New Knowledge Pack Released (KP-2022-004)
ID: c96054c4-586c-5a8e-bfb0-44c512b4b98b
STIX ID: report--c96054c4-586c-5a8e-bfb0-44c512b4b98b
Feed Name: Dragos Blog
This Knowledge Pack from Dragos describes the CHERNOVITE group and its PIPEDREAM ICS attack framework, detailing modular components (EVILSCHOLAR, BADOMEN, MOUSEHOLE, LAZYCARGO) that enable discovery, access, privilege escalation, and manipulation of Schneider Electric and Omron PLCs and related ICS protocols (CODESYS, Modbus, OPC UA, etc.). The pack provides over 250 characterizations and 500 detections — including protocol characterizations, YARA rules, signatures for tools like BITSAdmin, and scans for CVE-2022-22536 — to help detect, attribute, and mitigate these ICS-targeting capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
