Home/Threat Actor/CHERNOVITE (PIPEDREAM / INCONTROLLER)
Threat Actor

CHERNOVITE (PIPEDREAM / INCONTROLLER)

chernovite_pipedream · russia_consistent_state_actor_per_mandiant_dragos_high_confidence_no_specific_nation_attribution · active since 2022-01

CHERNOVITE is the Dragos-tracked Activity Group designation for the threat group behind PIPEDREAM (Mandiant alternative tracking: INCONTROLLER) ICS- specific malware framework disclosed April 13 2022 via joint Cybersecurity and Infrastructure Security Agency (CISA) + Department of Energy (DOE) + Federal Bureau of Investigation (FBI) + National Security Agency (NSA) cybersecurity advisory with Schneider Electric + Dragos + Mandiant industry analysis collaboration.

state-actor attribution via Dragos canonical high-confidence assessment without specific nation designation (per Dragos policy: "Dragos as a matter of policy doesn't publicly link APT groups to specific nations") + Mandiant Russia-consistent circumstantial assessment ("While we are unable to definitively attribute the malware, we note that the activity is consistent with Russia's historical interest in ICS... While our evidence connecting Incontroller to Russia is largely circumstantial, we note it given Russia's history of destructive cyber attacks, its current invasion of Ukraine, and related threats against Europe and North America") + Schneider Electric early 2022 investigation co-collaboration + SecurityWeek + Bleeping Computer + Hacker News + CyberScoop + TechCrunch + Security Management + Enterprise Times + Wikipedia + Ben Miller ISSA industry coverage.

standalone cluster paralleling kamacite + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

operational target profile signature liquid natural gas (LNG) + electric power sites initial target set per Dragos Robert M. Lee ("Specifically the initial targeting appears to be liquid natural gas and electric community specific. However, the nature of the malware is that it works in a wide variety of industrial controllers and systems") + signature U.S. LNG + key electric power sites per Ben Miller ISSA + signature Schneider Electric PLCs with Modbus + CODESYS + EcoStruxure Machine Expert + SoMachine capability + OMRON Sysmac NEX PLCs + Open Platform Communications Unified Architecture (OPC UA) servers + Windows-based engineering workstations via ASRock motherboard driver + Ukraine + NATO + Europe + North America per Mandiant Russia-invasion context.

operational attack architecture: (1) cluster-defining 7th-ICS-specific-malware-ever-found designation per Dragos after Stuxnet (2010) + Havex (2013) + Industroyer/CrashOverride (2016) + Triton/Trisis (2017) + BlackEnergy2 + Industroyer2 (2022)

(2) cluster-defining first-time industrial-cyber- capability-found-prior-to-deployment signature per Dragos CEO Robert M. Lee Twitter statement April 13 2022 ("This is the first time, I'm aware of, that an industrial cyber capability has been found prior to its deployment for intended effects. This capability was designed to be disruptive/destructive in nature, and we're actually a step ahead of the adversary")

(3) cluster-defining 5-integrated-utility component architecture per Dragos labeling: EVILSCHOLAR + BADOMEN + MOUSEHOLE + DUSTTUNNEL + LAZYCARGO (with Mandiant alternative tracking of components TagRun + CodeCall + OmShell)

(4) cluster- defining CVE-2020-15368 ASRock motherboard driver Windows kernel exploit via LAZYCARGO component with ASRock AsrDrv103.sys driver targeting Windows-based engineering workstations across IT + OT environments.

(5) cluster-defining multi- protocol coverage with Schneider Electric + OMRON Sysmac NEX PLCs + Open Platform Communications Unified Architecture (OPC UA) servers + CODESYS + Modbus protocol library + EcoStruxure Machine Expert + SoMachine software + Schneider PLC default Administrator/Administrator credentials legacy capability.

(6) cluster- defining 38% ICS attack techniques + 83% ICS attack tactics capability assessment per Dragos establishing PIPEDREAM as most-flexible ICS attack framework to date with potential to disrupt + degrade + potentially destroy industrial environments + processes per Dragos.

(7) cluster- defining Russia-consistent attribution per Mandiant circumstantial + Dragos high-confidence- state-actor-without-specific-nation-designation signature.

