PIPEDREAM Malware Targets a Wide Range of Industrial Control Systems
Industrial Control Systems (ICS) is a term used to describe the collection of systems, networks, and devices used to automate certain industrial processes. Typically, ICS use highly specialized software and tooling, which is an attractive target for cybercriminals who are looking to execute attacks against specific industries. ICS systems find use in various industries like transportation, energy, and manufacturing. In recent reports, Russian hackers have been employing the Indestroyer2 Malware to take down ICS in Ukraine. However, it seems that another malware family target that ICS has been identified in other parts of the world – PIPEDREAM.
The PIPEDREAM Malware is a pretty unique case when it comes to threats targeting ICS devices. Due to the nature of these high-profile attacks, researchers usually come across the malware families after the attack has been completed. However, the PIPEDREAM Malware was captured before it managed to take part in any attacks. This gives potential targets the unique opportunity to prepare for such an attack beforehand, and learn how the PIPEDREAM Malware could penetrate their network's defenses.
According to a statement released by the US government, industrial networks can be protected by utilizing multifactor authentication, as well as by ensuring that all ICS/SCADA devices use strong passwords that are rotated on a regular basis.
Otherwise, the purpose of the PIPEDREAM Malware is destruction, and taking down critical networks in the industries it attacks. If the malware's infiltration is successful, it could modify the configuration and behavior of a wide range of logic controllers and industrial software in order to take down the network completely.
ICS threats like the PIPEDREAM Malware are exceptionally dangerous as they have the potential to launch large-scale attacks, which cripple entire industries for extended periods of time – hence why such threats are currently being used in the Russia-Ukraine conflict.








