WASHINGTON—The National Security Agency, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Department of Energy, and Environmental Protection Agency released joint Cybersecurity Advisory AA26-231A on August 19, warning of an active cyber threat to Siemens S7 Series programmable logic controllers (PLCs).
The authoring agencies state that threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations. Actors use Internet scanning services to locate Internet-exposed or poorly protected devices running outdated software.
They employ artificial intelligence (AI)-generated exploitation scripts that incorporate the open-source snap7.dll/python-snap7 library and masquerade as legitimate monitoring tools.
These scripts provide read/write access to PLC memory, configuration data, and ladder logic via the S7comm protocol on TCP port 102.
Targeted models include all CPU variants of the S7-200 Series, S7-300 Series (including 314, 315, and 317 models), S7-400 Series, S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, and 1217C), and S7-1500 Series (including F-series safety controllers).
The agencies assess the activity is intended as persistent reconnaissance to develop capabilities and prepare for potential operational effects.










