The National Security Agency (NSA) and Federal Bureau of Investigation (FBI) have issued a warning about an active threat targeting critical infrastructure organizations using AI-generated exploit scripts. This threat is considered an evolution in capabilities, as it dramatically reduces the technical expertise and time required to develop working exploitation scripts and malicious tools.
AI-Generated Exploitation Scripts
The hackers behind the campaign are using artificial intelligence to generate exploitation scripts that give them access to credentials and other pathways for damage. These scripts are disguised as legitimate monitoring tools, making them difficult to detect. The use of AI to generate exploitation scripts has reduced the barrier to entry for attackers, allowing those with limited technical expertise to develop working scripts.
Targeting Critical Infrastructure
The campaign is targeting Siemens S7 Series PLCs, which are used in the energy, water, and agricultural industries to control pumps and monitor processes. The hackers are using internet scanning platforms to find PLCs exposed to the internet, and then using AI-generated scripts to exploit known vulnerabilities. This could lead to disruption of critical industrial processes, safety incidents, downtime, or equipment damage.
The advisory notes that the attacks are likely intended as persistent reconnaissance in targeted sectors and facilities to develop capabilities and prepare to cause operational effects against critical infrastructure. The use of AI-generated scripts has made it easier for attackers to adapt quickly to defensive measures, and to create custom tools designed to look like legitimate operational technology monitoring solutions.
Recommendations for Organizations
Organizations are urged to treat the advisory with urgency and initiate response efforts centered around programmable logic controllers (PLCs). This includes isolating PLCs from the internet, installing all patches, and enabling security tooling to monitor threat activity. It is also important for organizations to plan for what happens when they lose control of a PLC, as this could lead to a loss of view, loss of control, and a physical process running in a state that nobody in the control room can see.
According to industrial technology expert Brian Proctor, the introduction of AI has compressed the distance between a published vulnerability and a working script in the hands of someone who previously could not have written it themselves. He notes that the activity described in the advisory is the first half of an effects operation, and the second half is cheap once the first half is done.
Previous Incidents
In July, federal agencies warned that Iran-affiliated hackers were targeting PLCs made by several different companies, including Siemens, Schneider Electric, Rockwell Automation, and Allen-Bradley. The advisory notes that the Siemens-specific content should be understood and applied as one subset of the wider threat landscape.
Government officials were alarmed two weeks ago when dozens of water utilities across at least 12 states reported cyber intrusions allegedly involving Iranian actors targeting PLCs. The advisory appears to expand the campaign beyond water and wastewater facilities, highlighting the need for organizations to be vigilant and proactive in protecting their critical infrastructure.
- Isolate PLCs from the internet
- Install all patches
- Enable security tooling to monitor threat activity
- Plan for what happens when you lose control of a PLC
By following these recommendations, organizations can help protect themselves against the active threat targeting critical infrastructure organizations using AI-generated exploit scripts.
Source: The Record