Summary

On 13 April 2022 the U.S. Department of Energy, CISA, NSA and FBI issued advisory AA22-103A on custom tools that give an attacker “full system access” to multiple ICS devices. Dragos calls the toolkit PIPEDREAM and the group behind it CHERNOVITE; Mandiant calls it INCONTROLLER. Targets named in the advisory:

  • Schneider Electric Modicon and Modicon Nano PLCs (including TM251, TM241, M258, M238, LMC058, LMC078);
  • OMRON Sysmac NJ and NX PLCs;
  • OPC UA servers.

Mandiant’s component names describe the modules: TAGRUN (OPC UA scanning and tag reading/writing), CODECALL (Modbus and Codesys-based devices) and OMSHELL (OMRON). A Windows component installs a known-vulnerable ASRock motherboard driver (AsrDrv103.sys, CVE-2020-15368) to execute code in the kernel. The toolkit can scan, brute-force credentials, upload and download PLC logic, and send commands.

What makes this case unusual is timing: it was found before it was used to disrupt anything. That gave defenders a rare head start.

Apa maksudnya untuk Malaysia? 🇲🇾

PIPEDREAM is cross-industry by design. It targets general-purpose automation platforms and the OPC UA standard rather than one plant. If your estate includes Schneider Electric Modicon or OMRON Sysmac PLCs, Codesys-based controllers or OPC UA servers, the advisory’s mitigations apply directly:

  • Put PLCs behind segmented, monitored networks with no direct internet or flat-IT reachability.
  • Change default and shared passwords on PLCs and engineering tools, and require MFA for remote access into OT.
  • Use continuous OT monitoring to catch scanning and unexpected program uploads or downloads, which are the toolkit’s core actions.

Details / TTPs (ATT&CK for ICS)

TechniqueNameObserved behavior
T0846Remote System DiscoveryScans for Schneider, OMRON and OPC UA devices
T0888Remote System Information DiscoveryEnumerates device details
T0861Point & Tag IdentificationBrowses and reads OPC UA tags (TAGRUN)
T0845Program UploadPulls logic from PLCs
T0843Program DownloadPushes logic to PLCs
T1692.001Command MessageDirect device commands
T0890Exploitation for Privilege EscalationVulnerable ASRock driver (CVE-2020-15368)

Detection guidance

  • Alert on PLC program upload/download and mode changes from any host that is not an approved engineering workstation.
  • Detect OPC UA browsing of the full address space from new clients.
  • Block or alert on loading of AsrDrv103.sys, and enable Microsoft’s vulnerable-driver blocklist on Windows hosts in OT.

IoCs

Detection signatures and YARA rules are referenced in the CISA advisory; see also the Dragos and Mandiant reports.

References