NSA, CISA, FBI, DOE, and EPA warn of an active threat targeting Internet-exposed Siemens S7 Series PLCs with AI-generated exploitation scripts, insecure credentials, and Snap7-based tooling disguised as legitimate monitoring software. The advisory urges immediate hardening, patching, segmentation, and monitoring to protect critical infrastructure sectors and prevent disruption, safety incidents, and equipment damage. #SiemensS7 #Snap7 #CISA #NSA #FBI
Keypoints
- Multiple U.S. agencies released an advisory about an active threat to Siemens S7 Series PLCs.
- Threat actors are using AI-generated exploitation scripts and public information to target exposed or poorly protected PLCs.
- The activity focuses on Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 series controllers.
- Actors use internet scanning, insecure/default credentials, and Snap7-based Python tooling to gain read/write access through S7comm.
- The campaign is aimed at reconnaissance and capability development, with possible future operational disruption against critical infrastructure.
- Affected sectors include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
- The advisory recommends inventory, patching, network isolation, stronger access controls, logging, and S7-specific hardening measures.
MITRE Techniques
- [T1596.005] Search Open Technical Databases: Scan Databases – Used internet scanning services to identify exposed or poorly segmented Siemens S7 PLCs (‘Using Internet scanning services to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs’).
- [T1587.004] Develop Capabilities: Exploits – Threat actors developed exploits for known Siemens S7 vulnerabilities (‘Developing exploits for known Siemens S7 Series PLC vulnerabilities’).
- [T1588.007] Obtain Capabilities: Artificial Intelligence – AI was used to rapidly iterate and refine exploitation code (‘Rapidly iterating exploit code through AI-assisted development’).
- [T0834] Native API – AI-generated Python scripts incorporated the snap7.dll library to interact with PLCs (‘Deploying AI-generated Python scripts incorporating the snap7.dll library’).
- [T0821] Modify Controller Tasking – Write operations were performed on data blocks, likely for pre-positioning or effects (‘Conducting write operations on data blocks, potentially for pre-positioning for effects operations’).
- [T0849] Masquerading – Malicious scripts were disguised as legitimate monitoring tools to avoid detection (‘Masquerading as legitimate monitoring tools to evade detection’).
- [T1694] Insecure Credentials – Exposed devices were accessed using default or weak authentication (‘Accessing exposed devices that have unconfigured (default) or minimally configured authentication’).
- [T0893] Data from Local System – Read operations on data blocks were used for reconnaissance (‘Conducting read operations on data blocks, potentially for reconnaissance’).
Indicators of Compromise
- [IP/Network Port ] reconnaissance and exposure checks – TCP port 102, sequential IP scanning patterns
- [Tool/Library ] suspicious PLC interaction tooling – snap7.dll, python-snap7
- [Software/Protocol ] OT communications and access – S7comm, TIA Portal, STEP 7
- [File/Script ] AI-generated tooling used for PLC access – Python scripts, legitimate monitoring tool lookalikes
- [Organization/Service Names ] referenced tools and entities in the advisory – Censys, ZoomEye, Claroty, Dragos Platform, Nozomi Networks
Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a