PIPEDREAM
PIPEDREAM / INCONTROLLER
PIPEDREAM (INCONTROLLER)
PIPEDREAM (referred to by Mandiant as INCONTROLLER) is a modular toolkit discovered in 2022 for attacking industrial control systems. Unlike earlier ICS malware, it is not tailored to a single facility but designed as a reusable construction kit against widely used devices. It is regarded as the seventh known ICS-specific malware.
History & facts. PIPEDREAM was identified by Dragos in early 2022; on 13 April 2022 Cybersecurity and Infrastructure Security Agency (USA) (CISA), FBI, NSA and the United States of America (US) Department of Energy warned jointly. The kit can address widely used controllers (including from Schneider Electric and Omron) as well as OPC Unified Architecture (OPC UA) servers and additionally uses a vulnerability in a Windows driver (Common Vulnerabilities and Exposures (CVE)-2020-15368). According to analyses it covers a substantial portion of the known Industrial Control Systems (ICS) attack techniques. It was developed by the group CHERNOVITE (Activity Group) (CHERNOVITE); according to the analysts it was not yet deployed destructively „in the wild“ but discovered in advance.
Outlook & recommendation. What is special and disturbing about PIPEDREAM is its scalability: a reusable, device-generic toolkit considerably lowers the barrier for future attacks. Defence here means broadly monitoring behaviour against the MITRE MITRE ATT&CK for Industrial Control Systems (ATT&CK for ICS) matrix, checking OPC Unified Architecture (OPC UA) and Programmable Logic Controller (PLC) communication for anomalies and strictly securing engineering access. That the toolkit was discovered before deployment was a rare advantage — it should be used for preparation.