INCONTROLLER
MITRE ATT&CK: S1045 View on attack.mitre.org
Aliases: PIPEDREAM
- Malware type
- exploit-kit
- Family
- Malware family
- Operating systems
- engineering-workstation, field-controller/rtu/plc/ied, safety-instrumented-system/protection-relay, windows
- Profile updated
- 2026-07-07 15:06:54
Targeted industries: energy-and-utilities manufacturing
Context
INCONTROLLER is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric and Omron PLCs as well as OPC UA, Modbus, and CODESYS protocols. INCONTROLLER has the ability to discover specific devices, download logic on the devices, and exploit platform-specific vulnerabilities. As of September 2022, some security researchers assessed INCONTROLLER was developed by CHERNOVITE.
Detection coverage
- 1 YARA rules
Malware & tools used
- Multicast Discovery (attack-pattern)
- Point & Tag Identification (attack-pattern)
- Standard Application Layer Protocol (attack-pattern)
- Remote Services (attack-pattern)
- Command Message (attack-pattern)
- Connection Proxy (attack-pattern)
- Modify Parameter (attack-pattern)
- Change Operating Mode (attack-pattern)
- Download All (attack-pattern)
- Valid Accounts (attack-pattern)
- Remote System Discovery (attack-pattern)
- Program Download (attack-pattern)
- Remote System Information Discovery (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Port Scan (attack-pattern)
- Program Upload (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Network Sniffing (attack-pattern)
- Data Destruction (attack-pattern)
- Hardcoded Credentials (attack-pattern)
Detection rules
- SEKOIA_Implant_Win_Incontroller (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Incontroller (report)
- hub.dragos.com — Dragos Chernovitewp V2B (report)
- Mandiant — Cyber Operations Russian Vulkan (report)
- youtube.com — Watch (report)
- twitter.com — 1514366443277766656 (report)
- Mandiant — Incontroller State Sponsored Ics Tool (report)