Full Report
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.
Analysis Summary
# Threat Actor: Unidentified (Linked to Iran-affiliated activity)
## Attribution & Identity
* **Identification:** The primary threat actors behind the current campaign remain officially "unidentified" by federal agencies (NSA, FBI, CISA).
* **Known Associations:** The advisory notes that the current activity follows a July alert regarding **Iran-affiliated hackers**.
* **Likely Origin:** While not explicitly attributed, the behavior aligns with historical Iranian-linked targeting of Industrial Control Systems (ICS).
## Activity Summary
* **Campaign Focus:** An "active threat" involving the reconnaissance and exploitation of Siemens S7 Series Programmable Logic Controllers (PLCs).
* **Current Status:** Ongoing as of August 2026. The campaign is characterized by the use of **AI-assisted development** to create exploit scripts and custom malicious tools.
* **Objective:** Persistent reconnaissance to develop capabilities for future "operational effects" (disruption) against critical infrastructure.
## Tactics, Techniques & Procedures
* **AI-Assisted Development:** Utilizing artificial intelligence to generate exploitation scripts, reducing the technical barrier for entry and speeding up the weaponization of known vulnerabilities.
* **Internet Scanning:** Using scanning platforms to identify PLCs exposed directly to the public internet.
* **Masquerading:** Creating custom malicious tools designed to look like legitimate Operational Technology (OT) monitoring solutions.
* **Credential Access:** Deploying scripts specifically designed to harvest credentials and establish pathways for further damage.
* **Vulnerability Exploitation:** Targeting known vulnerabilities in Siemens S7 Series hardware.
* **MITRE ATT&CK IDs (Inferred):**
* T1046: Network Service Scanning
* T1588.006: Obtain Capabilities: Cyber Artifacts (AI-generated)
* T1036: Masquerading
* T0815: ICS-Specific: External Loss of Control (Potential/Targeted)
## Targeting
* **Sectors:** Energy, Water and Wastewater, Agriculture, Manufacturing, and the Defense Industrial Base (DIB).
* **Geography:** Primarily United States-based installations.
* **Victims:** Siemens S7 Series PLC installations. Recent activity also noted intrusions at dozens of water utilities across at least 12 U.S. states.
## Tools & Infrastructure
* **Hardware Targeted:** Siemens S7 Series PLCs (also mentions historical targeting of Schneider Electric, Rockwell Automation, and Allen-Bradley).
* **Malware/Scripts:** AI-generated exploitation scripts disguised as monitoring tools.
* **Infrastructure:** Internet scanning platforms (e.g., Shodan/Censys style tools) to locate exposed IP addresses.
## Implications
* **Strategic Risk:** The use of AI represents an "evolution" in capabilities, significantly compressing the time between a vulnerability being published and a working exploit being deployed.
* **Operational Risk:** Exploitation could lead to physical equipment damage, downtime, safety incidents, and cascading failures across interconnected critical infrastructure systems.
* **Third-Party Risk:** Many organizations are unaware of their exposure because internet connectivity was introduced by third-party vendors rather than the end-users.
## Mitigations
* **Network Isolation:** Isolate PLCs and OT hardware from the public internet immediately.
* **Patch Management:** Install all security patches for Siemens S7 Series hardware with urgency.
* **Monitoring:** Enable and prioritize security tooling to monitor for unauthorized access or anomalous threat activity within OT environments.
* **Vulnerability Assessment:** Conduct audits to ensure third-party vendors have not inadvertently exposed internal PLC installations to the internet.