U.S. government agencies are warning that threat actors are actively using artificial intelligence to generate scripts that exploit vulnerabilities in Siemens S7 Series programmable logic controllers, or PLCs, used across American critical infrastructure. The joint advisory, issued Wednesday by the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, the Department of Energy, and the Environmental Protection Agency, describes an ongoing threat to these industrial computers, which automate and control machinery in factories and other facilities. The warning states that while the advisory is specific to Siemens S7 devices, the broader targeting activity extends to all PLC owners and operators, who should apply mitigations to protect their systems.

The agencies identified the most targeted critical infrastructure sectors as Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. They also noted that Siemens S7 PLCs are used in the Defense Industrial Base, which could also be a target. Actors are reportedly using internet scanning services such as Censys and ZoomEye to locate exposed PLCs and then exploit critical and high-severity vulnerabilities, outdated software, and weak authentication.

The advisory details that attackers are leveraging artificial intelligence to create Python exploitation scripts that use the snap7.dll and python-snap7 libraries to communicate with Siemens S7 devices. These custom tools, which are disguised as legitimate operational technology monitoring software, can provide read and write access to PLC memory, configuration data, and ladder logic programs over the S7comm protocol. The agency analysis suggests the activity is focused on persistent reconnaissance, potentially setting the stage for disruptions to critical infrastructure, which could include data theft, equipment damage, extended downtime, or safety incidents.

The specifically targeted devices include the Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 models. The agencies urge organizations to inventory their Siemens S7 PLCs, install the latest security updates, block internet access to the devices, strengthen access controls, and monitor for unusual activity. This advisory follows a recent uptick in attacks on exposed PLCs at U.S. critical infrastructure organizations.

In July, hackers targeted more than 30 Minnesota water utilities, causing equipment malfunctions and forcing some facilities to temporarily switch to manual operations. CISA subsequently issued a warning about an increase in attacks against internet-exposed PLCs used by water and wastewater utilities. Earlier in April, U.S. agencies also warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation and Allen-Bradley PLCs, causing disruptions and financial losses across multiple critical infrastructure sectors.