Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →PIPEDREAM (Dragos’s name) and INCONTROLLER (Mandiant’s name) are two names for an industrial-control-system (ICS) toolset publicly analyzed on April 13, 2022. It was built to discover and operate industrial controllers and automation equipment, so it could disrupt processes at facilities that use the relevant protocols. The available reporting did not establish a destructive energy-facility incident. Mandiant judged the toolset very likely state-sponsored but said the evidence connecting it specifically to Russia was circumstantial; Dragos said it had high confidence the toolset had not been used in the wild for destructive effects at the time of its 2022 assessment.
What PIPEDREAM/INCONTROLLER is—and is not
This is best understood as an ICS-oriented toolset rather than a single conventional vulnerability exploit. Its modules use native industrial protocols and device functions to scan environments, enumerate controllers, read or change process data, and perform operations that could disable or reset equipment. The reports describe what the software was capable of doing, not proof that every capability was used against a live target.
Mandiant wrote: “While the targeting of any operational environments using this toolset is unclear, the malware poses a critical risk to organizations leveraging the targeted equipment.” Dragos separately wrote on April 13, 2022: “Dragos assesses with high confidence that PIPEDREAM has not yet been employed in the wild for destructive effects.” That statement is a time-bounded 2022 assessment, not a guarantee about every subsequent year.
The public analyses did not identify a confirmed energy facility that was attacked with PIPEDREAM/INCONTROLLER. They also did not establish that the operators successfully caused a blackout, physical damage, or a process accident.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Why energy and other industrial operators should care
Energy facilities depend on programmable logic controllers (PLCs), servo equipment, engineering workstations, and supervisory systems to keep generation, transmission, storage, and supporting processes within safe limits. A toolset that can authenticate to those systems and issue legitimate protocol commands may be dangerous even when it does not exploit a software flaw.
#1 Best Overall
Dragos assessed that PIPEDREAM could execute 38 percent of known ICS attack techniques and cover 83 percent of known ICS attack tactics. Those are capability-mapping estimates from Dragos’s 2022 analysis—not counts of attacks, probabilities of compromise, or measurements of damage.
Mandiant’s three-tool breakdown
| Component | Reported protocol or target | Reported functions and potential consequence |
|---|---|---|
| TAGRUN | OPC UA servers | Scans servers, enumerates structures and tags, reads or writes tag values, and can brute-force credentials. Unauthorized tag changes could alter process data or control behavior. |
| CODECALL | Modbus and Codesys; Schneider Electric PLCs | Scans for and interacts with controllers, reads and writes registers, and performs device operations that the report says could disconnect, delete files from, or crash a controller. |
| OMSHELL | Omron PLCs through HTTP, Telnet, and FINS | Can activate Telnet, access devices, transfer files, capture traffic, kill processes, and wipe program memory or reset devices. |
These functions were reported for particular equipment and protocols. Mandiant noted that other devices could also be reachable when they implement the relevant protocols. The reporting does not show that every listed operation was carried out against a production asset.
Rank #2
Dragos’s five-component taxonomy
Dragos used a different naming scheme for the same publicly discussed activity. Its five names are not substitutes for Mandiant’s three-tool breakdown; they are separate analytic labels.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
| Dragos name | Role described by Dragos |
|---|---|
| EVILSCHOLAR | Part of the toolset’s ability to enumerate and understand an industrial environment. |
| BADOMEN | Associated with reaching engineering workstations and moving through the operational environment. |
| DUSTTUNNEL | Supports access and movement across industrial zones. |
| MOUSEHOLE | Linked to interaction with process controllers and industrial equipment. |
| LAZYCARGO | Associated with disabling controllers and manipulating logic or programming. |
Dragos’s overall assessment was that the components could enumerate an OT environment, reach engineering workstations, exploit process controllers, cross network zones, disable controllers, and manipulate controller logic or programming. “Could” describes assessed capability, not observed deployment.
Equipment and protocols named in the analyses
| Vendor or technology | Examples named in the reporting | Important qualification |
|---|---|---|
| Schneider Electric Modicon | M251, M258, and M221 PLCs | Examples from the analysis, not a complete list of exposed Schneider product lines. |
| Omron | NX1P2 and NJ501 PLCs; R88D-1SN10F-ECT servo drive | Examples from the analysis, not a complete vulnerability inventory. |
| Industrial protocols | OPC UA, Modbus, Codesys, and Omron FINS | Other devices may be affected if they expose compatible protocol functions. |
Mandiant described the toolset as relying on native functions and did not report it as exploiting Schneider or Omron product vulnerabilities in the conventional CVE-style sense. Protocol exposure, reachable management interfaces, weak credentials, and insufficient separation between IT and OT therefore matter as much as software-patch status.
