Skip to main content

2022 · Multiple (energy, manufacturing)

PIPEDREAM / INCONTROLLER

A modular ICS attack toolkit discovered before deployment against a victim environment, capable of interacting with specific controller families and industrial protocols.

Targeting / attempted compromiseNot publicly tied to a specific victim

What happened

Tooling with modules for scanning, interacting with and manipulating certain PLC families, plus components abusing a known-vulnerable driver for privilege escalation on Windows engineering hosts.

Who

Assessed by public reporting as a state-associated capability; no formal attribution in the joint advisory.

Where

Not publicly attributed to a specific victim environment.

Why

Assessed objective: pre-positioning for disruptive effects against industrial operations.

How

Designed to operate from a compromised host with control-network reachability, using native industrial protocols and vendor tooling behaviours rather than a single exploit.

Timeline

  1. Early 2022Capability identified through industry and government collaboration
  2. 13 April 2022Joint advisory published warning ICS/SCADA operators

Attack path

Described at the level required to build detection and controls.

Initial Access

Unknown

Not applicable / not observed publicly

Engineering environment

Assessed

Designed to run on hosts with control-network reach

Control systems

Reported

Modules to enumerate and command specific controllers

Impact

OT impactNo publicly confirmed victim impact — the capability was identified before observed use.
Safety impactPotential; not realised publicly.
Operational impactPrompted broad defensive action across critical infrastructure sectors.
Detected byCollaboration between government agencies and industrial security researchers.

Technology involved

Specific PLC familiesOPC UA serversWindows engineering workstations

ATT&CK techniques

T0846T0855T0843T0858

Vulnerabilities and weaknesses exploited

  • A known-vulnerable Windows driver was reported as part of the privilege escalation component

Control failures

  • Not applicable — no publicly documented victim compromise

Where earlier detection was possible

  • Baselining protocol clients per controller
  • Detecting OPC UA and controller enumeration
  • Engineering workstation execution monitoring

Defensive lessons

  • Protocol-native tooling is now a standing capability, not a novelty
  • Detection must focus on who is talking to controllers, not only on malware signatures
  • Advisory-driven hunts are worth running proactively

Why should I care?

Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.