Hacking

Boffins hacked Siemens Simatic S7, most secure controllers in the industry

A group of Israeli researchers demonstrated that it is possible to take over the Simatic S7 controller one of the most secure controllers in the industry.

A team of Israeli researchers demonstrated that it is possible to take control of the Simatic S7 controller without the knowledge of the operators.

The team was composed of researchers from the Cyber ​​Centers at the Technion and Tel Aviv University and experts from the National Cyber ​​Arrangement.

Among the prominent experts involved in the research there is the head of the Cyber ​​Security Research Center at the Technion, Prof. Eli Boehm and Dr. Sarah Bitan of the Technion’s Faculty of Computer Science, Prof. Avishay Wall of the School of Electrical Engineering at Tel Aviv University, and the students Aviad Carmel, Alon Dankner and Uriel Malin. 

The Siemens S7 is considered one of the most secure controllers in the industry, it is used in power plants, traffic lights, water pumps, building control, production lines, aviation systems, and many other critical infrastructures. 

“[The experts were able to] to turn off and turn on the controller, load various control logic into it, and change the activation code and source code.” reads a post published on the TechTimes. “They also succeeded in creating a situation where cattle operators cannot identify the “hostile intervention” performed in cattle.

The researchers reported their finding to Siemens and presented the attack technique (dubbed “Rogue7” ) at the Black Hat security conference held in Las Vegas last week. 

The experts focused their study on the safety of Siemens Simatic S7 industrial controllers. Siemens S7 devices are connected to a computer, that sends them the commands, and manage multiple devices such as sensors and motors.

The team has made a reverse-engineering the communication protocol implemented by Siemens, then developed a rogue engineering workstation that mimicked the TIA Portal, and was able to send commands to the controller. 

The attack scenario sees hackers, with access to the network and the PLC of the target organization, setting up a fake workstation.

“After reverseengineering the cryptographic protocol, we are able to create a rogue engineering station which can masquerade as the TIA to the PLC and inject any messages favourable to the attacker. As a first example we extend attacks that can remotely start or stop the PLC to the latest S7-1500 PLCs.” reads the research paper published by the experts. “Our main attack can download control logic of the attacker’s choice to a remote PLC. Our strongest attack – the stealth program injection attack – can separately modify the running code and the source code, which are both downloaded to the PLC. This allows us to modify the control logic of the PLC while retaining the source code the PLC presents to the engineering station. “

The experts successfully tested their attack on Siemens S7 1500 PLC.

Further details on the “Rogue7” attack are reported in a research paper published by the experts.

“The attack also shows that securing industrial control systems is a more difficult and challenging task than securing information systems.” explained Dr. Bitan.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Siemens Simatic S7, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

14 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

15 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

20 hours ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

1 day ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.