The U.S. government on Wednesday warned of an “active threat” targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.
The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That said, the ongoing PLC targeting activity is assessed to be broader in scope than Siemens PLCs.
“The actors leverage internet scanning services like Censys and ZoomEye to identify internet-exposed PLCs running outdated software or that are otherwise poorly protected,” according to the advisory published by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA).
Targets of the activity include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies did not attribute the attacks to a known threat actor or group.
The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not to mention have cascading impacts across interconnected systems.
The activity has been found to have singled out the following Siemens PLC models –
- S7-200 Series (all CPU variants)
- S7-300 Series (all CPU variants including 314, 315, 317 models)
- S7-400 Series (all CPU variants)
- S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants)
- S7-1500 Series (all CPU variants, including F-series safety controllers)
“Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives,” the agencies said. “If these PLCs are exposed to the internet or insufficiently segmented, then threat actors can exploit various critical and high severity known vulnerabilities in these PLCs.”
Among the tools deployed by the threat actor is a custom Python script that incorporates open-source industrial automation libraries like “snap7.dll” or “python-snap7,” thereby mimicking legitimate monitoring utilities that provide read/write access to PLC memory, configuration data, and ladder logic programs via the S7comm protocol.
The use of AI to generate exploitation scripts and rapidly iterate them marks an “evolution” in offensive capabilities, lowering technical barriers to Industrial Control System (ICS) attacks, as well as the technical expertise and time required to develop them.
To counter the threat, the authoring agencies are urging operational technology (OT) system owners and operators using Siemens S7 Series and other PLC devices to ensure they are running the latest versions, isolated from the internet wherever possible, have strong access controls, and employ security tooling to monitor ICS environments for signs of anomalous or malicious activity.
“The combination of known vulnerabilities, accessible exploitation libraries, and AI-assisted development creates a high-probability attack scenario against inadequately protected PLC installations,” the agencies said.
Multi-Agent Autonomous Attack Targets Taiwan
The development comes as threat actors are increasingly harnessing the power of AI to carry out cyber attacks. In a report published last week, Israeli cybersecurity company Dream detailed a near-autonomous attack targeting government entities in Asia. Although the research did not disclose which government was attacked, The Financial Times and Reuters said Taiwan was the target.
“The investigation found clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw,” Taiwan’s Ministry of Digital Affairs said.
The activity, observed between July 1 and 4, 2026, across 12 attack waves and likely undertaken by a Chinese-language operator, leverages an AI-powered framework built on the Hermes and OpenClaw agents to deploy up to eight lettered sub-agents in parallel to automate various aspects of the intrusion.
This includes performing reconnaissance, cracking government employee credentials, exfiltrating data, discovering a signature validation flaw in a personal authentication service, and installing persistent backdoors on government web applications. The eight sub-agents, although run concurrently, target different attack surfaces –
- A – SSO exploitation and credential attacks
- B – JWT bypass testing and CAPTCHA brute-force
- C – Reconnaissance across multiple government portals
- D – API scanning and admin panel bypass
- E – CVE research and vulnerability chain testing
- F – Supply chain target assessment
- I – Password spraying with CAPTCHA bypass using Tesseract OCR
- Q – Deep API endpoint exploitation
For initial access, the framework is said to have found hidden API endpoints that returned a valid authenticated session irrespective of the request body. These endpoints were then used to harvest employee usernames and then attack one of the government portals to crack 85 accounts using password spraying techniques.
In all, the illicit access allowed the attacker to exfiltrate more than 2,564 personnel records, a database of all department system users, seven SSO client secrets, six internal database credentials across MSSQL, Oracle, and Sybase, and internal network IP ranges.
“The attacker didn’t stop at primary targets,” Dream explained. “It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies – scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities.”
The framework also implements a learning engine to look up vulnerability databases, GitHub repositories, and security research to zero in on techniques that could be adapted to the target infrastructure.
“In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure,” Dream said. “It spells out one thing loudly – the cost of running a competent attack has collapsed, but the cost of defending against one has not.”
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

