US Warns of AI-Powered Attacks on Siemens PLCs

Photo: BleepingComputer
Quick answer
US cybersecurity agencies have detected AI-powered attacks on Siemens S7 industrial controllers, exploiting vulnerabilities with AI-generated scripts.
US cybersecurity agencies, including NSA, CISA, and the FBI, have issued a joint warning about targeted attacks on Siemens S7 programmable logic controllers (PLCs), which are widely used in critical infrastructure. Attackers are leveraging artificial intelligence to create specialized scripts that exploit vulnerabilities in these devices.
The attacks impact several key sectors, including energy, water supply, chemical industries, and manufacturing. Siemens S7 controllers are also used in defense industries, making them a potential target for cybercriminals. Internet scanning services like Censys and ZoomEye are being used to identify vulnerable devices.
Cybercriminals are developing Python scripts using libraries such as snap7.dll and python-snap7, which enable interaction with PLCs via the S7comm protocol. These tools are disguised as legitimate industrial monitoring software and provide access to device memory, configurations, and operational logic. The primary goal of these attacks is reconnaissance and preparation for potential infrastructure disruptions.
Experts recommend that organizations conduct an inventory of all Siemens S7 controllers, apply the latest security updates, restrict internet access to devices, and enhance authentication controls. Special attention should be given to monitoring unusual activity that may indicate attempted breaches.
The warning follows a series of attacks on US critical infrastructure. In July, hackers disrupted operations at over 30 water treatment facilities in Minnesota, forcing a shift to manual control. Earlier, CISA reported an increase in attacks on PLCs in water supply systems, and in April, US agencies warned of Iranian-linked hackers targeting Rockwell Automation controllers.
Common questions
- Which Siemens devices are under attack?
- The targeted devices include Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers. These are widely used in industrial and critical infrastructure sectors.
- How are attackers using AI in these cyberattacks?
- Cybercriminals are using AI to generate Python scripts that interact with PLCs via the snap7 library. These tools are disguised as legitimate monitoring software and allow access to device memory and configurations.
- What protective measures are recommended?
- Organizations should update controller firmware, restrict internet access to devices, strengthen authentication, and monitor for unusual activity. Conducting an inventory of all Siemens S7 devices is also advised.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml