logo

New Knowledge Pack Released (KP-2022-004)

ID: c96054c4-586c-5a8e-bfb0-44c512b4b98b

STIX ID: report--c96054c4-586c-5a8e-bfb0-44c512b4b98b

Feed Name: Dragos Blog

Threat Score
85/100

Date Published: 2022-04-15

Date Updated: 2026-04-27

...
...

This Knowledge Pack from Dragos describes the CHERNOVITE group and its PIPEDREAM ICS attack framework, detailing modular components (EVILSCHOLAR, BADOMEN, MOUSEHOLE, LAZYCARGO) that enable discovery, access, privilege escalation, and manipulation of Schneider Electric and Omron PLCs and related ICS protocols (CODESYS, Modbus, OPC UA, etc.). The pack provides over 250 characterizations and 500 detections — including protocol characterizations, YARA rules, signatures for tools like BITSAdmin, and scans for CVE-2022-22536 — to help detect, attribute, and mitigate these ICS-targeting capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.