‘We Are Crossing a Threshold’ Warns Critical Infrastructure Security Expert
An artificial intelligence-assisted cyberattack campaign is targeting widely used online operational technology devices made by Siemens, the U.S. cyber defense agency warned Wednesday – the first time it’s called out an AI-assisted cyber campaign against OT.
See Also: Rise of Malicious AI Skills Expands Enterprise Risk
“Threat actors are conducting reconnaissance and capability development against U.S.-based Siemens PLC installations using AI-generated exploitation scripts disguised as legitimate monitoring tools,” reads the advisory, published Wednesday by the Cybersecurity and Infrastructure Security Agency, the NSA, the FBI and other agencies.
The advisory described the activity as “persistent reconnaissance in targeted … facilities to develop capabilities and prepare to cause operational effects” – pre-positioning, in other words, when hackers obtain the persistent access they need to map the enemy’s networks, and figure out how to hurt them, and hard.
Threat actors are “testing and refining their exploitation techniques against specific PLC models to improve their ability,” the advisory warns, referring to programmable logic controllers.
“This is not a theoretical risk – it is an active threat,” the advisory stated, adding that attackers were employing “internet scanning services to find internet-exposed PLCs running outdated software or that are otherwise poorly protected.”
PLCs are computerized devices used in industrial plants to automate mechanical or electrical processes. A PLC controls physical actuators like motors and valves to run factory machinery, water treatment plants, or commercial building systems.
Successful compromise of PLCs “could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations and cascading impacts across interconnected systems,” the advisory states.
A spokesperson for Siemens did not respond to a request for comment.
“We are crossing a threshold,” said Operational Technology Cybersecurity Coalition Executive Director Tatyana Bolton.
The attacks were not sophisticated or autonomous, and didn’t apply the kind of cutting edge agentic tools like those involved in the recent Hugging Face breach, she told ISMG. But even basic AI tools would allow attackers to scale across the skills gap that has historically protected OT.
“We can’t depend any longer on the fact that OT is obscure,” she said. “AI has ended that.”
Specialized large language models like Mythos and Fable have proven very effective at both finding vulnerabilities in the first place, and – as in this case – scripting exploits to weaponize them.
The advisory said the threat actor uses AI to “generate exploitation scripts using publicly available information” like published vulnerabilities. This is a step change in attacker potential, the advisory said. “Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working [industrial control system, or] ICS exploitation scripts and malicious tools.”
The threat actors combined AI-assisted scripting with open-source industrial automation libraries to create custom tools that mimicked legitimate OT monitoring solutions, the advisory said.
The targets included organizations in the “critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities” sectors.
The campaign comes amid an ongoing federal investigation into a wave of cyberattacks that struck dozens of rural and small town water and wastewater utilities in at least 12 states across the nation, at the end of July. These attacks are widely believed to have been mounted by Iran, as the U.S.-Israeli launched conflict there rolled into its sixth month, with no end in sight (see: A Baffling Case of Inept Iranian Strikes on Water Utilities).
The water attacks, which have been going on for months, also targeted PLCs, including one particular S7 series model, along with others made by Rockwell Automation and Schneider Electric.
It is not clear whether or not the same actor might be behind both campaigns, and CISA media relations did not immediately respond to a request for comment. The NSA’s press office declined to comment immediately.
Bolton said the finger of suspicion pointed at Iran. “I think it would be naive to assume that [this latest wave of attacks is] separate,” she said. “It comes too close in time, and is too similar of an attack.”
Nonetheless, she noted that “there’s no reporting on the attribution, and that’s notoriously difficult.” At this early stage, she said, “you never really know.”
Click Here For The Original Source.
