logo

CHERNOVITE’s PIPEDREAM Malware Targeting Industrial Control Systems (ICS)

ID: fa5a6aa3-ef84-59af-987c-df6773496f72

STIX ID: report--fa5a6aa3-ef84-59af-987c-df6773496f72

Feed Name: Dragos Blog

Threat Score
78/100

Date Published: 2022-04-13

Date Updated: 2026-04-27

...
...

PIPEDREAM is a sophisticated, modular ICS malware toolkit attributed to the CHERNOVITE group that can manipulate PLCs and industrial software (including Omron, Schneider, CODESYS, Modbus, and OPC UA). Dragos reports the toolkit can execute 38% of known ICS attack techniques and 83% of ICS attack tactics, contains five major components (EVILSCHOLAR, BADOMEN, DUSTTUNNEL, MOUSEHOLE, LAZYCARGO), and — while highly capable of causing disruption or destruction — has not been observed performing destructive actions in the wild; the report provides detailed defensive mitigations and recommendations for ICS operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.