Hackers are targeting critical infrastructure facilities, including water, food, energy, chemical, manufacturing, and commercial facilities, by exploiting Siemens S7 Series programmable logic controllers (PLCs) and utilizing artificial intelligence in their attacks, according to a warning issued by US government agencies.
Active Threats to Critical Infrastructure
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Energy Department, and Environmental Protection Agency (EPA) have issued a joint alert regarding the active threats posed by these AI-powered attacks. The agencies emphasize that these attacks are not theoretical, but rather an active threat that could disrupt critical industrial processes, cause safety incidents, or lead to the compromise of sensitive data.
Use of AI-Generated Exploitation Scripts
The alert highlights the use of AI-generated exploitation scripts in these attacks, which represents an evolution in threat actor capabilities. According to the alert,
Using AI to generate exploitation scripts dramatically reduces the technical expertise and time required to develop working ICS exploitation scripts and malicious tools.Additionally, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures.
A former top CISA official, Michael Garcia, noted that this is the first time the agency has mentioned the use of AI scripts to target operational technology (OT) systems in one of its cybersecurity advisories (CSAs). Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, stated on LinkedIn that
It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems.
Recommendations and Concerns
The advisory does not recommend using AI in response to these attacks, instead focusing on traditional defensive measures. However, Frenos, an OT penetration testing company, expressed concerns about the method by which the attackers could use this approach beyond Siemens-made PLCs. Brian Proctor, CEO of Frenos, stated that
Siemens S7 is the subject here, but the exposure pattern is not brand specific.He added that an adversary who has mapped the data blocks understands the process and can identify what an operator would fail to notice.
Siemens has stated that it is aware of the alert and is coordinating closely with CISA. The company noted that the advisory does not describe new vulnerabilities within the S7 Series PLCs, but rather reflects threat actors employing new techniques to exploit potential misconfigurations. Siemens has issued a security bulletin and will provide updates to potentially affected customers through its ProductCERT team.
Conclusion
The US government agencies' warning highlights the increasing threat posed by AI-powered attacks on critical infrastructure. The use of AI-generated exploitation scripts represents a significant evolution in threat actor capabilities, and it is essential for organizations to take traditional defensive measures to protect themselves against these active threats.
The alert serves as a reminder of the importance of cybersecurity in protecting critical infrastructure and the need for continued vigilance and cooperation between government agencies, private companies, and individuals to prevent and respond to these threats.
As the threat landscape continues to evolve, it is crucial for organizations to stay informed and adapt their cybersecurity strategies to address the emerging threats and protect their critical infrastructure.
Source: CyberScoop