The NSA, CISA, FBI, Department of Energy and Environmental Protection Agency issued a joint advisory Wednesday warning that attackers are using AI to write exploitation scripts against Siemens S7 industrial controllers, the devices that run pumps, valves and motors at water treatment plants, power facilities and chemical sites. The advisory describes an “active threat” and says the tools are still in use.
The scripts are Python programs built on the snap7.dll and python-snap7 libraries, which let software talk to Siemens S7 hardware over its native S7comm protocol. Disguised as ordinary operational-technology monitoring tools, they can read and write PLC memory, configuration data and the ladder-logic programs that define how a facility’s equipment actually behaves. Attackers find exposed devices using commercial internet-scanning services, including Censys and ZoomEye, then exploit known vulnerabilities, outdated software and weak authentication to get in. The agencies assess the activity as reconnaissance: attackers positioning themselves for disruption, equipment damage, extended downtime or safety incidents, not yet causing them.
“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the advisory states. The targeted models span five hardware generations, S7-200 through S7-1500, and the affected sectors reach beyond water into critical manufacturing, energy, chemical, food and agriculture, commercial facilities, and the defense industrial base, which also runs Siemens S7 equipment.
Wednesday’s advisory does not attribute the AI-script activity to a specific actor. It follows a separate warning the same five agencies updated on July 22, tracking a campaign against Rockwell, Schneider Electric and Siemens controllers that they have formally linked to Iran. Four days after that update, more than 30 community water systems across Minnesota were hit in a coordinated attack, forcing several to switch pump and treatment controls to manual operation. No formal attribution has been made for the Minnesota incident specifically, though the security firm Tenable has said the pattern is consistent with CyberAv3ngers, a group tied to Iran’s Revolutionary Guard Corps that has targeted Rockwell and Siemens equipment before.
Michael Garcia, a former CISA official now at Monument Policy Advocacy, called Wednesday’s advisory a first: the first time he has seen the agency say directly that an actor is using AI-generated scripts against operational technology. Brian Proctor, chief executive of the OT security firm Frenos, said the underlying exposure is not specific to one vendor: “Siemens S7 is the subject here, but the exposure pattern is not brand specific.”
The recommended fixes are unglamorous and have been recommended before: inventory every Siemens S7 device on the network, apply security patches, take controllers off the public internet, tighten access controls, and watch for unusual activity. The vulnerabilities involved are largely known ones. What AI changes, on the agencies’ own account, is how much technical skill and time an attacker needs to turn a known vulnerability into working code.
Other recent incidents point the same direction. A North Korean group ran open-weight models on its own attack infrastructure earlier this month, and researchers found that splitting a malicious instruction in two roughly doubled how often coding agents carried it out. Reaching an industrial controller used to take real expertise. The agencies are now saying, in writing, that it does not anymore.
Sources: BleepingComputer, The Register, Nextgov/FCW
–
By the Control Plane Editorial Team