Five US agencies warn AI scripts now hunt exposed Siemens PLCs

A five-agency advisory flags an active AI-assisted campaign against internet-exposed Siemens S7 controllers across critical US sectors.

CSBadmin
2 Min Read

Five US agencies warned Wednesday that attackers are using AI-generated scripts to break into internet-exposed Siemens S7 programmable logic controllers (PLCs), calling the campaign an “active threat” to critical infrastructure.

The joint advisory from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency said adversaries are combining AI coding assistants with the open-source snap7 libraries to build custom tools that mimic legitimate OT monitoring software. Those tools use the S7comm protocol to read and write PLC memory, configuration data, and ladder logic programs.

Operators first scan for targets with services like Censys and ZoomEye, then lean on default or weak credentials to get in. The most targeted sectors are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities, with defense plants also named as at risk.

“This is not a theoretical risk, it is an active threat,” the agencies said. Experts see the activity as a continuation of the campaign suspected to be run by Iran-linked operators that hit more than 30 Minnesota water systems in July, now supercharged with AI-assisted tooling.

The advisory assesses the intrusions as persistent reconnaissance and capability development aimed at positioning for write operations that could disrupt industrial processes, trigger safety incidents, or damage equipment.

Agencies urge owners to inventory all S7-200 through S7-1500 controllers, apply critical firmware patches, and verify no PLC is reachable from the internet. They recommend blocking TCP port 102 at perimeter firewalls, reviewing access controls, and hunting for anomalies such as S7comm connections from non-engineering workstations or writes outside change windows. Snap7 library usage outside approved machines is a red flag.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.