PIPEDREAM, also tracked as INCONTROLLER, is a modular industrial control system attack framework developed by the CHERNOVITE activity group and assessed as a state-sponsored capability intended for disruptive or destructive operations in operational technology environments. It is widely regarded as one of the few publicly known ICS-specific malware families and was identified before confirmed operational deployment for physical impact, giving defenders unusual pre-deployment visibility into a mature OT attack capability.
The framework is designed to target programmable logic controllers and related industrial software, with documented focus on Schneider Electric and Omron devices, OPC UA servers, and CODESYS-based environments. Because CODESYS is broadly embedded across many industrial vendors, the framework’s potential applicability extends beyond the initially identified device set. Reported capabilities include rapid OT reconnaissance, enumeration of industrial assets and services, brute forcing of controller and OPC UA credentials, direct interaction with PLCs over native industrial protocols, manipulation of controller logic and operating modes, denial-of-control and denial-of-view effects, disruption of operator access, wiping or bricking of targeted devices, and use of compromised PLCs as pivot points or proxies deeper into OT networks.
PIPEDREAM also includes Windows-focused intrusion components that support host reconnaissance, command and control, lateral tool transfer, and loading of unsigned drivers through exploitation of a vulnerable driver, enabling post-compromise operations across converged IT and OT environments. Documented toolkit modules include EVILSCHOLAR for Schneider Electric and CODESYS-oriented controller operations, BADOMEN for Omron interaction and remote shell functionality, MOUSEHOLE for OPC UA enumeration and node manipulation, DUSTTUNNEL for host reconnaissance and command and control, and LAZYCARGO for vulnerable-driver-based driver loading.
The framework has been associated with attack paths that begin with compromise of Windows systems in enterprise or supervisory environments, followed by pivoting into OT segments for controller discovery, protocol-level interaction, and process manipulation. High-confidence reporting indicates likely intended target environments include electric power and oil and gas infrastructure, particularly liquefied natural gas operations, though the underlying techniques are adaptable to other industrial sectors. PIPEDREAM represents a significant evolution in ICS malware because it combines scalable multi-vendor OT disruption with conventional Windows intrusion tradecraft in a single coordinated framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"LAZYCARGO ... drops and exploits a vulnerable ASRock driver to load an unsigned driver." ... "1https://github.com/stong/CVE-2020-15368"
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PIPEDREAM is the seventh-known Industrial Control Systems (ICS)-specific malware and the fifth malware specifically developed to disrupt industrial processes.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
CHERNOVITE can leverage PIPEDREAM’s multiple components to perform rapid reconnaissance of ICS networks by using a variety of mechanisms, including: Identifying known MAC addresses, Port numbers, HTTP banners, Omron’s proprietary Factory Interface Network Service Protocol (FINS), Modbus, Schneider’s custom Discovery broadcast protocol (NetManage).
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS attack framework designed to target industrial controllers, specifically noted here as targeting Schneider Electric and OMRON devices.
Modular ICS attack framework targeting multiple industrial controllers and protocols, including Schneider Electric, OMRON, OPC UA servers, CODESYS environments, and Modbus TCP write functions for direct PLC manipulation.
Named ICS malware/tooling referenced in OT threat intelligence coverage.
Modular ICS attack platform (reported discovered in 2022) assessed as capable of disrupting or destroying OT operations, including disabling/bricking control systems and potentially undermining safety systems; described as adaptable to multiple industrial environments with initial focus on electric and oil & gas/LNG.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.