logo

Analyzing PIPEDREAM: Results from Runtime Testing

ID: 953aadff-d1b8-5b94-a5e7-1e5f2fbac578

STIX ID: report--953aadff-d1b8-5b94-a5e7-1e5f2fbac578

Feed Name: Dragos Blog

Threat Score
88/100

Date Published: 2022-10-27

Date Updated: 2026-04-27

...
...

PIPEDREAM (attributed to CHERNOVITE) is a cross-industry ICS malware framework that Dragos tested in runtime and found capable of disruptive and destructive effects: MOUSEHOLE can manipulate OPC UA-controlled processes, EVILSCHOLAR can perform CODESYSv3 logic corruption on PLCs, and BADOMEN can modify Omron NX/NJ controllers and 1S-series servo drives; safety controller targeting is not yet supported but is a likely future development. The report confirms high technical capability, demonstrates physical-impact scenarios (overpressurizing pipelines, overspeeding servos), and reiterates previously published mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.