Five U.S. agencies said attackers are actively probing Siemens S7 PLCs in the U.S., using AI-generated scripts disguised as legitimate monitoring tools to gain read and write access.
The advisory says the actors scan for internet-exposed or poorly segmented controllers, exploit known flaws or weak credentials, and use snap7-based Python tools over S7comm on TCP port 102.
Targeted models span S7-200, S7-300, S7-400, S7-1200 and S7-1500 systems, with manufacturing, energy, water, chemical, food and commercial facilities seen as the most exposed sectors.
Agencies urged operators to inventory devices, patch firmware, block internet access, tighten remote access and monitor for anomalies such as off-hours S7comm traffic, unauthorized writes and snap7.dll use.
Officials said the campaign reflects a broader PLC threat beyond Siemens and could pre-position attackers for disruption, safety incidents, equipment damage and cascading supply-chain effects.