Several U.S. federal agencies have issued a joint alert on August 19, highlighting active cyber threats against Siemens S7 Series programmable logic controllers (PLCs) within critical infrastructure sectors. This warning underscores the urgent need for enhanced cybersecurity measures across the nation.
Active Threats to Siemens PLCs
The advisory from the NSA, CISA, FBI, Department of Energy, and EPA describes the cyber risk as ongoing and significant. Hackers are reportedly using AI-generated scripts that mimic legitimate monitoring tools to infiltrate devices exposed to the Internet.
Attackers are leveraging Internet scanning platforms like Censys and ZoomEye to identify Siemens S7 PLCs that are either publicly accessible or poorly isolated from corporate networks. Post identification, they employ AI-assisted techniques to quickly create and modify exploitation code, making it easier to breach these industrial systems.
Methods and Tools Used in Attacks
The hacking tools utilize open-source automation libraries such as snap7.dll and python-snap7, enabling unauthorized read and write operations on PLC memory and configuration data via the S7comm protocol. These activities are disguised as normal monitoring operations, reducing the chances of detection.
All major Siemens S7 lines, including S7-200, S7-300, S7-400, S7-1200, and S7-1500, are at risk, along with the F-series safety controllers. Hackers are exploiting devices with default or weak credentials, facilitating easy access where security practices are lax.
Implications and Recommended Actions
Current activities suggest persistent reconnaissance and the development of exploit capabilities, rather than immediate sabotage. Hackers seem to be preparing for potential future attacks that could disrupt industrial operations.
Key sectors affected include Critical Manufacturing, Energy, Water and Wastewater, and more, with the Defense Industrial Base also identified as a possible target. Recent cyber incidents in U.S. water utilities highlight the ongoing threat to operational technology systems.
Potential impacts include disrupted processes, safety incidents, equipment damage, and extended downtimes. In response, agencies urge operators to conduct comprehensive inventories of their S7 devices, update firmware, and strengthen network security measures.
Specific actions include blocking TCP port 102, ensuring no PLC is directly internet-accessible, and tightening access controls. Continuous monitoring for anomalous traffic and unauthorized activities is also critical.
Organizations are encouraged to report any suspicious activity to CISA or the FBI’s Internet Crime Complaint Center. Adherence to these guidelines is crucial to safeguarding critical infrastructure from cyber threats.
