Skip to content
Tech News
← Back to articles

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

read original more articles
Why This Matters

The U.S. government warns of ongoing AI-driven cyberattacks targeting Siemens PLCs in critical infrastructure, highlighting a growing threat to essential sectors like energy, water, and manufacturing. These sophisticated exploits leverage AI-generated scripts to access and manipulate industrial control systems, posing risks of disruption, data theft, and safety hazards. This underscores the urgent need for enhanced cybersecurity measures in industrial environments to protect national security and public safety.

Key Takeaways

U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.

PLCs are industrial computers used to automate and control machinery and physical processes in factories and other critical infrastructure.

The NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency issued the joint advisory Wednesday, saying the attacks are ongoing.

"This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs)," reads the advisory.

"However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems."

The critical infrastructure sectors most targeted include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies also note that Siemens S7 PLCs are used in the Defense Industrial Base, which could also be targeted.

Threat actors are using internet scanning services, including Censys and ZoomEye, to find exposed Siemens PLCs and exploit critical and high-severity vulnerabilities, outdated software, and weak authentication.

The advisory says the attackers are using artificial intelligence to develop Python exploitation scripts that use the 'snap7.dll' and 'python-snap7' libraries to communicate with Siemens S7 PLC devices.

These custom tools are disguised as legitimate OT monitoring software and can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol.

The agencies say the activity appears focused on persistent reconnaissance, potentially preparing attackers for disruption to critical infrastructure, including stealing sensitive data, damaging equipment, causing extended downtime, or leading to safety incidents.

... continue reading