Threats · Activity group
CHERNOVITE
Executive summary
CHERNOVITE is the Dragos activity group credited with developing PIPEDREAM, the modular ICS attack framework discovered before deployment. PIPEDREAM is capability, not an actor: it is the toolset, and CHERNOVITE is the cluster that built it. Conflating the two is the single most common naming error in OT threat intelligence.
PIPEDREAM's significance is its portability. Rather than targeting one plant, its modules speak standard industrial protocols and vendor-specific interfaces, so the same framework can be pointed at many environments.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- PIPEDREAMCapability / malware nameConfirmed
Tracked by Dragos — Malware / capability name developed by CHERNOVITE — not an alias for the group.
- INCONTROLLERCapability / malware nameConfirmed
Tracked by Google Threat Intelligence / Mandiant / Schneider Electric — Independent naming for the same tool set.
Relevance
Why OT defenders care
Objectives
- Reusable, cross-vendor ICS effects capability
- Manipulation and disablement of controllers and safety systems
Reported impacts
- No publicly confirmed deployment against a live process
- Assessed potential for loss of control, loss of view and loss of safety
Observed behaviours
- Programmatic discovery of controllers over industrial protocols
- Ability to read, write and manipulate controller configuration and logic
- OPC UA client functionality for broad environment interaction
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- PIPEDREAM / INCONTROLLERModular framework with components for device discovery, controller manipulation and OPC UA interaction.
- ASRock driver abuse componentReported Windows kernel driver exploitation component for host-level effects.
Commercial tool
Not publicly established
Open-source utility
Not publicly established
Native OS tool
Not publicly established
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- Capability discovered prior to any publicly confirmed deployment
Atlas incident case studies
- PIPEDREAM / INCONTROLLER2022 · Multiple (energy, manufacturing)
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Baseline OPC UA and Modbus client sets; alert on any new client
- Restrict CODESYS and vendor engineering ports to named engineering hosts
- Enforce controller mode switches and logic checksum baselining
- Detect device discovery sweeps on control networks — they should never occur unannounced
Hunt for this activity
- Protocol use from an unexpected Purdue levelAn industrial protocol is being used across a Purdue boundary where it should not appear.
- Unexpected controller write or programming behaviourA controller received a write or programming operation that does not match an approved change.
- New ICS protocol communicating pairTwo devices are speaking an industrial protocol to each other for the first time.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- GovernmentCISA / DOE / NSA / FBIAPT Cyber Tools Targeting ICS/SCADA Devices (AA22-103A) (opens in a new tab)
- Vendor IntelligenceDragosCHERNOVITE's PIPEDREAM: Malware Targeting Industrial Control Systems (opens in a new tab)
- Vendor IntelligenceGoogle Threat Intelligence / MandiantINCONTROLLER: New State-Sponsored Cyber Attack Tools Target Multiple Industrial Control Systems (opens in a new tab)
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)