What is PIPEDREAM?

PIPEDREAM, called INCONTROLLER by Mandiant, is a modular attack toolkit against industrial controllers that was disclosed in April 2022, before it had been deployed against a victim. The toolkit can attack PLCs from Schneider Electric and Omron as well as OPC UA servers, targeting technology used in thousands of plants. Dragos attributes the toolkit to the group CHERNOVITE; its development is widely attributed to a state actor. It is the seventh known ICS-specific malware, after Stuxnet, Industroyer and TRITON, among others.


πŸ—“οΈ How was PIPEDREAM discovered?

Date Event
Early 2022 Dragos and Mandiant analyse the toolkit, together with governments and vendors
13 April 2022 Joint advisory from CISA, DOE, NSA and FBI (AA22-103A)
April 2022 Dragos (PIPEDREAM) and Mandiant (INCONTROLLER) publish their analyses

The fact that the toolkit was found before deployment makes PIPEDREAM unique: for the first time, defenders had the chance to act before any damage was done.


πŸ”§ What modules does PIPEDREAM consist of?

Module Target Capabilities
EVILSCHOLAR Schneider Modicon M221, M251, M258 (via CODESYS) Scanning, cracking passwords, modifying programs
BADOMEN Omron NX/NJ controllers and servo drives Uploading programs, manipulating drives
MOUSEHOLE OPC UA servers Reconnaissance and reading/writing values
Windows component Engineering workstations Abusing a vulnerable driver to gain administrator rights

Notably, the toolkit mainly uses legitimate functions of the protocols, such as upload, download and writing values, rather than software bugs. Patching alone therefore does not help.


πŸ” What could PIPEDREAM do?

  • Modify or delete PLC programs, causing a process to stop or behave unsafely
  • Bypass safety settings and drive servomotors beyond their limits
  • Break network connections and take away operators’ view of the process
  • Cause denial of service on controllers

Because CODESYS is used by hundreds of manufacturers, the impact reaches far beyond Schneider Electric.


🎯 What lessons can you draw from PIPEDREAM?

  • Know your assets β€” know which PLCs, firmware versions and OPC UA servers you have
  • Network segmentation β€” engineering access to PLCs only from a separate, controlled zone
  • OT-specific network monitoring β€” detect program downloads and write commands outside maintenance windows
  • MFA and a jump server for all remote access
  • Offline backups of PLC programs to recover quickly
  • An OT incident response plan β€” rehearse the scenario in which controllers can no longer be trusted

🧠 Why is PIPEDREAM so widely applicable?

Earlier ICS malware was usually custom-built for one installation. PIPEDREAM is a toolkit that can be used against many installations at once:

Characteristic Earlier ICS malware PIPEDREAM
Target One specific installation Entire product families
Approach Custom-built per attack Reusable modules
Method Often vulnerabilities Mainly legitimate protocol functions
Sectors One sector Energy, oil & gas, manufacturing, water

The abuse of CODESYS is crucial: CODESYS is used as a runtime by hundreds of PLC manufacturers. Whoever masters CODESYS communication can therefore potentially address devices from many brands. OPC UA is also used in virtually every modern installation, which makes the MOUSEHOLE module widely usable for reconnaissance.


❓ Frequently asked questions

What is the difference between PIPEDREAM and INCONTROLLER?

PIPEDREAM and INCONTROLLER are two names for the same attack toolkit. Dragos called the toolkit PIPEDREAM, Mandiant used the name INCONTROLLER. Both companies published their analyses in April 2022, at the same time as a joint advisory from US government agencies.

Has PIPEDREAM ever been used in an attack?

There are no publicly confirmed attacks in which PIPEDREAM caused damage. The toolkit was discovered and shared before it had been deployed against a victim. That makes PIPEDREAM unique among ICS malware: defenders could use the knowledge to prepare detection rules and measures.

Which PLCs are vulnerable to PIPEDREAM?

PIPEDREAM specifically targets Schneider Electric Modicon M221, M251 and M258 controllers, Omron NX and NJ controllers, and OPC UA servers. Because the toolkit uses CODESYS communication, PLCs from other manufacturers with a CODESYS runtime may also be at risk.

Does patching help against PIPEDREAM?

Patching only partly helps against PIPEDREAM, because the toolkit mainly uses legitimate functions, such as uploading and downloading PLC programs. More effective are network segmentation, restricting engineering access, controller passwords and OT monitoring that detects unusual program changes.

Who developed PIPEDREAM?

The developer of PIPEDREAM has not been officially named. Dragos tracks the group as CHERNOVITE and assesses the toolkit as the work of a state actor, given the scale, complexity and cost of its development. Mandiant described the activity as consistent with Russian interests, without a firm attribution.

What is CODESYS and why does it matter for PIPEDREAM?

CODESYS is a vendor-neutral development environment and runtime for IEC 61131-3 PLC programs, built into the controllers of hundreds of manufacturers. PIPEDREAM uses CODESYS communication to address Schneider Electric controllers. As a result, other devices with a CODESYS runtime may also be at risk, which makes it important to follow CODESYS updates and hardening advice.

Which sectors were most at risk from PIPEDREAM?

PIPEDREAM posed the greatest risk to energy companies, in particular liquefied natural gas and electricity, but the targeted controllers and OPC UA servers are found in virtually every sector. Water utilities, the process industry and discrete manufacturing also use Schneider Electric and Omron controllers. Advisory AA22-103A therefore urged all sectors to take action.


πŸ“Œ In summary

PIPEDREAM (INCONTROLLER) is a modular state-built attack toolkit against Schneider Electric and Omron PLCs and OPC UA servers, found in 2022 before it was deployed. It abuses legitimate protocol functions, which makes segmentation, monitoring and access control more important than patching.