APT / THREAT GROUP
INCONTROLLER
3
aliases
Last seen:Mar 17, 2026
Intelligence Profile
INCONTROLLER (aka PIPEDREAM) is a set of tools built to target machine automation devices. The tools can interact with specific industrial equipment embedded in different types of machinery leveraged across multiple industries. This tool set is very likely state sponsored and contains capabilities related to disruption, sabotage, and potentially physical destruction.
Threat Analysis
INCONTROLLER is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
External References
Quick Facts
TypeAPT / Threat Group
Aliases3
Also Known As
INCONTROLLERwin.incontrollerPIPEDREAM
External Intelligence
Malpedia: win.incontrollerResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.