Detecting CHERNOVITE’s PIPEDREAM with the Dragos Platform
ID: dbe50ff2-ca41-55da-84b0-1c5344ecdceb
STIX ID: report--dbe50ff2-ca41-55da-84b0-1c5344ecdceb
Feed Name: Dragos Blog
PIPEDREAM, attributed to the CHERNOVITE activity group, is an ICS-focused malware suite capable of manipulating PLCs (including Omron and Schneider Electric devices) and exploiting industrial protocols such as CODESYS, Modbus, and OPC UA to disrupt, degrade, or potentially destroy industrial processes; the report maps behaviors to MITRE ATT&CK for ICS, lists Dragos Platform detections and mitigations, and directs customers to Knowledge Pack KP-2022-004 and a detailed whitepaper for defensive actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