(8) signature rapid-reconnaissance-of- ICS-networks operational pattern per Dragos whitepaper with concern about changes to time-to- detect for defenders accustomed to attackers sitting dormant in networks for months.

(9) signature loss-of-safety + loss-of-availability + loss-of-control of industrial environment capability per Dragos with disable-emergency- shutdown-system + manipulate-operational- environment-to-unsafe-conditions potential per Mandiant.

(10) signature comparable-to-TRITON- INDUSTROYER-STUXNET per Mandiant ("It is comparable to TRITON, which attempted to disable an industrial safety system in 2017.

INDUSTROYER, which caused a power outage in Ukraine in 2016; and STUXNET, which sabotaged the Iranian nuclear program around 2010")

(11) signature Dragos Knowledge Pack KP-2022-004 detections for EVILSCHOLAR + BADOMEN + MOUSEHOLE + LAZYCARGO + compiled Python executable Yara rules + compiled Python transfer to OT asset behavioral signature; cluster fills the Dragos-CHERNOVITE-PIPEDREAM- activity-group + 7th-ICS-specific-malware-ever- found + April-13-2022-joint-CISA-DOE-FBI-NSA- advisory + 5-component-EVILSCHOLAR-BADOMEN- MOUSEHOLE-DUSTTUNNEL-LAZYCARGO + Schneider-Omron- OPC-UA-Modbus-CODESYS-protocol-coverage + CVE- 2020-15368-ASRock-motherboard-driver-LAZYCARGO + LNG-electric-power-initial-target-signature + Russia-consistent-Mandiant-attribution- circumstantial + captured-pre-deployment-unique- defender-opportunity-signature position in OT/ICS Dragos-taxonomy actor cluster cell.

canonical illustration of state-actor-without-definitive- nation-attribution methodology + 5-component- framework architecture + Schneider/Omron/OPC-UA/ Modbus/CODESYS multi-protocol coverage + CVE- 2020-15368 ASRock motherboard driver kernel exploit + LNG + electric power initial-target signature + captured-pre-deployment defender- opportunity unique pattern cited in essentially all subsequent ICS/OT threat industry analyses through 2022-2026 period.

russia_consistent_state_actor_per_mandiant_dragos_high_confidence_no_specific_nation_attribution confidence: high 25 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited1

Profile

CHERNOVITE is the Dragos-tracked Activity Group designation for the threat group behind PIPEDREAM (Mandiant alternative tracking: INCONTROLLER) ICS- specific malware framework disclosed April 13 2022 via joint CISA + DOE + FBI + NSA cybersecurity advisory with Schneider Electric + Dragos + Mandiant industry analysis collaboration. State-actor attribution via Dragos canonical high- confidence assessment without specific nation designation + Mandiant Russia-consistent circumstantial assessment given Russia's invasion of Ukraine + historical interest in ICS context. Cluster-defining first-time industrial-cyber- capability-found-prior-to-deployment signature per Dragos CEO Robert M.

Lee. Standalone cluster paralleling kamacite + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.

Operational target profile
  • Liquid natural gas (LNG) initial signature.
  • Electric power sites initial signature.
  • Schneider Electric PLCs + OMRON Sysmac NEX PLCs + OPC UA servers signature targeting.
  • Ukraine + NATO + Europe + North America per Mandiant Russia-invasion context Operational attack architecture: (1) 7th-ICS-specific-malware-ever-found designation (cluster-defining) (2) Captured pre-deployment unique-defender- opportunity (cluster-defining) (3) 5-component framework EVILSCHOLAR + BADOMEN + MOUSEHOLE + DUSTTUNNEL + LAZYCARGO (cluster- defining) (4) CVE-2020-15368 ASRock motherboard driver Windows kernel exploit via LAZYCARGO (cluster- defining) (5) Multi-protocol Schneider/Omron/OPC-UA/ Modbus/CODESYS coverage (cluster-defining) (6) 38% ICS techniques + 83% ICS tactics capability (signature) (7) Russia-consistent Mandiant attribution (circumstantial) + Dragos high-confidence-state- actor-without-nation-designation (cluster- defining) The cluster fills the Dragos-CHERNOVITE-PIPEDREAM- activity-group + 7th-ICS-specific-malware-ever-found + April-13-2022-joint-CISA-DOE-FBI-NSA-advisory + 5-component-EVILSCHOLAR-BADOMEN-MOUSEHOLE- DUSTTUNNEL-LAZYCARGO + Schneider-Omron-OPC-UA- Modbus-CODESYS-protocol-coverage + CVE-2020-15368- ASRock-motherboard-driver + LNG-electric-power- initial-target-signature + Russia-consistent- Mandiant-attribution-circumstantial + captured-pre- deployment-unique-defender-opportunity-signature position in OT/ICS Dragos-taxonomy actor cluster cell.

