Pipedream / Incontroller
Pipedream / Incontroller とは何ですか?
Pipedream / IncontrollerA modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers.
Pipedream (Dragos) — also called Incontroller (Mandiant) — is a custom ICS attack framework disclosed in a U.S. CISA / DOE / NSA / FBI joint advisory in April 2022. Unlike earlier targeted ICS malware (Stuxnet, Industroyer, Triton) that hit a single victim, Pipedream is a modular toolset designed to enumerate and manipulate large families of industrial controllers — Schneider Electric Modicon PLCs, OMRON Sysmac NEX PLCs, and any OPC UA server — for reconnaissance, configuration change, denial of service, and selective disruption. Its discovery as a fully built capability before observed deployment ('left of boom' in ICS terms) led Dragos to publicly attribute it to a state-aligned actor they track as CHERNOVITE, widely reported as Russia-linked. Pipedream tooling can scan engineering networks for target devices, brute-force credentials, modify ladder logic, disable safety systems, and selectively crash controllers. Defenses focus on robust IT/OT segmentation, removal of internet-exposed engineering interfaces, signed-firmware enforcement, and OT-specific NDR (Dragos Platform, Claroty xDome, Nozomi Guardian) tuned for the framework's documented IOCs.
● 例
- 01
A Pipedream module enumerates Schneider Modicon PLCs on an engineering network, reads ladder logic, and stages selective writes to disable safety interlocks.
- 02
An OT defender rules out Pipedream-like access by removing direct internet-exposed Modbus/OPC UA endpoints and putting engineering workstations behind a jump host with phishing-resistant MFA.
● よくある質問
Pipedream / Incontroller とは何ですか?
A modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers. サイバーセキュリティの OT / ICS / IoT カテゴリに属します。
Pipedream / Incontroller とはどういう意味ですか?
A modular ICS-attack toolkit disclosed by U.S. CISA, Dragos, and Mandiant in April 2022 — attributed by some to a Russian state actor — capable of discovering and disrupting Schneider Electric, OMRON, and OPC UA-based industrial controllers.
Pipedream / Incontroller はどのように機能しますか?
Pipedream (Dragos) — also called Incontroller (Mandiant) — is a custom ICS attack framework disclosed in a U.S. CISA / DOE / NSA / FBI joint advisory in April 2022. Unlike earlier targeted ICS malware (Stuxnet, Industroyer, Triton) that hit a single victim, Pipedream is a modular toolset designed to enumerate and manipulate large families of industrial controllers — Schneider Electric Modicon PLCs, OMRON Sysmac NEX PLCs, and any OPC UA server — for reconnaissance, configuration change, denial of service, and selective disruption. Its discovery as a fully built capability before observed deployment ('left of boom' in ICS terms) led Dragos to publicly attribute it to a state-aligned actor they track as CHERNOVITE, widely reported as Russia-linked. Pipedream tooling can scan engineering networks for target devices, brute-force credentials, modify ladder logic, disable safety systems, and selectively crash controllers. Defenses focus on robust IT/OT segmentation, removal of internet-exposed engineering interfaces, signed-firmware enforcement, and OT-specific NDR (Dragos Platform, Claroty xDome, Nozomi Guardian) tuned for the framework's documented IOCs.
Pipedream / Incontroller からどのように防御しますか?
Pipedream / Incontroller に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Pipedream / Incontroller の別名は何ですか?
一般的な別名: Pipedream, Incontroller, CHERNOVITE toolkit。
● 関連用語
- ot-iot№ 587
産業用制御システム (ICS)
産業プロセスを自動化・監視するシステムの総称で、SCADA、DCS、PLC、RTU、安全制御システムなどを含む。
- ot-iot№ 1083
SCADA
遠隔のフィールド機器からテレメトリを収集し、運転員が広域な工業プロセスを監視・操作できるようにする監視制御・データ収集システム。
- ot-iot№ 1229
Stuxnet
2010 年に明らかになった高度なワーム。Siemens 製 PLC を再プログラムしてイランのウラン濃縮遠心分離機を破壊し、米国とイスラエルの関与が広く指摘されている。
- ot-iot№ 588
Industroyer / CrashOverride
2016 年のウクライナ電力網攻撃で使用され、2022 年に Industroyer2 として更新されたモジュール型 ICS マルウェア。電力網のネイティブプロトコルを話し変電所を遮断できる。
- ot-iot№ 1297
TRITON / TRISIS
2017 年にサウジアラビアの石油化学プラントで発見された、Schneider 製 Triconex 安全計装システムを標的とするマルウェア。ロシア関連のアクターに帰属とされる。
- ot-iot№ 850
OPC UA
OPC 統一アーキテクチャ。認証と暗号化を組み込んだサービス指向の産業プロトコルで、OT と IT の間で意味づけされたデータを交換する。