Pipedream / Incontroller
Qu'est-ce que Pipedream / Incontroller ?
Pipedream / IncontrollerA modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers.
Pipedream (Dragos) — also called Incontroller (Mandiant) — is a custom ICS attack framework disclosed in a U.S. CISA / DOE / NSA / FBI joint advisory in April 2022. Unlike earlier targeted ICS malware (Stuxnet, Industroyer, Triton) that hit a single victim, Pipedream is a modular toolset designed to enumerate and manipulate large families of industrial controllers — Schneider Electric Modicon PLCs, OMRON Sysmac NEX PLCs, and any OPC UA server — for reconnaissance, configuration change, denial of service, and selective disruption. Its discovery as a fully built capability before observed deployment ('left of boom' in ICS terms) led Dragos to publicly attribute it to a state-aligned actor they track as CHERNOVITE, widely reported as Russia-linked. Pipedream tooling can scan engineering networks for target devices, brute-force credentials, modify ladder logic, disable safety systems, and selectively crash controllers. Defenses focus on robust IT/OT segmentation, removal of internet-exposed engineering interfaces, signed-firmware enforcement, and OT-specific NDR (Dragos Platform, Claroty xDome, Nozomi Guardian) tuned for the framework's documented IOCs.
● Exemples
- 01
A Pipedream module enumerates Schneider Modicon PLCs on an engineering network, reads ladder logic, and stages selective writes to disable safety interlocks.
- 02
An OT defender rules out Pipedream-like access by removing direct internet-exposed Modbus/OPC UA endpoints and putting engineering workstations behind a jump host with phishing-resistant MFA.
● Questions fréquentes
Qu'est-ce que Pipedream / Incontroller ?
A modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers. Cette notion relève de la catégorie OT / ICS / IoT en cybersécurité.
Que signifie Pipedream / Incontroller ?
A modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers.
Comment fonctionne Pipedream / Incontroller ?
Pipedream (Dragos) — also called Incontroller (Mandiant) — is a custom ICS attack framework disclosed in a U.S. CISA / DOE / NSA / FBI joint advisory in April 2022. Unlike earlier targeted ICS malware (Stuxnet, Industroyer, Triton) that hit a single victim, Pipedream is a modular toolset designed to enumerate and manipulate large families of industrial controllers — Schneider Electric Modicon PLCs, OMRON Sysmac NEX PLCs, and any OPC UA server — for reconnaissance, configuration change, denial of service, and selective disruption. Its discovery as a fully built capability before observed deployment ('left of boom' in ICS terms) led Dragos to publicly attribute it to a state-aligned actor they track as CHERNOVITE, widely reported as Russia-linked. Pipedream tooling can scan engineering networks for target devices, brute-force credentials, modify ladder logic, disable safety systems, and selectively crash controllers. Defenses focus on robust IT/OT segmentation, removal of internet-exposed engineering interfaces, signed-firmware enforcement, and OT-specific NDR (Dragos Platform, Claroty xDome, Nozomi Guardian) tuned for the framework's documented IOCs.
Comment se défendre contre Pipedream / Incontroller ?
Les défenses contre Pipedream / Incontroller combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.
Quels sont les autres noms de Pipedream / Incontroller ?
Noms alternatifs courants : Pipedream, Incontroller, CHERNOVITE toolkit.
● Termes liés
- ot-iot№ 587
Système de contrôle industriel (ICS)
Terme générique désignant les systèmes qui automatisent et supervisent des procédés industriels : SCADA, DCS, PLC, RTU et systèmes de sécurité.
- ot-iot№ 1083
SCADA
Systèmes de télégestion et d'acquisition de données qui collectent la télémétrie d'équipements distants et permettent aux opérateurs de surveiller et de piloter de grands procédés.
- ot-iot№ 1229
Stuxnet
Ver très sophistiqué dévoilé en 2010 qui a saboté les centrifugeuses iraniennes d'enrichissement d'uranium en reprogrammant des PLC Siemens, attribué aux États-Unis et à Israël.
- ot-iot№ 588
Industroyer / CrashOverride
Logiciel malveillant ICS modulaire utilisé contre le réseau électrique ukrainien en 2016 et réapparu sous le nom Industroyer2 en 2022, capable de parler les protocoles natifs du réseau.
- ot-iot№ 1297
TRITON / TRISIS
Malware découvert en 2017 ciblant les SIS Triconex de Schneider dans une usine pétrochimique saoudienne, attribué à un acteur lié à la Russie.
- ot-iot№ 850
OPC UA
OPC Unified Architecture, protocole industriel orienté services avec authentification et chiffrement natifs pour échanger des données sémantiques entre OT et IT.