logo

Pipedream ICS malware toolkit is a nightmare

ID: dca2d939-7f74-5531-94cf-7a833d3dbec2

STIX ID: report--dca2d939-7f74-5531-94cf-7a833d3dbec2

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-05-09

Date Updated: 2026-03-24

Author: Luke Davis

...
...

This report outlines Pipedream (INCONTROLLER), a modular ICS malware framework attributed to the CHERNOVITE group that enables enumeration and interaction with industrial devices via Modbus, OPC UA, HTTP, and OEM tooling like CodeSys without relying on software exploits, drawing comparisons to Triton, Industroyer, and Stuxnet. It also notes the rise of ransomware against industrial entities (including the PSI Software incident) and lessons from Colonial Pipeline, emphasizing that OT impacts often originate from compromised Windows systems and recommending regular off-network compromise assessments to bolster OT resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.