Power Grid

Pipedream/Incontroller — ICS attack toolkit disclosure

Disclosed 13 April 2022

United States (capability disclosure; LNG and electric targets reported)

What happened

DOE, CISA, NSA and the FBI jointly warned that state-linked actors had built a modular attack toolkit — called Pipedream by Dragos, which tracks the developer as Chernovite, and Incontroller by Mandiant — capable of scanning, compromising and controlling Schneider Electric and Omron PLCs and OPC UA servers, plus a Windows kernel exploit via a vulnerable ASRock driver. Reporting indicated the tools were positioned toward US LNG and electric targets but were discovered before being employed in a disruptive attack. No public attribution to a specific state has been made. This is a capability record rather than an executed attack; the marker is a country-level reference.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Reported / attributed
Confidence
Moderate
Infrastructure
Power Grid
Latitude
35.5000°
Longitude
-95.0000°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. APT Cyber Tools Targeting ICS/SCADA Devices (AA22-103A)CISA, DOE, NSA and FBI joint advisory · Incident reporting