Collection

US agencies warn hackers are using AI-generated scripts to target Siemens PLCs

3 sources
Post cover image

Questions this post answers

How are attackers using AI to target Siemens S7 PLCs?

Attackers use AI coding assistants to help write Python scripts, built with the snap7.dll and python-snap7 libraries, that communicate with Siemens S7 PLCs over the S7comm protocol. These scripts are disguised as legitimate OT monitoring software, making them harder to detect, and can read and write PLC memory, configuration settings, and ladder logic once connected. Security teams tracking OT threats can follow evolving AI-assisted attack techniques on daily.dev.

Which Siemens PLC models are affected by the S7comm-based attack campaign?

The campaign targets the entire S7 lineup, including S7-200, S7-300, S7-400, S7-1200, and S7-1500 models. Attackers first locate exposed devices using internet scanning tools like Censys and ZoomEye before deploying scripts to interact with them over the S7comm protocol. Infrastructure defenders monitoring PLC exposure risks can stay current on advisories via daily.dev.

Who is suspected of being behind the attacks on Siemens PLCs and water systems?

Iranian-affiliated threat actors are suspected in related attacks on water systems across at least 12 US states, including one incident that disrupted operations in Minnesota. Five federal agencies, including the NSA, CISA, and FBI, frame the broader Siemens PLC targeting as reconnaissance likely preparing for future disruption, data theft, or physical equipment damage. Those tracking nation-state threats to critical infrastructure can follow developments on daily.dev.

112 Impressions