Skip to main content
OT Atlas

Threats · Activity group

CHERNOVITE

unknownStage 2 ICS effectsDragosAttribution · Moderate
Last verified

Executive summary

CHERNOVITE is the Dragos activity group credited with developing PIPEDREAM, the modular ICS attack framework discovered before deployment. PIPEDREAM is capability, not an actor: it is the toolset, and CHERNOVITE is the cluster that built it. Conflating the two is the single most common naming error in OT threat intelligence.

PIPEDREAM's significance is its portability. Rather than targeting one plant, its modules speak standard industrial protocols and vendor-specific interfaces, so the same framework can be pointed at many environments.

At a glance

Tracked byDragos
NexusState-actor capability assessed by vendors; no public government attribution to a named state
First observed2022 (public disclosure)
Last reported2022 joint advisory; continued vendor tracking
ICS kill chainStage 2 — Develop ICS capability

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

CHERNOVITE
  • PIPEDREAM
    Capability / malware nameConfirmed

    Tracked by Dragos — Malware / capability name developed by CHERNOVITE — not an alias for the group.

  • INCONTROLLER
    Capability / malware nameConfirmed

    Tracked by Google Threat Intelligence / Mandiant / Schneider Electric — Independent naming for the same tool set.

Relevance

Why OT defenders care

Objectives

  • Reusable, cross-vendor ICS effects capability
  • Manipulation and disablement of controllers and safety systems

Reported impacts

  • No publicly confirmed deployment against a live process
  • Assessed potential for loss of control, loss of view and loss of safety

Observed behaviours

  • Programmatic discovery of controllers over industrial protocols
  • Ability to read, write and manipulate controller configuration and logic
  • OPC UA client functionality for broad environment interaction

Targeting

Sectors, geography and assets

Target industries

Electric powerOil and gasLiquefied natural gasManufacturing

Target geography

Not publicly established for deployment; capability applicable globally

Observed assets

PLC (Schneider Modicon, Omron)OPC UA serverEngineering workstationSafety controller

Protocols in scope

Modbus TCPCODESYSOPC UAOmron FINS / HTTPSchneider vendor protocols

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • PIPEDREAM / INCONTROLLERModular framework with components for device discovery, controller manipulation and OPC UA interaction.
  • ASRock driver abuse componentReported Windows kernel driver exploitation component for host-level effects.

Commercial tool

Not publicly established

Open-source utility

Not publicly established

Native OS tool

Not publicly established

ATT&CK

Technique mapping

ATT&CK Enterprise

History

Known campaigns and incidents

Reported campaigns

  • Capability discovered prior to any publicly confirmed deployment

Atlas incident case studies

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Baseline OPC UA and Modbus client sets; alert on any new client
  • Restrict CODESYS and vendor engineering ports to named engineering hosts
  • Enforce controller mode switches and logic checksum baselining
  • Detect device discovery sweeps on control networks — they should never occur unannounced

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.