U.S. authorities on Wednesday warned of an AI-fueled campaign that attempts to exploit vulnerable Siemens S7 devices across multiple industries, including energy, water, critical manufacturing, agriculture and, potentially, the defense industry.
The FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency said in an advisory that hackers are conducting reconnaissance and gathering other information about Internet-exposed S7 programmable logic controllers.
Many of the targeted devices run out-of-service software or are otherwise vulnerable to attack. As part of the campaign, attackers are using AI-generated exploitation scripts disguised as legitimate monitoring software. They employ AI to generate code to gain initial access, pilfer credentials, and execute denial-of-service and other nefarious actions.
Depending on the specific circumstances, exploitation of these tools could lead to the “disruption of critical industrial processes, safety incidents, downtime or equipment damage,” among other impacts, according to the advisory.
The hackers are targeting variants of Siemens S7-200, S7-200, S7-400, S7-1200 and S7-1500 Series PLC models.
Recent Iran-linked cyber activity
The advisory follows a wave of recent cyber threat activity linked to Iran-nexus actors against drinking and wastewater facilities. Authorities in July warned about exploitation of vulnerable PLCs from Rockwell Automation, Schneider Electric and Siemens S7-1200 devices.
U.S. authorities suspect that Iran-nexus threat actors are behind a wave of cyberattacks against water systems across at least 12 states. Operators at those sites were cut off from their monitoring equipment and locked out of their own password-protected systems.
It is not immediately clear whether the latest PLC attacks came from the same Iran-backed threat groups or if other hackers have begun targeting PLCs as well.
Security teams should ensure their current firmware versions are updated to the latest versions and apply security patches as well as check for known vulnerabilities, enable multifactor authentication and confirm that PLCs are not accessible from the internet, according to the advisory.
Officials also advised security teams to read prior guidance related to mitigating threats to operational technology.
A spokesperson for Siemens was not immediately available for comment.