“INCONTROLLER” / “PIPEDREAM” ICS Toolkit Targeting Energy Sector
ID: 841b961b-c057-59e9-8043-c5651ff12a6a
STIX ID: report--841b961b-c057-59e9-8043-c5651ff12a6a
Feed Name: Kudelski Security
Threat Score
This advisory analyzes Incontroller/Pipedream — a modular toolkit attributed to a suspected state-sponsored actor (“Chernovite”) targeting electric and gas OT environments. The toolkit enables discovery, credential brute-forcing, PLC manipulation (Schneider, Omron), OPC UA access, PLC implants, and uses an ASRock driver exploit (CVE-2020-15368) for privilege escalation; no confirmed in-the-wild destructive deployments are reported, and detection/mitigation guidance is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
