CHERNOVITE is the Dragos-designated activity group associated with development of PIPEDREAM, also tracked by Mandiant as INCONTROLLER. It is assessed as a state-sponsored threat actor focused on industrial control systems and operational technology, with tooling intended for disruptive, degradative, and potentially destructive operations against industrial processes rather than financially motivated crime. At the time of public reporting, no confirmed disruptive or destructive intrusions had been attributed to CHERNOVITE, making it notable as a pre-deployment exposure of a mature ICS attack capability. CHERNOVITE’s known capability set centers on PIPEDREAM, a modular ICS malware framework targeting Schneider Electric and Omron programmable logic controllers, OPC UA servers, and CODESYS-based environments. The framework includes components for rapid ICS reconnaissance, controller discovery, manipulation of PLC logic and parameters, brute forcing of credentials in industrial environments, denial-of-service actions against controllers, and arbitrary OPC UA node interaction. Reported capabilities include changing controller operating modes, backing up and restoring configurations, wiping PLC memory, loading native implants onto PLCs, and manipulating Omron servo motor speed and torque in ways that could create unsafe operating conditions. The toolkit also includes Windows-focused components that support host reconnaissance, command and control, lateral tool transfer, and kernel-level post-exploitation through exploitation of a vulnerable signed driver to load unsigned code. CHERNOVITE has been described as capable of using PLCs as network proxies across OT environments, potentially bypassing segmentation controls and perimeter monitoring, and of undermining OT authentication and encryption by collecting PLC network traffic and weakening controller authentication. The framework supports both IT-to-OT pivoting and direct OT manipulation, aligning with a staged intrusion model that begins with initial compromise in enterprise systems and progresses through reconnaissance, lateral movement, and controller compromise. Likely target environments include electric power and liquefied natural gas operations. The actor’s tradecraft and tooling indicate a mission profile consistent with strategic prepositioning and sabotage capability development against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Development of a modular ICS attack framework capable of interacting with multiple industrial controllers and protocols across several vendors, enabling direct manipulation of PLC logic and process control.
Referenced as a named activity cluster in the context of OT/ICS threat intelligence reporting.
Developer of the PIPEDREAM ICS/OT attack framework, capable of executing advanced attacks against industrial infrastructure. No known attacks have been attributed to CHERNOVITE as PIPEDREAM was discovered before use.
Named activity group assessed to be behind the Pipedream/INCONTROLLER industrial control system (ICS) malware framework, enabling scanning, compromise, and control of ICS/SCADA devices after initial access in OT networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.