Chernovite

Origin
RU
Primary motivation
sabotage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:08:55

Targeted industries: energy-and-utilities manufacturing

Context

Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for targeting industrial control systems and operational technology environments, with the ability to disrupt, degrade, and potentially destroy physical processes. Chernovite has demonstrated a deep understanding of ICS protocols and intrusion techniques, making them a significant threat to critical infrastructure sectors.

Reports & references

  • dragos.com — Pipedream Mousehole Opcua Module (report)
  • dragos.com — Chernovite Pipedream Malware Targeting Industrial Control Systems (report)
  • dragos.com — The 2022 Ics Ot Vulnerability Briefing Recap (report)
  • dragos.com — Responding To Chernovites Pipedream With Dragos Global Services (report)

External references