logo

Evil PLC Attack: Hacking PLCs to Attack Engineering Workstations

ID: 33576786-070b-50f5-af00-cc91dc24e19a

STIX ID: report--33576786-070b-50f5-af00-cc91dc24e19a

Feed Name: Claroty Team82

Threat Score
78/100

Date Published: 2023-08-07

Date Updated: 2026-04-17

Author: Sharon Brizinov; Mashav Sapir; Amir Preminger; Uri Katz; Noam Moshe

...
...

Team82's 'Evil PLC Attack' research demonstrates a novel and practical technique in which attackers store specially crafted data on PLCs so that when an engineer performs a normal upload from the PLC to an engineering workstation, the workstation parses the malicious data and executes code; the paper includes proof-of-concept exploits against seven major automation vendors, discusses attack scenarios (internet-exposed PLCs, traveling integrators, and defensive honeypots), explains methodology and findings, and provides mitigations such as network segmentation, client authentication/PKI, monitoring, and patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.