The U.S. government issued a warning Wednesday about an "active threat" targeting critical infrastructure organizations through the use of artificial intelligence-generated exploit scripts. The advisory, published jointly by the National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency, identifies attackers exploiting Siemens S7 Series Programmable Logic Controllers to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. The agencies did not link the attacks to any specific threat actor or group.

The campaign targets multiple critical infrastructure sectors, including Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. Threat actors are using internet scanning services like Censys and ZoomEye to locate internet-exposed PLCs running outdated software or otherwise poorly protected systems. The attackers have focused on specific Siemens PLC models across the S7-200, S7-300, S7-400, S7-1200, and S7-1500 series, including all CPU variants and F-series safety controllers. According to the agencies, the ongoing PLC targeting activity is assessed to be broader in scope than just Siemens PLCs. Among the tools deployed is a custom Python script incorporating open-source industrial automation libraries like "snap7.dll" or "python-snap7," which mimics legitimate monitoring utilities providing read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol.

The agencies state that "threat actors are using AI assistance to generate exploitation scripts using publicly available information" on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives. The advisory warns that if these PLCs are exposed to the internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities. The report notes the exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, with potential cascading impacts across interconnected systems. The agencies add that "the combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario" against inadequately protected PLC installations.

The use of AI to generate exploitation scripts and rapidly iterate them marks what the agencies describe as an "evolution" in offensive capabilities, lowering technical barriers to Industrial Control System attacks as well as the technical expertise and time required to develop them. This shift enables attackers to automate script generation using publicly available information, transforming what once required specialized knowledge into a process accessible to less sophisticated actors. The authoring agencies urge operational technology system owners and operators using Siemens S7 Series and other PLC devices to ensure they're running the latest versions, isolated from the internet wherever possible, have strong access controls, and employ security tooling to monitor ICS environments for signs of anomalous or malicious activity. The democratization of attack tools through generative AI may force infrastructure defenders to fundamentally rethink their assumptions about who can credibly threaten industrial systems and how quickly those threats can adapt.