{"uid":"cap_k5ZX-4bFnVq4O93zYkhvg","slug":"ot-intel-api-ics-malware-encyclopedia-8ea8ee79","name":"OT Intel API — ICS Malware Encyclopedia","description":"ICS malware encyclopedia. Pass ?name=PIPEDREAM. Returns capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques. Covers PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY.","url":"https://ot-intel-api.onrender.com/ot/malware","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","description":"Malware name e.g. PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"name":"PIPEDREAM","aliases":["INCONTROLLER"],"confidence":"high","first_seen":"2022","capabilities":["discovery","lateral_movement","disruption","destruction"],"data_sources":["Dragos-Threat-Intelligence","OT-Intel-DB","MITRE-ATT&CK-ICS","DeepSeek-CTI-Analysis"],"affected_vendors":["Schneider Electric","OMRON"],"attributed_actor":"CHERNOVITE","mitre_techniques":["T0843","T0821","T0855"],"targeted_protocols":["Modbus","OPC UA","CODESYS","IEC 61850"],"detection_signatures":["YARA rule: PIPEDREAM_loader","Anomalous CODESYS write commands"]}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"name":"PIPEDREAM"}}},"response":{"name":"PIPEDREAM","aliases":["INCONTROLLER"],"freshness":"2026-06-16T17:38:06.064Z","confidence":"high","first_seen":"2022","capabilities":["discovery","lateral_movement","disruption","destruction","persistence"],"data_sources":["OT-Intel-DB","MITRE-ATT&CK-ICS","DeepSeek-CTI-Analysis","Dragos-Threat-Intelligence"],"affected_vendors":["Schneider Electric","Omron","CoDeSys"],"attributed_actor":"CHERNOVITE","mitre_techniques":["T0843","T0846","T0851","T0853","T0856","T0869","T0871","T0883","T0888","T0890"],"targeted_protocols":["FINS","Modbus","CoDeSys","OPC UA"],"detection_signatures":["PIPEDREAM_Omron_FINS_Scan","PIPEDREAM_Schneider_Modbus_Write","PIPEDREAM_CoDeSys_Exploit","PIPEDREAM_OPCUA_Discovery"]}},"exampleRequest":{"name":"PIPEDREAM"},"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ENbdRzId9SgVxFLt8A-6m","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns detailed intelligence on named ICS/OT malware including capabilities, targeted OT protocols, attributed actor, affected vendors, detection signatures, and MITRE ATT&CK ICS techniques.","exampleAgentPrompt":"Can you pull up the full intelligence profile for PIPEDREAM malware — I need its capabilities, which OT protocols it targets, who the attributed actor is, affected vendors, detection signatures, and the MITRE ATT&CK ICS techniques associated with it?","exampleUseCases":null,"resultDescription":"A structured record for the queried ICS malware including: a description of its capabilities, the OT/ICS protocols it targets (e.g. Modbus, OPC-UA, IEC-104), the attributed threat actor or group, a list of affected vendors, detection signatures, and the associated MITRE ATT&CK for ICS technique IDs and names.","failureModes":["Unknown malware name returns 404 or empty result — only PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, and BLACKENERGY are supported","Missing required 'name' query parameter returns 400 Bad Request","Payment not processed results in 402 Payment Required","Service temporarily unavailable on Render cold start causes slow or failed response"],"whenToPreferThis":"Use this endpoint when you need encyclopedic, structured intelligence on a specific named ICS/OT malware family — particularly one of the six covered entries (PIPEDREAM, TRITON, INDUSTROYER2, CRASHOVERRIDE, FROSTYLOOP, BLACKENERGY). Prefer this over generic CVE or IOC endpoints when the query is about malware behavior, protocol targeting, or actor attribution in industrial control system contexts.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:30:52.474Z","isFirstParty":false}