Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve [Execution](https://attack.mitre.org/tactics/TA0104), [Persistence](https://attack.mitre.org/tactics/TA0110), and [Lateral Movement](https://attack.mitre.org/tactics/TA0109) objectives. Adversaries may modify an existing project file or bring their own project files into the environment.(Citation: Nicolas Falliere, Liam O Murchu, Eric Chien February 2011) The ability for an adversary to deploy an infected project file relies on access to a workstation with Siemens PLC programming software installed on it from which a program download can be performed.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Workstation
is blocked by Code Signing
is blocked by Detection of Siemens Project File Format Infection
is blocked by Encrypt Sensitive Information
is blocked by Audit
is blocked by Restrict File and Directory Permissions
Impressum Deutsch Englisch