THREAT OPS › Threat News › Defending Against an Active Threat to Siemens S7 Series PLCs
Defending Against an Active Threat to Siemens S7 Series PLCs
<h2><strong>Executive summary</strong></h2> <p><em><strong>Note:</strong> This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advis
MITRE ATT&CK techniques
- Artificial IntelligenceT1588.007
- VulnerabilitiesT1588.006
- Native APIT1106
- Data from Local SystemT1005
- MasqueradingT1036
- Search Open Technical DatabasesT1596
- Multi-Factor AuthenticationT1556.006
- ExploitsT1587.004
- CredentialsT1589.001
- Obtain CapabilitiesT1588
- Scan DatabasesT1596.005
- Develop CapabilitiesT1587
- Search Open Technical DatabasesAML.T0000
- Obtain CapabilitiesAML.T0016
- Develop CapabilitiesAML.T0017
- Data from Local SystemAML.T0037
- MasqueradingAML.T0074
Indicators of compromise
- https://www.siemens.com/en-us/content/cert-services/#6cOXgBJ3xa94mcOefayaUhurl
- https://www.ic3.gov/CSA/2026/260114.pdfurl
- https://media.defense.gov/2022/Sep/22/2003083007/-1/-1/0/CSA_ICS_Know_the_Opponent_.PDFurl
- https://ic3.gov/url
- https://www.fbi.gov/contact-us/field-officesurl
- https://www.siemens.com/certurl
- https://www.siemens.com/en-us/content/cert-services/url
- contact@cisa.dhs.govemail
- energysrma@hq.doe.govemail
- productcert@siemens.comemail
- cybersecurityreports@nsa.govemail
- dib_defense@cyber.nsa.govemail
- mediarelations@nsa.govemail
- services.automation@siemens.comemail
Original source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a