Threat actor · all actors
ChernoviteMISP-2ce00149 state
🇷🇺 RU
aka Chernovite
Last updated: 2026-08-20
About this actor
Chernovite is a highly capable and sophisticated threat actor group that has developed a modular ICS malware framework called PIPEDREAM. They are known for targeting industrial control systems and operational technology environments, with the ability to disrupt, degrade, and potentially destroy physical processes. Chernovite has demonstrated a deep understanding of ICS protocols and intrusion techniques, making them a significant threat to critical infrastructure sectors.
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
DragosICS mineral names
How we know this
- Data origin
- MISP threat-actor galaxy Imported from the open-source MISP threat-actor galaxy.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- None on file.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty.
See how actor data is built for the full pipeline.
Activity timeline
- 2020 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2020-15368 | 5.5 | 5.5 | 0.1390 | 2020-06-29 | see CVE |
No techniques attributed.
Co-occurring actors
None.
Similar actors
Active in same years
- Crypt32 1.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00