by

US agencies warn over Siemens attacks

US agencies have warned that hackers are snuffling Siemens PLCs and cooking up attacks on critical infrastructure.

The NSA, CISA, FBI, EPA and DOE issued a joint cybersecurity advisory aimed at critical infrastructure organisations using Siemens programmable logic controllers.

According to the agencies, the hackers are scanning the internet for exposed PLCs and building exploits that could disrupt industrial processes.

They warned that attacks could damage equipment, trigger worker safety incidents, expose sensitive data, and spill over into supply chains, linked facilities, and business operations. The unnamed threat actors have targeted energy, critical manufacturing, water and wastewater, food and agriculture, chemical and commercial facilities.

The kit in the firing line includes the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series.

For most of those devices, the warning applies regardless of the CPU variant, which gives defenders a fairly broad headache. The agencies said the attackers are using AI to create exploitation scripts for initial access, credential theft, DoS attacks and other mischief.

The attackers can exploit known vulnerabilities in the targeted PLCs, rather than needing anything especially exotic. Open-source industrial automation libraries such as snap7.dll and python-snap7 are being mixed with AI-made scripts.

The result is malicious tooling that mimics legitimate OT monitoring software while poking at Siemens PLCs. These tools let attackers tamper with PLC memory, configuration data and ladder logic programs, which is grim news for anyone running industrial systems.

The advisory said:

“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools. In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

The advisory says this is an active threat rather than some theoretical PowerPoint nightmare.

However, it does not mention any high-impact attacks that have already been spotted in the wild. The agencies believe the threat actors are conducting “persistent reconnaissance” ahead of future attacks that could be disruptive or destructive.

The advisory tells organisations that use Siemens and other PLCs to install the latest patches and keep controllers off the internet unless necessary.

It urges strong access controls and recommends security products that can monitor ICS environments for malicious activity.

The warning follows a string of Iran-linked attacks aimed at the US water sector. At least 12 US states have seen attacks on OT systems, although there are no confirmed cases of water supply disruption.

CISA has urged the water and wastewater sector to protect OT systems, especially PLCs. Around the same period, the US government warned that Iranian hackers were targeting PLCs from Siemens, Schneider Electric and Rockwell Automation.

 

TOPICS:
cisa  ·  critical infrastructure  ·  cybersecurity  ·  FBI  ·  industrial control systems  ·  NSA  ·  OT security  ·  PLCs  ·  Siemens

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews