AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure

AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. (TL-2026-2076), also tracked as AA26-231A Campaign, is a critical-severity ICS/SCADA threat, first published 2026-08-19 and last reviewed 2026-08-20. It has no confirmed attribution, affects Siemens SIMATIC S7-200, references 11 CVEs (CVE-2026-51218, CVE-2026-15105, CVE-2020-15782), maps to 46 MITRE ATT&CK techniques (T0812, T0813, T0819), and is covered by 9 detection rules and 43 indicators of compromise.

Key facts for TL-2026-2076

Threat ID
TL-2026-2076
Also known as
AA26-231A Campaign, AA26-097A Siemens Nexus
Severity
CRITICAL
Status
ACTIVE
Category
ICS_SCADA
First published
2026-08-19
Last reviewed
2026-08-20
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
critical manufacturing, energy, water and wastewater, chemical, food and agriculture, commercial facilities, defense industrial base
Target regions
united states of america
Detection rules
9
Indicators of compromise
43
Updates
2026-08-20 · 3 updates · revalidated 3× · latest source

Malware and tooling in AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

Malware and tooling: IOCONTROL

NSA, CISA, FBI, DOE, and EPA jointly issued advisory AA26-231A on August 19, 2026 warning of active, ongoing attacks targeting Siemens S7 Series PLCs (S7-200 through S7-1500) in U.S. critical infrastructure. Threat actors are using AI-generated Python exploitation scripts leveraging the open-source snap7/python-snap7 libraries over the S7comm protocol to conduct persistent reconnaissance, read/write PLC memory and ladder logic, and preposition for potential disruptive attacks across the manufacturing, energy, water, chemical, food/agriculture, and commercial facilities sectors.

How AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. works

On August 19, 2026, five U.S. federal agencies — the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA) — jointly issued cybersecurity advisory AA26-231A warning of an active, ongoing cyber threat to Siemens S7 Series programmable logic controllers (PLCs) deployed across U.S. critical infrastructure sectors.

The advisory describes a rapidly evolving threat in which adversaries are using artificial intelligence to generate Python-based exploitation scripts employing the open-source snap7.dll and python-snap7 libraries. These libraries implement the Siemens S7comm protocol (used over TCP port 102 via ISO-on-TPC/RFC 1006), which by design lacks native authentication or encryption. The AI-generated scripts are disguised as legitimate OT monitoring software and provide both read and write access to PLC memory, configuration data, and ladder logic programs.

Attackers begin by using internet scanning services — specifically Censys and ZoomEye — to identify Internet-exposed Siemens PLCs. Once discovered, they exploit a combination of critical and high-severity known vulnerabilities, outdated firmware, and weak or default authentication credentials to gain access. The AI-generated tooling dramatically reduces the technical expertise and time required to develop working ICS exploit code, lowering the barrier for adversaries to target operational technology environments.

While the advisory focuses on Siemens S7 PLCs, it explicitly warns that 'ongoing PLC targeting activity is broader than Siemens PLCs' and that all PLC owners and operators should apply mitigations. Broader context links this activity to Iranian IRGC-affiliated cyber actors previously documented in CISA advisory AA26-097A (April 2026, updated July 22, 2026), which described Iranian-linked actors — including CyberAv3ngers / Shahid Kaveh Group — exploiting internet-connected PLCs from Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens (S7-1200 series added in the July 22 update). On July 26-27, 2026, a coordinated attack linked to these actors disrupted over 30 community water systems in Minnesota, forcing manual operations, causing pressure loss and flooding. The new advisory marks an escalation where AI-generated tooling is now being applied specifically to Siemens S7 exploitation at scale.

The targeted Siemens PLC families encompass all CPU variants of S7-200, S7-300, S7-400, S7-1200, and S7-1500 series. These controllers are used across at least six critical infrastructure sectors: Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, Commercial Facilities, and the Defense Industrial Base. The adversary's objectives appear focused on persistent reconnaissance, data theft, and pre-positioning for potential disruptive operations including equipment damage and safety incidents.

Key technical indicators include anomalous S7comm behavior from non-engineering workstations, sequential IP scanning on TCP port 102 (S7comm), usage of snap7.dll or python-snap7 outside approved engineering workstations, S7comm activity during off-hours, and connections from unexpected geographic regions. The snap7 library itself contains two publicly disclosed vulnerabilities — CVE-2026-51218 (heap buffer overflow in TS7Worker::PerformFunctionWrite, CVSS 7.5, automatable, PoC available) and CVE-2026-15105 (deserialization in TS7Worker::PerformFunctionRead, CVSS 6.3) — both of which can be weaponized in these AI-generated attack scripts.

Immediate mitigations include inventorying all Siemens S7 PLCs, applying critical firmware patches (including TIA Portal V17+ for per-device passwords on S7-1200/S7-1500), blocking TCP port 102 at perimeter firewalls, deploying ICS-aware intrusion detection, implementing DMZ architecture separating OT and IT networks, enabling PLC password protection and protection levels, and monitoring for anomalous S7comm activity, unauthorized PUT/GET operations, and snap7 usage outside approved engineering workstations.

MITRE ATT&CK techniques used in TL-2026-2076

Execution

T0812 Default Credential; T0859 Valid Accounts; T0865 Brute Force; T1059 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python; T1106 Native API

Impact

T0813 Denial of Control; T0830 Process Manipulation; T0831 Manipulation of View; T0858 Change Operating Mode; T0890 Data Manipulation; T1529 System Shutdown/Reboot; T1565 Data Manipulation; T1565.001 Data Manipulation: Stored Data Manipulation

Initial Access

T0819 Network Service Scanning; T0853 Data from Information Repositories; T0883 Internet Accessible Device; T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Persistence

T0822 External Remote Services

Inhibit Response Function

T0835 Program Upload; T0843 Program Download; T0855 Unauthorized Command Message

Collection

T0842 Adversary-in-the-Middle; T0893 Data from Local System; T1005 Data from Local System

Evasion

T0849 Masquerading

Discovery

T0888 Remote System Information Discovery; T1046 Network Service Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading: Match Legitimate Name or Location

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1219 Remote Access Tools

Credential Access

T1110 Brute Force; T1552 Unsecured Credentials; T1552.007 Unsecured Credentials: Default Passwords

stealth

T1574 Hijack Execution Flow

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Lateral Movement

T1694 Insecure Credentials

Affected products and versions in AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

  • Siemens — SIMATIC S7-200
    Vulnerable versions: All CPU variants
  • Siemens — SIMATIC S7-300
    Vulnerable versions: All CPU variants (314, 315, 317)
  • Siemens — SIMATIC S7-400
    Vulnerable versions: All CPU variants
  • Siemens — SIMATIC S7-1200
    Vulnerable versions: All CPU variants (1211C, 1212C, 1214C, 1215C, 1217C) with firmware below V4.5.0
    Fixed in: Firmware V4.5.0+ (TIA Portal V17+)
  • Siemens — SIMATIC S7-1500
    Vulnerable versions: All CPU variants including F-series safety controllers with firmware below V2.9.2
    Fixed in: Firmware V2.9.2+
  • Siemens — SIMATIC S7-1500 TM MFP
    Vulnerable versions: All firmware versions with unresolved BIOS-level CVEs
  • Snap7 — davenardella/snap7
    Vulnerable versions: 1.4.0; 1.4.1; 1.4.2; 1.4.3
  • python-snap7 — python-snap7
    Vulnerable versions: All versions earlier than 3.0
    Fixed in: 3.0+ (pure Python, no snap7.dll dependency)

Remediation for AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

Patches

  • Update S7-1200 firmware to V4.5.0+ to address CVE-2020-15782 and CVE-2022-38465
  • Update S7-1500 firmware to V2.9.2+ to address memory protection bypass and global private key vulnerabilities
  • Update TIA Portal to V17+ for per-device password enforcement on S7-1200/S7-1500
  • Apply Siemens ProductCERT bulletin SSB-104599 recommendations for all affected S7 families
  • Configure CPUs for 'Only allow secure PG/PC and HMI communication' where available

Immediate actions

  • Inventory all Siemens S7 Series PLCs across the enterprise to establish baseline
  • Block TCP port 102 (S7comm/ISO-TSAP) at perimeter firewalls immediately
  • Ensure no Siemens S7 PLCs are accessible from the Internet; remove any that are publicly exposed
  • Change all default PLC passwords and implement per-device passwords via TIA Portal V17+
  • Enable PLC password protection and set protection level to Level 3 (read/write protection)
  • Deploy ICS-aware intrusion detection (e.g., SENAMI) to monitor for anomalous S7comm traffic
  • Review logs for unauthorized snap7.dll usage or python-snap7 scripts on engineering workstations

Workarounds

  • Configure host-based firewalls on engineering workstations to restrict snap7.dll usage
  • Use application whitelisting to prevent unauthorized Python/snap7 scripts on OT workstations
  • Replace default TIA Portal certificates and generate unique per-device keys
  • Enable logging of all S7comm read/write operations for forensic visibility

Longer-term hardening

  • Implement DMZ architecture separating OT and IT networks per NIST SP 800-82 guidelines
  • Apply cell protection concepts (IEC 62443) with zone-based segmentation
  • Deploy passive OT network monitoring (SERINUS OT or equivalent) for unauthorized device detection
  • Implement ICS-SOC with 24/7 monitoring capability for OT protocol anomalies
  • Establish incident response procedures specific to PLC/ICS compromise scenarios
  • Disable unused protocols and web servers on all Siemens S7 PLCs
  • Implement VPN-only access for remote PLC engineering and maintenance
  • Monitor Censys, ZoomEye, and Shodan for external exposure of your OT asset inventory

CVEs associated with AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

CVE-2026-51218, CVE-2026-15105, CVE-2020-15782, CVE-2022-38465, CVE-2025-40943, CVE-2020-15791, CVE-2025-27127, CVE-2024-54678, CVE-2025-40759, CVE-2025-24811, CVE-2021-22681

Weaknesses (CWE) in AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

CWE-122, CWE-502, CWE-287, CWE-522, CWE-95, CWE-434, CWE-306, CWE-798, CWE-94

Timeline of AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

Showing the 20 most recent tracked events.

  • Siemens ProductCERT publishes SSB-104599 addressing increasing cyber threats to S7 Series PLCs; updated multiple times through July 2026
  • Siemens ProductCERT publishes SSA-503939 disclosing CVE-2025-24811, an unauthenticated remote DoS vulnerability in S7-1200 PLCs via malformed packets on TCP 80; no fix available.
  • Siemens ProductCERT publishes SSA-452276 disclosing CVE-2025-40943, a code injection vulnerability in S7-1500 via malicious trace files (CVSS 9.6); partial fix released for firmware V4.1.2+.
  • CyberAv3ngers/Shahid Kaveh Group (Iranian IRGC-affiliated) escalates targeting of internet-exposed Rockwell Automation/Allen-Bradley PLCs across US critical infrastructure, using manufacturer software and leased infrastructure
  • CISA, FBI, NSA, EPA, DOE, CYBERCOM, and Treasury issue AA26-097A warning of Iranian-affiliated cyber actors exploiting PLCs across US critical infrastructure, targeting Rockwell Automation, then Schneider Electric and Siemens S7-1200
  • Siemens updates SSB-104599 to reference CISA advisory AA26-097A, acknowledging Siemens S7 PLCs as potential targets in the Iranian-affiliated campaign.
  • CVE-2026-51218 published: heap buffer overflow in snap7 TS7Worker::PerformFunctionWrite() (CVSS 7.5, HIGH, network-exploitable, no auth required, PoC available, later upgraded to automatable by CISA)
  • CISA warns of an increase in attacks against internet-exposed PLCs at water/wastewater utilities as OT-targeting activity broadly intensifies.
  • CVE-2026-15105 published: deserialization vulnerability in snap7 TS7Worker::PerformFunctionRead() (CVSS 6.3 MEDIUM, adjacent network, PoC published, no vendor fix)
  • CISA AA26-097A updated to add Siemens S7-1200 series and Schneider Electric PLCs to list of targeted devices by Iranian-affiliated actors; CISA rates exploitation as automatable
  • Siemens SSB-104599 updated to V1.2, adding S7-1200 as a specifically named target based on CISA advisory updates
  • Coordinated cyberattack targets over 30 community water systems across Minnesota (Braham, Plymouth, South St. Paul, Maple Plain), compromising PLCs, forcing manual operations, causing pressure loss and flooding. FBI and CISA investigate possible Iranian nexus
  • Multiple Minnesota cities (Braham, Plymouth, South St. Paul, Maple Plain) publicly disclose the water-system cyberattacks; federal investigation launched; attribution to CyberAv3ngers assessed as likely.
  • Censys ARC snapshot identifies 4,117 internet-exposed Siemens SIMATIC S7-1200 hosts, 86% concentrated in southern and central Europe (Greece, Spain, Italy, Austria), predominantly via mobile carrier networks.
  • CISA issues urgent warning about 'significant increase in cyber threat actors targeting PLCs in the Water and Wastewater Systems sector,' urges immediate removal of publicly exposed PLCs from the Internet
  • Water-utility PLC attacks spread to at least 12 states (Michigan, Minnesota, Georgia, New Jersey, South Dakota, and others); Clayton County Water Authority (serving 300,000 customers in Georgia) issues a boil-water advisory after pressure loss from PLC manipulation.
  • CISA reports still finding water system controls exposed online with no password or default passwords set; advises immediate hardening.
  • BleepingComputer, Cybersecurity Dive, and other outlets publish detailed coverage of the AA26-231A advisory, highlighting the AI-powered attack methodology.
  • NSA, CISA, FBI, DOE, and EPA jointly issue AA26-231A warning of active AI-powered attacks targeting Siemens S7 Series PLCs (S7-200 through S7-1500) using AI-generated Python scripts leveraging snap7/python-snap7 libraries over S7comm protocol
  • Agencies confirm the campaign remains active and ongoing; no specific nation-state attribution has been confirmed for this latest wave.

Update history for TL-2026-2076

Sources cited for AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

Threats related to AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S.

Detection coverage for TL-2026-2076

As of 2026-08-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2076 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats