Ethical Hacking News
The threat landscape for critical infrastructure continues to evolve, with recent warnings from the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the U.S. Department of Energy (DOE), and the U.S. Environmental Protection Agency (EPA) signaling an active AI-assisted attacks against Siemens S7 Series programmable logic controllers (PLCs). The joint advisory highlights the growing threat of AI-generated exploitation scripts disguised as legitimate monitoring tools, and provides guidance on how to mitigate this threat. Asset owners must take immediate action to secure their PLC installations and ensure the integrity of their critical infrastructure.
The National Security Agency (NSA), CISA, FBI, DOE, and EPA issue a joint advisory warning of active AI-assisted attacks against Siemens S7 Series programmable logic controllers (PLCs). Threat actors use AI-generated exploitation scripts disguised as legitimate monitoring tools to map target environments. Attackers leverage internet scanning services to find Internet-exposed PLCs running outdated software or poorly protected. The attackers' scripts use open-source snap7.dll and python-snap7 libraries, which are legitimate industrial automation tools. The threat actors can adapt to defensive measures and rapidly leverage additional attack vectors. Researchers warn that a defender who patches a vulnerability may find the attacker's tooling already adapted before the change window closes. Asset owners are advised to prioritize inventory, patching, and deploying ICS-aware monitoring to mitigate the threat. Third-party exposure is flagged as a specific problem, and asset owners should check for potential vulnerabilities. Clear signs defenders can monitor include S7comm connections, PLC read or write activity, and scans of multiple IP addresses on TCP port 102.
The threat landscape for critical infrastructure continues to evolve, with recent warnings from the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the U.S. Department of Energy (DOE), and the U.S. Environmental Protection Agency (EPA) signaling an active AI-assisted attacks against Siemens S7 Series programmable logic controllers (PLCs). The joint advisory, which is co-signed by these five federal agencies, serves as a cautionary warning to U.S.-based Siemens PLC installations and highlights the growing threat of AI-generated exploitation scripts disguised as legitimate monitoring tools.
The advisory, which covers every S7 generation, from the S7-200 to the S7-1500 F-series safety controllers, is direct about the nature of the threat. According to the advisory, threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations, using AI-generated exploitation scripts to map the target environment. The attackers leverage internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected.
The key detail in this threat is how the attackers try to hide their activity. They make their scripts look like legitimate OT monitoring software, making it harder for security teams to notice them while they map the target environment. The tools themselves are not custom malware. The attackers use the open-source snap7.dll and python-snap7 libraries, which are legitimate industrial automation tools. These libraries can communicate directly with Siemens PLCs over S7comm on TCP port 102, allowing access to PLC memory, configuration data, and ladder logic programs.
The advisory highlights the evolution in threat actor capabilities, which dramatically reduces the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. The threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information. If PLCs are exposed to the Internet, they are at high risk for exploitation.
Researchers warn that a defender who patches a vulnerability may now find the attacker's tooling already adapted before the change window closes. The observed activity breaks into two phases. Actors use scanning services like Censys and ZoomEye to locate Internet-exposed PLCs, then run read operations to understand the target environment before any writes happen. The authoring agencies assess this as pre-positioning: the actors are building a map and testing their techniques against specific CPU models, refining as they go, before they're ready to cause disruption.
The target list covers Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. The Defense Industrial Base is also named, given its use of S7-series hardware. If these actors move from read to write, the potential consequences include process disruption, equipment damage, and safety incidents through manipulation of interlocks or emergency shutdown systems, and cascading effects across interconnected supply chains.
The advisory flags third-party exposure as a specific problem. Asset owners who rely on system integrators or managed service providers for remote PLC access may not know their controllers are reachable from the Internet. If an external support partner holds credentials for your S7 devices and you haven’t recently verified that those connections are segmented and monitored, this advisory is a good prompt to check.
There are several clear signs defenders can monitor. They should look for S7comm connections from devices that are not normally used for engineering, PLC read or write activity outside scheduled maintenance, and scans of multiple IP addresses on TCP port 102. It is also worth checking for Python processes loading snap7.dll on systems where it should not be present. Connections from unexpected countries or locations should also raise an alert.
On the mitigation side, the agencies prioritize inventory first, then patching with Internet-facing controllers at the top of the queue. Block TCP port 102 at the perimeter firewall, require password protection on all controllers, configure protection levels to limit what an unauthenticated or low-privilege session can read or write, and deploy ICS-aware monitoring capable of baselining legitimate S7comm behavior. Disabling the PLC web server where it’s not needed and limiting simultaneous S7comm sessions also appear in the guidance, alongside TIA Portal’s know-how protection and complete restart protection features.
The advisory closes by recommending direct engagement with Siemens ProductCERT for model-specific hardening and patch compatibility verification, which matters in OT environments where a firmware update can interact badly with third-party integrations and can’t simply be rolled back.
In conclusion, the joint advisory from the NSA, CISA, FBI, DOE, and EPA serves as a clear warning to U.S.-based Siemens PLC installations about the growing threat of AI-assisted attacks. The threat actors are using AI-generated exploitation scripts disguised as legitimate monitoring tools, making it harder for security teams to notice them while they map the target environment. The agencies provide guidance on how to mitigate this threat, including prioritizing inventory, patching, and deploying ICS-aware monitoring. Asset owners must take immediate action to secure their PLC installations and ensure the integrity of their critical infrastructure.
Related Information:
https://www.ethicalhackingnews.com/articles/NSA-CISA-and-Federal-Agencies-Issue-Joint-Advisory-on-AI-Assisted-Attacks-on-Siemens-S7-PLCs-ehn.shtml
https://securityaffairs.com/197566/ics-scada/nsa-cisa-fbi-doe-and-epa-warn-of-active-ai-assisted-attacks-on-siemens-s7-plcs.html
Published: Thu Aug 20 15:38:18 2026 by llama3.2 3B Q4_K_M