Aliases

25
chernovite_pipedreamchernovitechernovite activity grouppipedreampipedream malwarepipedream toolkitpipedream frameworkincontrollerincontroller malwareincontroller frameworkchernovite ics targeting malwarechernovite seventh ics-specific malware ever foundchernovite april 13 2022 cisa fbi nsa doe joint advisory disclosurechernovite schneider electric omron plc targetingchernovite opc ua modbus codesys industrial protocolchernovite cve-2020-15368 asrock motherboard driverchernovite evilscholar badomen mousehole dusttunnel lazycargo componentschernovite mandiant tagrun codecall omshell componentschernovite russia-consistent mandiant attributionchernovite state-actor dragos high-confidencechernovite captured pre-deployment unique-defender-opportunitychernovite liquid natural gas lng electric power initial targetschernovite swiss army knife hacking ics frameworkchernovite ics-cert kp-2022-004 dragos knowledge pack detectionschernovite 38 percent ics attack techniques 83 percent ics attack tactics capability

Notable Campaigns

10
2022-2026Continued Industry Reference Status (2022-2026)
2022CHERNOVITE Origin, Early 2022 PIPEDREAM Pre-Deployment Discovery
2022CHERNOVITE April 13 2022 Joint CISA + DOE + FBI + NSA Cybersecurity Advisory Canonical Disclosure
2022CHERNOVITE PIPEDREAM Seventh-ICS-Specific-Malware-Ever-Found Designation
2022CHERNOVITE PIPEDREAM 5-Component Architecture Signature (EVILSCHOLAR + BADOMEN + MOUSEHOLE + DUSTTUNNEL + LAZYCARGO)
2022CHERNOVITE LAZYCARGO CVE-2020-15368 ASRock Motherboard Driver Windows Kernel Exploit Signature
2022CHERNOVITE LNG + Electric Power Initial Target Set Signature
2022CHERNOVITE Russia-Consistent Attribution per Mandiant Signature (Circumstantial)
2022CHERNOVITE PIPEDREAM Multi-Protocol Coverage Signature
2022CHERNOVITE PIPEDREAM 38% ICS Attack Techniques + 83% ICS Attack Tactics Capability Assessment

