LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1045: INCONTROLLER

INCONTROLLER is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric and Omron PLCs as well as OPC UA, Modbus, and CODESYS protocols. INCONTROLLER has the ability to discover specific devices, download logic on the devices, and exploit platform-specific vulnerabilities. As of September 2022, some security researchers assessed INCONTROLLER was developed by CHERNOVITE.[1][2][3][4][5]

ICSS1045MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S1045: INCONTROLLER describes [INCONTROLLER](https://attack.mitre.org/software/S1045) is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric and Omron PLCs as well as OPC UA, Modbus, and CODESYS protocols. [INCONTROLLER](https://attack.mitre.org/software/S1045) has the ability to discover specific devices, download logic on the devices, and exploit platform-specific vulnerabilities. As of September 2022, some security researchers assessed [INCONTROLLER](https://attack.mitre.o...

Executive priority

S1045: INCONTROLLER is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S1045: INCONTROLLER by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Engineering Workstation, Field Controller/RTU/PLC/IED, Safety Instrumented System/Protection Relay, Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S1045: INCONTROLLER appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

INCONTROLLER

INCONTROLLER is custom malware that includes multiple modules tailored towards ICS devices and technologies, including Schneider Electric and Omron PLCs as well as OPC UA, Modbus, and CODESYS protocols. INCONTROLLER has the ability to discover specific devices, download logic on the devices, and exploit platform-specific vulnerabilities. As of September 2022, some security researchers assessed INCONTROLLER was developed by CHERNOVITE.[1][2][3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

20 rows
DomainIDNameRelationship / procedure
ICST0846.003Multicast DiscoverySub-technique

INCONTROLLER can perform a UDP multicast scan of UDP port 27127 to identify Schneider PLCs that use that port for the NetManage protocol.[3][5]

ICST0861Point & Tag Identification

INCONTROLLER can remotely read the OCP UA structure from devices.[1]

ICST0869Standard Application Layer Protocol

INCONTROLLER can remotely send commands to a malicious agent uploaded on Omron PLCs over HTTP or HTTPS.[1]

ICST0886Remote Services

INCONTROLLER can use the CODESYS protocol to remotely connect to Schneider PLCs and perform maintenance functions on the device.[5]

INCONTROLLER can use Telnet to upload payloads and execute commands on Omron PLCs. [2][3] The malware can also use HTTP-based CGI scripts (e.g., cpu.fcgi, ecat.fcgi) to gain administrative access to the device.[5]

ICST0884Connection Proxy

The INCONTROLLER PLCProxy module can add an IP route to the CODESYS gateway running on Schneider PLCs to allow it to route messages through the PLC to other devices on that network. This allows the malware to bypass firewall rules that prevent it from directly communicating with devices on the same network as the PLC.[5]

ICST0836Modify Parameter

INCONTROLLER can use the HTTP CGI scripts on Omron PLCs to modify parameters on EtherCat connected servo drives.[5]

ICST0858Change Operating Mode

INCONTROLLER can establish a remote HTTP connection to change the operating mode of Omron PLCs.[3][5]

ICST0843.001Download AllSub-technique

INCONTROLLER can modified program logic on Omron PLCs using either the program download or backup transfer functions available through the HTTP server.[5]

ICST0859Valid Accounts

INCONTROLLER can brute force password-based authentication to Schneider PLCs over the CODESYS protocol (UDP port 1740).[1]

INCONTROLLER can perform brute force guessing of passwords to OPC UA servers using a predefined list of passwords.[1][5]

ICST0846Remote System Discovery

INCONTROLLER can use the FINS (Factory Interface Network Service) protocol to scan for and obtain MAC address associated with Omron devices.[1][5]

ICST0843Program Download

INCONTROLLER has used the CODESYS protocol to download programs to Schneider PLCs.[5][2] INCONTROLLER has also modified program logic on Omron PLCs using either the program download or backup transfer functions available through the HTTP server.[5]

ICST0888Remote System Information Discovery

INCONTROLLER includes a library that creates Modbus connections with a device to request its device ID.[1][5]

ICST0867Lateral Tool Transfer

INCONTROLLER can use a Telnet session to load a malware implant on Omron PLCs.[1][5]

ICST0846.001Port ScanSub-technique

INCONTROLLER has the ability to perform scans for TCP port 4840 to identify devices running OPC UA servers.[5]

ICST0845Program Upload

INCONTROLLER can use the CODESYS protocol to upload programs from Schneider PLCs.[5][2]

INCONTROLLER can obtain existing program logic from Omron PLCs by using either the program upload or backup functions available through the HTTP server.[5]

ICST0890Exploitation for Privilege Escalation

INCONTROLLER has the ability to exploit a vulnerable Asrock driver (AsrDrv103.sys) using CVE-2020-15368 to load its own unsigned driver on the system.[5]

ICST0842Network Sniffing

INCONTROLLER can deploy Tcpdump to sniff network traffic and collect PCAP files.[5]

ICST0809Data Destruction

INCONTROLLER can wipe the memory of Omron PLCs and reset settings through the remote HTTP service.[2][3][5]

ICST1694.002Hardcoded CredentialsSub-technique

INCONTROLLER can login to Omron PLCs using hardcoded credentials, which is documented in CVE-2022-34151.[5]

ICST1692.001Command MessageSub-technique

INCONTROLLER can send custom Modbus commands to write register values on Schneider PLCs.[1]

INCONTROLLER can send write tag values on OPC UA servers.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.1
Created
Modified
Raw hash
e6e2b39159f48555...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.1Current bundlee6e2b39159f4…
19.11.1Older bundlee6e2b39159f4…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA-AA22-103A

    DHS/CISA. (2022, May 25). Alert (AA22-103A) APT Cyber Tools Targeting ICS/SCADA Devices. Retrieved September 28, 2022.

    Open source URL
  2. [2]
    Brubaker-Incontroller

    Nathan Brubaker, Keith Lunden, Ken Proska, Muhammad Umair, Daniel Kapellmann Zafra, Corey Hildebrandt, Rob Caldwell. (2022, April 13). INCONTROLLER: New State-Sponsored Cyber Attack Tools Target Multiple Industrial Control Systems. Retrieved September 28, 2022.

    Open source URL
  3. [3]
    Dragos-Pipedream

    DRAGOS. (2022, April 13). Pipedream: Chernovite’s Emerging Malware Targeting Industrial Control Systems. Retrieved September 28, 2022.

    Open source URL
  4. [4]
    Schneider-Incontroller

    Schneider Electric. (2022, April 14). Schneider Electric Security Bulletin: “APT Cyber Tools Targeting ICS/SCADA Devices” . Retrieved September 28, 2022.

    Open source URL
  5. [5]
    Wylie-22

    Jimmy Wylie. (2022, August). Analyzing PIPEDREAM: Challenges in Testing an ICS Attack Toolkit. Defcon 30.

    Open source URL
  6. [6]
    PIPEDREAM

    (Citation: Dragos-Pipedream)(Citation: Wylie-22)

  7. [7]
    mitre-attackS1045
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.