AI Exploits OT Equipment, But Not Cheaply
Forescout researchers used AI to port RCE exploits to PLCs, but high cost and effort still deter criminals.
Industrial control systems have long been considered a tougher target than standard IT networks, shielded by proprietary protocols and specialized hardware. But a new experiment from Forescout researchers suggests that artificial intelligence is steadily chipping away at that advantage. The team demonstrated that AI can be guided to port a remote code execution exploit from one programmable logic controller to another, ultimately crashing the device and executing attacker-supplied shellcode. The catch: it took significant human expertise and more than $500 in API fees to get there.
Porting an Exploit Between PLCs
Forescout researchers set out to answer a straightforward question: could someone use AI to target the growing population of internet-exposed industrial devices? Their approach involved taking a known remote code execution (RCE) vulnerability and attempting to adapt it to work on a different PLC model. These devices run closed-source software, which typically makes them harder to manipulate than open-source systems.
Despite that obstacle, the experiment succeeded. The researchers not only managed to trigger a denial-of-service condition that crashed the target device but also achieved a working RCE capable of executing attacker-supplied ARM shellcode. The ability to run arbitrary code on a PLC is a significant step, as it opens the door to manipulating industrial processes or causing physical damage.
AI-Assisted Attacks Cost More Than Expected
The success, however, came with substantial costs and limitations. According to the researchers, the final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial code execution ultimately bricked the PLC, rendering it unusable. These constraints highlight the practical hurdles that remain for would-be attackers.
"It required significant researcher input. The final RCE development stage consumed more than $500 in API usage. An attempt to extend the exploit beyond the initial RCE ultimately bricked the PLC,"
the researchers said in the report, as quoted by TechRadar Pro. They added that the exercise taught them valuable lessons about AI-assisted exploitation in OT, concluding that "It can be done, but it’s not as easy as it sounds. For now, the difficulty, cost, and specialist expertise required are likely to make this kind of attack less attractive than easier alternatives."
Why Criminals Will Look Elsewhere
The researchers' assessment suggests that for financially motivated cybercriminals, the economics do not yet favor AI-driven OT exploitation. The combination of high API costs, the need for specialized knowledge, and the risk of bricking devices makes it less appealing than other attack vectors. Criminals often seek the path of least resistance, and traditional IT attacks—such as ransomware or phishing—remain far more lucrative and less technically demanding.
The Nation-State Exception
What the report does not delve into, as TechRadar notes, is the calculus for nation-state attackers. These actors command significant resources and treat industrial infrastructure as a prime target. For them, spending over $500 in API usage is negligible compared to the strategic value of compromising a power grid or manufacturing plant. The report points to Sandworm's 2025 attack on Poland's electricity suppliers as a reminder that state-sponsored groups are already active in this space.
Exposed Industrial Devices a Growing Concern
The experiment underscores the growing exposure of industrial devices to the internet. PLCs are critical components in sectors like energy, water treatment, and manufacturing, and their connectivity often expands for operational convenience. This increased attack surface, combined with advances in AI, raises the stakes for securing OT environments. While the cost barrier may protect against casual criminals, it does little to deter determined adversaries with deep pockets.
What This Means for Critical Infrastructure
The implications for critical infrastructure operators are significant, even if the immediate threat is limited. The Forescout research demonstrates that AI can be a powerful tool in the hands of skilled operators, potentially lowering the barrier to entry for sophisticated attacks over time. For now, though, the practical difficulties of AI-assisted OT exploitation mean that traditional defense measures—such as network segmentation, robust authentication, and regular patching—remain effective against most threats.
Yet the research serves as a warning that the security landscape is evolving. As AI models improve and API costs decline, the equation may shift, making it easier for less-skilled attackers to leverage AI for OT exploitation. This could mean that critical infrastructure providers need to pay closer attention to AI-driven threats in the coming years, even if the current risk is manageable.
- More than $500 in API usage was consumed during the final RCE development stage.
- An attempt to extend the exploit beyond the initial RCE bricked the PLC.
- Sandworm's 2025 attack on Poland's electricity suppliers highlighted nation-state interest in industrial targets.
Conclusion: A Costly but Real Milestone
The Forescout experiment is a milestone in AI-assisted OT exploitation, but it comes with caveats that temper immediate alarm. The researchers themselves frame the achievement as a proof of concept rather than a practical attack method for criminals. However, the fact that AI can be steered to execute shellcode on a PLC—even with significant human help—suggests that the barriers are not insurmountable. As AI tools become more sophisticated and cheaper to use, the window of relative safety for OT systems may narrow. For operators of critical infrastructure, this is a reason to strengthen defenses now, before the cost equation tilts in favor of attackers.
Sources
- TechRadar Original source
Continue Reading
MSP Ransomware Defense Needs More Than Backups
Acronis data shows 143 MSP victims in 2025. A six-point checklist helps providers verify real recovery capability.
Legacy Lenovo login tied to Dropbox account hacks
Dropbox says attackers abused a legacy Lenovo login integration to access 5,000 accounts.
SonicWall SMA 1000 Zero-Days Exploited in Chained Attacks
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.