CHERNOVITE (PIPEDREAM / INCONTROLLER)
CHERNOVITE is the Dragos-tracked Activity Group designation for the threat group behind PIPEDREAM (Mandiant alternative tracking: INCONTROLLER) ICS- specific malware framework disclosed April 13 2022 via joint Cybersecurity and Infrastructure Security Agency (CISA) + Department of Energy (DOE) + Federal Bureau of Investigation (FBI) + National Security Agency (NSA) cybersecurity advisory with Schneider Electric + Dragos + Mandiant industry analysis collaboration.
state-actor attribution via Dragos canonical high-confidence assessment without specific nation designation (per Dragos policy: "Dragos as a matter of policy doesn't publicly link APT groups to specific nations") + Mandiant Russia-consistent circumstantial assessment ("While we are unable to definitively attribute the malware, we note that the activity is consistent with Russia's historical interest in ICS... While our evidence connecting Incontroller to Russia is largely circumstantial, we note it given Russia's history of destructive cyber attacks, its current invasion of Ukraine, and related threats against Europe and North America") + Schneider Electric early 2022 investigation co-collaboration + SecurityWeek + Bleeping Computer + Hacker News + CyberScoop + TechCrunch + Security Management + Enterprise Times + Wikipedia + Ben Miller ISSA industry coverage.
standalone cluster paralleling kamacite + raspite_leafminer + covellite_lazarus_ics in v0.1.166 OT/ICS Dragos-taxonomy actor cluster cell.
operational target profile signature liquid natural gas (LNG) + electric power sites initial target set per Dragos Robert M. Lee ("Specifically the initial targeting appears to be liquid natural gas and electric community specific. However, the nature of the malware is that it works in a wide variety of industrial controllers and systems") + signature U.S. LNG + key electric power sites per Ben Miller ISSA + signature Schneider Electric PLCs with Modbus + CODESYS + EcoStruxure Machine Expert + SoMachine capability + OMRON Sysmac NEX PLCs + Open Platform Communications Unified Architecture (OPC UA) servers + Windows-based engineering workstations via ASRock motherboard driver + Ukraine + NATO + Europe + North America per Mandiant Russia-invasion context.
operational attack architecture: (1) cluster-defining 7th-ICS-specific-malware-ever-found designation per Dragos after Stuxnet (2010) + Havex (2013) + Industroyer/CrashOverride (2016) + Triton/Trisis (2017) + BlackEnergy2 + Industroyer2 (2022)
(2) cluster-defining first-time industrial-cyber- capability-found-prior-to-deployment signature per Dragos CEO Robert M. Lee Twitter statement April 13 2022 ("This is the first time, I'm aware of, that an industrial cyber capability has been found prior to its deployment for intended effects. This capability was designed to be disruptive/destructive in nature, and we're actually a step ahead of the adversary")
(3) cluster-defining 5-integrated-utility component architecture per Dragos labeling: EVILSCHOLAR + BADOMEN + MOUSEHOLE + DUSTTUNNEL + LAZYCARGO (with Mandiant alternative tracking of components TagRun + CodeCall + OmShell)
(4) cluster- defining CVE-2020-15368 ASRock motherboard driver Windows kernel exploit via LAZYCARGO component with ASRock AsrDrv103.sys driver targeting Windows-based engineering workstations across IT + OT environments.
(5) cluster-defining multi- protocol coverage with Schneider Electric + OMRON Sysmac NEX PLCs + Open Platform Communications Unified Architecture (OPC UA) servers + CODESYS + Modbus protocol library + EcoStruxure Machine Expert + SoMachine software + Schneider PLC default Administrator/Administrator credentials legacy capability.
(6) cluster- defining 38% ICS attack techniques + 83% ICS attack tactics capability assessment per Dragos establishing PIPEDREAM as most-flexible ICS attack framework to date with potential to disrupt + degrade + potentially destroy industrial environments + processes per Dragos.
(7) cluster- defining Russia-consistent attribution per Mandiant circumstantial + Dragos high-confidence- state-actor-without-specific-nation-designation signature.
(8) signature rapid-reconnaissance-of- ICS-networks operational pattern per Dragos whitepaper with concern about changes to time-to- detect for defenders accustomed to attackers sitting dormant in networks for months.
(9) signature loss-of-safety + loss-of-availability + loss-of-control of industrial environment capability per Dragos with disable-emergency- shutdown-system + manipulate-operational- environment-to-unsafe-conditions potential per Mandiant.
(10) signature comparable-to-TRITON- INDUSTROYER-STUXNET per Mandiant ("It is comparable to TRITON, which attempted to disable an industrial safety system in 2017.
INDUSTROYER, which caused a power outage in Ukraine in 2016; and STUXNET, which sabotaged the Iranian nuclear program around 2010")
(11) signature Dragos Knowledge Pack KP-2022-004 detections for EVILSCHOLAR + BADOMEN + MOUSEHOLE + LAZYCARGO + compiled Python executable Yara rules + compiled Python transfer to OT asset behavioral signature; cluster fills the Dragos-CHERNOVITE-PIPEDREAM- activity-group + 7th-ICS-specific-malware-ever- found + April-13-2022-joint-CISA-DOE-FBI-NSA- advisory + 5-component-EVILSCHOLAR-BADOMEN- MOUSEHOLE-DUSTTUNNEL-LAZYCARGO + Schneider-Omron- OPC-UA-Modbus-CODESYS-protocol-coverage + CVE- 2020-15368-ASRock-motherboard-driver-LAZYCARGO + LNG-electric-power-initial-target-signature + Russia-consistent-Mandiant-attribution- circumstantial + captured-pre-deployment-unique- defender-opportunity-signature position in OT/ICS Dragos-taxonomy actor cluster cell.
canonical illustration of state-actor-without-definitive- nation-attribution methodology + 5-component- framework architecture + Schneider/Omron/OPC-UA/ Modbus/CODESYS multi-protocol coverage + CVE- 2020-15368 ASRock motherboard driver kernel exploit + LNG + electric power initial-target signature + captured-pre-deployment defender- opportunity unique pattern cited in essentially all subsequent ICS/OT threat industry analyses through 2022-2026 period.