Defending Against an Active Threat to Siemens S7 Series PLCs

Defending Against an Active Threat to Siemens S7 Series PLCs
NSA, CISA, FBI, DOE, and EPA warn of an active threat targeting Internet-exposed Siemens S7 Series PLCs with AI-generated exploitation scripts, insecure credentials, and Snap7-based tooling disguised as legitimate monitoring software. The advisory urges immediate hardening, patching, segmentation, and monitoring to protect critical infrastructure sectors and prevent disruption, safety incidents, and equipment damage. #SiemensS7 #Snap7 #CISA #NSA #FBI

Keypoints

  • Multiple U.S. agencies released an advisory about an active threat to Siemens S7 Series PLCs.
  • Threat actors are using AI-generated exploitation scripts and public information to target exposed or poorly protected PLCs.
  • The activity focuses on Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 series controllers.
  • Actors use internet scanning, insecure/default credentials, and Snap7-based Python tooling to gain read/write access through S7comm.
  • The campaign is aimed at reconnaissance and capability development, with possible future operational disruption against critical infrastructure.
  • Affected sectors include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities.
  • The advisory recommends inventory, patching, network isolation, stronger access controls, logging, and S7-specific hardening measures.

MITRE Techniques

  • [T1596.005] Search Open Technical Databases: Scan Databases – Used internet scanning services to identify exposed or poorly segmented Siemens S7 PLCs (‘Using Internet scanning services to identify Internet-exposed or poorly segmented Siemens S7 Series PLCs’).
  • [T1587.004] Develop Capabilities: Exploits – Threat actors developed exploits for known Siemens S7 vulnerabilities (‘Developing exploits for known Siemens S7 Series PLC vulnerabilities’).
  • [T1588.007] Obtain Capabilities: Artificial Intelligence – AI was used to rapidly iterate and refine exploitation code (‘Rapidly iterating exploit code through AI-assisted development’).
  • [T0834] Native API – AI-generated Python scripts incorporated the snap7.dll library to interact with PLCs (‘Deploying AI-generated Python scripts incorporating the snap7.dll library’).
  • [T0821] Modify Controller Tasking – Write operations were performed on data blocks, likely for pre-positioning or effects (‘Conducting write operations on data blocks, potentially for pre-positioning for effects operations’).
  • [T0849] Masquerading – Malicious scripts were disguised as legitimate monitoring tools to avoid detection (‘Masquerading as legitimate monitoring tools to evade detection’).
  • [T1694] Insecure Credentials – Exposed devices were accessed using default or weak authentication (‘Accessing exposed devices that have unconfigured (default) or minimally configured authentication’).
  • [T0893] Data from Local System – Read operations on data blocks were used for reconnaissance (‘Conducting read operations on data blocks, potentially for reconnaissance’).

Indicators of Compromise

  • [IP/Network Port ] reconnaissance and exposure checks – TCP port 102, sequential IP scanning patterns
  • [Tool/Library ] suspicious PLC interaction tooling – snap7.dll, python-snap7
  • [Software/Protocol ] OT communications and access – S7comm, TIA Portal, STEP 7
  • [File/Script ] AI-generated tooling used for PLC access – Python scripts, legitimate monitoring tool lookalikes
  • [Organization/Service Names ] referenced tools and entities in the advisory – Censys, ZoomEye, Claroty, Dragos Platform, Nozomi Networks


Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a