Evil PLC Attack: Hacking PLCs to Attack Engineering Workstations
ID: 33576786-070b-50f5-af00-cc91dc24e19a
STIX ID: report--33576786-070b-50f5-af00-cc91dc24e19a
Feed Name: Claroty Team82
Date Published: 2023-08-07
Date Updated: 2026-04-17
Author: Sharon Brizinov; Mashav Sapir; Amir Preminger; Uri Katz; Noam Moshe
Team82's 'Evil PLC Attack' research demonstrates a novel and practical technique in which attackers store specially crafted data on PLCs so that when an engineer performs a normal upload from the PLC to an engineering workstation, the workstation parses the malicious data and executes code; the paper includes proof-of-concept exploits against seven major automation vendors, discusses attack scenarios (internet-exposed PLCs, traveling integrators, and defensive honeypots), explains methodology and findings, and provides mitigations such as network segmentation, client authentication/PKI, monitoring, and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
