Unidentified cybercriminals used scripts created by artificial intelligence to launch a large-scale attack on Siemens S7 series programmable logic controllers (PLCs) connected to the Internet – which are used in water plants, manufacturing, energy and other critical facilities. Five U.S. federal agencies described the incident as an active threat.

Image credit: Philipp Katzenberger / unsplash.com
Hackers targeting U.S. critical infrastructure are using open source industrial automation libraries, including snap7.dll/python-snap7, and scripts developed by artificial intelligence coding assistants. Based on open source libraries, they created their own tools to simulate operating technical monitoring software and provide read and write access to controller memory, configuration data and other tools through the S7comm protocol.
“This is not a theoretical risk – it is an active threat.”,— warn US authorities. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) jointly issued the warning. There is no word yet on the source of the threat, but one version says it is a continuation of a cyberattack linked to Iranian hackers that occurred in July. Subsequently, water and wastewater control operators in at least 12 states were affected; in Minnesota alone, more than 30 public water systems were disrupted.
Photo credit: Adi Goldstein/unsplash.com
A new series of attacks targets Internet-facing Siemens S7 series controllers in mission-critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial enterprises. We are talking about most of the key industries that provide goods and services that ordinary citizens use in their daily lives. To hunt for vulnerable controllers, attackers use scanning services Censys and ZoomEye and use artificial intelligence to crack them.
Owners and operators of this equipment are advised to urgently inventory all Siemens S7 series controllers, install the necessary security updates and ensure that they are all inaccessible over the network. It is recommended to check for abnormal activities in the S7comm protocol, such as abnormal mechanisms for connecting, accessing and operating data from unknown workstations. The presence of the attacker can be revealed by sequentially scanning IP addresses on port 102 and repeating connection attempts with different parameters.
If you find an error, select it with your mouse and press CTRL+ENTER.
