise of sensitive data, and cascading effects on supply chains, associated facilities, and business operations.
The unidentified threat actors have targeted sectors such as energy, critical manufacturing, water and wastewater, food and agriculture, chemical, and commercial facilities.
Targeted devices include the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series; for most of them, regardless of the CPU variant.
The agencies said the attackers are using AI to create exploitation scripts for initial access, credential access, DoS attacks, and other purposes. The hackers can also exploit known vulnerabilities affecting the targeted PLCs.
Open source industrial automation libraries such as snap7.dll and python-snap7 are being combined with AI-made scripts to create malicious tools that mimic legitimate OT monitoring software. These tools enable the attackers to tamper with the memory of the targeted Siemens PLC, as well as configuration data and ladder logic programs.Advertisement. Scroll to continue reading.
The advisory notes:
“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploi
SecurityWeek ·