Attribution & Reporting

Attributed by
Dragos (canonical CHERNOVITE Activity Group designation + PIPEDREAM 5-component breakdown + April 13 2022 disclosure)Robert M. Lee / Dragos CEO (canonical state-actor high-confidence + captured-pre-deployment statement)Mandiant (canonical INCONTROLLER alternative tracking + Russia-consistent circumstantial attribution + TagRun/CodeCall/OmShell components)Nathan Brubaker / Mandiant Director of Intelligence Analysis (canonical INCONTROLLER state-sponsored assessment)CISA (canonical April 13 2022 joint advisory co-issuer)U.S. Department of Energy (DOE) (canonical joint advisory co-issuer)FBI (canonical joint advisory co-issuer)NSA (canonical joint advisory co-issuer)Schneider Electric (canonical early 2022 investigation co-collaborator + security bulletin)SecurityWeek (canonical Russia-Linked Pipedream/Incontroller coverage)Bleeping Computer / Sergiu Gatlan (canonical US warns of govt hackers targeting ICS coverage)The Hacker News (canonical U.S. Warns of APT Hackers Targeting ICS coverage)CyberScoop / Derek B. Johnson (canonical Feds warn foreign government-connected hackers coverage)TechCrunch / Carly Page (canonical April 14 2022 State-backed hackers custom malware coverage)Security Management / ASIS Online (canonical No Longer a PIPEDREAM Seventh ICS-Focused Malware coverage)Enterprise Times / Ian Murphy (canonical CISA warns over Chernovite Pipedream coverage)Wikipedia (canonical Pipedream toolkit tracking)Ben Miller / electricfork (canonical CHERNOVITE PIPEDREAM Seventh ICS-Tailored Malware ISSA presentation)
Key reporting
reportDragos: CHERNOVITE Activity Group + PIPEDREAM 5-component framework (April 13, 2022)
reportMandiant: INCONTROLLER alternative tracking + Russia-consistent circumstantial attribution
reportCISA + DOE + FBI + NSA: April 13, 2022 joint cybersecurity advisory
reportSchneider Electric: early 2022 security bulletin
reportSecurityWeek: Russia-Linked Pipedream/Incontroller ICS Malware Designed to Target Energy Facilities
reportBleeping Computer / Sergiu Gatlan: US warns of govt hackers targeting industrial control systems
reportThe Hacker News: U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware
reportCyberScoop / Derek B. Johnson: Feds warn about foreign government-connected hackers
reportTechCrunch / Carly Page: State-backed hackers have developed custom malware (April 14 2022)
reportSecurity Management / ASIS Online: No Longer a PIPEDREAM Seventh ICS-Focused Malware Discovered
reportEnterprise Times / Ian Murphy: CISA warns over Chernovite Pipedream modular ICS malware
reportWikipedia: Pipedream (toolkit)
reportBen Miller / electricfork: CHERNOVITE's PIPEDREAM The Seventh ICS-Tailored Malware ISSA presentation

Operational

State sponsor

CHERNOVITE is Dragos's high-confidence state-actor designation for the threat group behind PIPEDREAM (Mandiant alternative tracking: INCONTROLLER) ICS- specific malware framework. Mandiant assesses "very likely state-sponsored" with activity "consistent with Russia's historical interest in ICS" given Russia's invasion of Ukraine + related threats against Europe + North America, while noting that connecting evidence is "largely circumstantial." Dragos as a matter of policy doesn't publicly link APT groups to specific nations. Honest attribution caveat: No definitive nation- state attribution publicly established by any vendor.

Mandiant Russia-consistent assessment explicitly circumstantial.