How strong is the Russia attribution?
Mandiant assessed INCONTROLLER as very likely state sponsored, but it could not associate the toolset with a previously tracked group. Its Russia assessment was explicitly circumstantial: Russia’s history of destructive cyber operations and earlier Russia-nexus activity against ICS provided context, not direct proof of authorship.
Dragos assigned the activity group the name CHERNOVITE. That naming does not establish the group’s national identity or prove that a Russian government organization built or deployed the toolset. “Russia-linked” is therefore a useful description of the assessment context, not a settled attribution finding.
Rank #4
Capability versus confirmed use
| Question | What the public 2022 reporting establishes |
|---|---|
| Could it interact with industrial controllers? | Yes. The modules were designed to scan and issue commands through OPC UA, Modbus, Codesys, HTTP, Telnet, and FINS. |
| Was a specific energy facility named as a confirmed victim? | No such facility was established in the reporting summarized here. |
| Was destructive in-the-wild use confirmed? | No. Dragos said it had high confidence that destructive use had not occurred as of its April 2022 analysis. |
| Was Russia proven to be the operator? | No. Mandiant’s Russia connection was circumstantial, despite its “very likely state sponsored” assessment. |
| Does the 2022 assessment prove the 2026 status? | No. Later use, additional victims, and current exposure require up-to-date incident and vendor intelligence. |
What industrial defenders should do
The recommendations below come from the Mandiant and Dragos 2022 reports. They are defensive priorities, not a substitute for current equipment advisories or a site-specific safety review.
- Inventory the relevant assets. Identify Schneider Modicon M251, M258, or M221 PLCs; Omron NX1P2 or NJ501 PLCs; the named Omron servo drive; OPC UA servers and clients; and systems using Modbus, Codesys, or FINS. Record firmware, management paths, owners, and approved communication partners.
- Separate IT and OT. Enforce segmentation between business networks, engineering workstations, control networks, and safety-related systems. Restrict conduits between zones to documented business and operational requirements.
- Allow only expected devices and commands. Use industrial firewalls with deep-packet inspection where appropriate. Define which hosts may connect to PLCs and which protocol operations are normal for each asset.
- Turn on and review logs. Enable OPC server and client audit logging. Retain authentication, configuration, program-transfer, and controller-event records long enough to investigate an incident.
- Hunt for the behaviors the reports highlight. Investigate irregular OPC UA connections, credential brute forcing, unexpected tag or configuration changes, abnormal Modbus or Codesys traffic, unexpected Telnet activation, and unusual Omron FINS activity.
- Use ICS-aware monitoring. Intrusion-prevention and detection systems should understand industrial protocols and alert on commands that are unusual for the asset, account, time, or operating state.
- Prepare for denial and disruption. Rehearse an incident-response plan that includes loss of controller availability, altered logic, wiped program memory, unsafe process states, and the need to operate equipment manually or from known-good backups.
- Validate changes with operations and vendors. Confirm that firmware, PLC logic, credentials, and remote-access settings match approved configurations, and obtain current vendor guidance for the exact product versions in use.
Government advisory context
A joint CISA, FBI, NSA, and Department of Energy advisory titled “APT Cyber Tools Targeting ICS/SCADA Devices” was published on April 13, 2022 and cited the Mandiant and Dragos analyses. The advisory’s existence places PIPEDREAM/INCONTROLLER in a broader U.S. government warning about advanced persistent-threat tools aimed at ICS and SCADA devices. Current operators should consult the latest government and vendor notices rather than treat a 2022 advisory as a current exposure list.
Best Value
- Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
- ABIS BOOK
- Packt Publishing
What remains unknown
The public reports do not identify the operational environments, if any, in which the toolset was used; a confirmed destructive incident; a conclusively identified operator; or a complete list of affected products. They also do not establish whether capabilities changed after April 2022. Those limits matter when prioritizing risk: the toolset demonstrates a credible ability to disrupt compatible industrial equipment, but a capability demonstration is not evidence that every energy operator was targeted or compromised.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute

