U.S. cybersecurity agencies are warning that threat actors are using AI-generated Python scripts to target Siemens S7 programmable logic controllers (PLCs) used in critical infrastructure across the United States.
PLCs are industrial computers that automate and control machinery, production lines, and physical processes in factories, utilities, and other critical infrastructure environments.
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), FBI, Department of Energy, and Environmental Protection Agency issued a joint advisory on Wednesday, warning that the activity is ongoing.
“This advisory is related to current threats to Siemens S7 Series Programmable Logic Controllers (PLCs).” Read the advisory.
“However, ongoing PLC targeting activity is broader than Siemens PLC. All PLC owners and operators should apply relevant mitigation measures to reduce risks to their devices and systems.”
The critical infrastructure sectors most at risk include critical manufacturing, energy, water and wastewater, chemical production, food and agriculture, and commercial facilities. Siemens S7 PLCs are also deployed across the defense industrial base, which could make those systems potential targets.
According to the advisory, attackers are using internet scanning services such as Censys and ZoomEye to identify exposed Siemens PLCs. They are then targeting critical and high-severity vulnerabilities, outdated software, and weak authentication controls.
Cybersecurity agencies said threat actors are using artificial intelligence to develop Python-based exploit scripts that rely on the snap7.dll and python-snap7 libraries to communicate with Siemens S7 PLC devices.
The custom tools are designed to resemble legitimate operational technology (OT) monitoring software. They can potentially provide attackers with read and write access to PLC memory, configuration information, and ladder logic programs through the S7comm protocol.
The activity currently appears focused on continuous reconnaissance. However, the agencies warn that this access could allow attackers to steal sensitive information, damage equipment, extend operational outages, trigger safety incidents, and disrupt critical infrastructure operations.
The Siemens PLC models being actively targeted include the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series.
Organizations operating Siemens S7 PLCs should maintain an up-to-date asset inventory, install the latest security updates, remove direct internet exposure, enforce strong access controls, and monitor for unusual activity targeting industrial control systems.
The advisory follows a recent increase in attacks against internet-exposed PLCs supporting critical infrastructure organizations in the United States.
In July, hackers targeted more than 30 water utilities in Minnesota, causing equipment failures and forcing some facilities to temporarily switch to manual operations.
CISA has also warned that attacks against internet-exposed PLCs used by water and wastewater utilities are increasing.
In early April, the U.S. government warned that Iranian-linked hackers were targeting internet-exposed Rockwell Automation and Allen-Bradley PLCs. The attacks caused disruption and economic damage across multiple critical infrastructure sectors.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