Dragos high-confidence state-actor without specific nation designation; Schneider Electric does not provide nation attribution. Attribution chain: (1) April 13 2022 joint CISA + DOE + FBI + NSA cybersecurity advisory canonical disclosure: per Bleeping Computer + Hacker News + Security Management + CyberScoop + TechCrunch + Enterprise Times: federal advisory issued by Cybersecurity and Infrastructure Security Agency (CISA) + Department of Energy (DOE) + Federal Bureau of Investigation (FBI) + National Security Agency (NSA) warning that state-sponsored hackers had developed custom modular malware to scan for, compromise, and take control of ICS and SCADA devices specifically targeting Schneider Electric programmable logic controllers (PLCs) + OMRON Sysmac NEX PLCs + Open Platform Communications Unified Architecture (OPC UA) servers. (2) Dragos canonical CHERNOVITE + PIPEDREAM attribution + 7th-ICS-specific-malware designation: per Dragos Robert M. Lee: "Since early 2022, Dragos has been analysing the PIPEDREAM toolset, which is the seventh ever ICS specific malware. We track its developers as the threat group CHERNOVITE, which we assess with high confidence to be a state actor that developed the PIPEDREAM malware for use in disruptive or destructive operations against ICS. Specifically the initial targeting appears to be liquid natural gas and electric community specific." (3) Mandiant canonical INCONTROLLER alternative tracking + Russia-consistent attribution: per Mandiant via SecurityWeek + CyberScoop: "INCONTROLLER is very likely state-sponsored and contains capabilities related to disruption, sabotage, and potentially physical destruction... While we are unable to definitively attribute the malware, we note that the activity is consistent with Russia's historical interest in ICS... While our evidence connecting Incontroller to Russia is largely circumstantial, we note it given Russia's history of destructive cyber attacks, its current invasion of Ukraine, and related threats against Europe and North America." (4) Schneider Electric + Mandiant January 2022 private analysis: per SecurityWeek: "Schneider Electric said it started investigating the APT toolset in early 2022 with Mandiant. The industrial giant noted that Incontroller/Pipedream appears to abuse legitimate functionality to achieve its goals and it does not exploit any vulnerability." (5) Captured pre-deployment unique-defender- opportunity signature: per Dragos Robert M. Lee Twitter statement April 13 2022: "This is the first time, I'm aware of, that an industrial cyber capability has been found prior to its deployment for intended effects. This capability was designed to be disruptive/destructive in nature, and we're actually a step ahead of the adversary." Cluster-defining unique defender opportunity signature. (6) PIPEDREAM 5-component architecture canonical Dragos breakdown: per Dragos blog: "PIPEDREAM impacts its targets by way of five integrated utilities Dragos has labeled: EVILSCHOLAR, BADOMEN, MOUSEHOLE, DUSTTUNNEL, and LAZYCARGO." Mandiant tracks 3 components as TagRun + CodeCall + OmShell. (7) CVE-2020-15368 ASRock motherboard driver Windows engineering workstation initial access: per Hacker News + Bleeping Computer: "The actors can compromise Windows-based engineering workstations, which may be present in information technology (IT) or OT environments, using an exploit that compromises an ASRock motherboard driver with known vulnerabilities (CVE-2020-15368) to execute malicious code in the Windows kernel." (8) 38% ICS attack techniques + 83% ICS attack tactics capability assessment: per Dragos: "It is believed to have the potential to execute at least 38 percent of known ICS attack techniques and 83 percent of known ICS attack tactics.

" Operational target profile
  • Liquid natural gas (LNG) initial signature per Dragos.
  • Electric power sites initial signature per Dragos.
  • Ukraine + NATO + Europe + North America signature per Mandiant assessment of Russia- invasion context.
  • Schneider Electric PLCs signature targeting.
  • OMRON Sysmac NEX PLCs signature targeting.
  • OPC UA servers signature targeting.
  • CODESYS + Modbus + EcoStruxure Machine Expert + SoMachine signature ICS protocol coverage.
  • Windows-based engineering workstations via ASRock motherboard driver CVE signature The cluster fills the Dragos-CHERNOVITE-PIPEDREAM- activity-group + 7th-ICS-specific-malware-ever-found + April-13-2022-joint-CISA-DOE-FBI-NSA-advisory + 5-component-EVILSCHOLAR-BADOMEN-MOUSEHOLE- DUSTTUNNEL-LAZYCARGO + Schneider-Omron-OPC-UA- Modbus-CODESYS-protocol-coverage + CVE-2020-15368- ASRock-motherboard-driver + LNG-electric-power- initial-target-signature + Russia-consistent- Mandiant-attribution-circumstantial + captured-pre- deployment-unique-defender-opportunity-signature position in OT/ICS Dragos-taxonomy actor cluster cell.
Motivations
state_actor_ics_disruptive_destructive_capability_development, russia_consistent_circumstantial_attribution_signature, lng_electric_power_initial_target_signature, schneider_omron_opc_ua_codesys_modbus_multi_protocol_capability, captured_pre_deployment_unique_defender_opportunity_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)35/60 · 58%
Analytics (MITRE CAR)25/60 · 41%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MODBUS TCP + UDP PROTOCOL COMMUNICATION SIGNATUREMODULAR ICS ATTACK FRAMEWORK DRAGOS DESCRIPTIONMOUSEHOLE COMPONENTSCHNEIDER ELECTRIC ECOSTRUXURE MACHINE EXPERT + SOMACHINE TARGETINGSCHNEIDER ELECTRIC PLC DEFAULT CREDENTIALS ADMINISTRATOR/ADMINISTRATOR LEGACYSWISS ARMY KNIFE HACKING ICS FRAMEWORK DESCRIPTION PER WIKIPEDIA

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin