What is TRITON?
TRITON, also known as TRISIS or HatMan, is malware discovered in 2017 at a petrochemical plant in Saudi Arabia and the first known attack on a Safety Instrumented System: the system that shuts an installation down safely to prevent explosions, fire or toxic releases. The attackers tried to reprogram the Triconex safety controllers from Schneider Electric. A bug in their code tripped the installation into its safe state instead, which led to the attack being discovered. TRITON is regarded as a turning point, because the attackers appeared willing to put human lives at risk.
๐๏ธ How did the attack unfold?
| When | Event |
|---|---|
| 2014 | Initial access to the plantโs IT network (according to later investigation) |
| June 2017 | Unexpected safety shutdown of a unit; initially taken for a malfunction |
| August 2017 | Second shutdown; incident response by Schneider Electric and Mandiant |
| December 2017 | Public disclosure by FireEye/Mandiant and Dragos |
| October 2020 | US sanctions the Russian research institute CNIIHM for its involvement |
| 2022 | US formally charges an employee of that institute |
๐ง How did TRITON work technically?
- Over several years the attackers moved from the office network through the DMZ into the OT network
- On an engineering workstation for the safety system they planted the malware, disguised as a Triconex diagnostic tool
- The malware communicated with the Tricon controllers via the proprietary TriStation protocol
- It injected a backdoor into the memory of the safety PLC so the logic could later be changed remotely
- A check inside the controller itself detected an anomaly and drove the process to its safe state
Crucially, the controllersโ physical key switch was in the PROGRAM position instead of RUN, which made remote programming possible.
๐ Which ATT&CK techniques did TRITON use?
| Phase | Technique from MITRE ATT&CK for ICS |
|---|---|
| Access | Lateral movement from IT to OT, use of an engineering workstation |
| Execution | Modifying the controller program, program download |
| Persistence | Backdoor in firmware memory |
| Evasion | Disguised as legitimate software (masquerading) |
| Impact | Disabling safety functions (inhibit response function) |
๐ฏ What lessons can you draw from TRITON?
- Separate the safety system from the process control network and from IT; an SIS belongs in its own zone under IEC 62443
- Key switch in RUN โ allow programming only during planned maintenance
- Harden engineering workstations further: application whitelisting, MFA and no internet access
- Monitor for program changes โ a download to a safety controller outside maintenance windows is always suspicious
- Investigate unexplained trips as a possible cyber incident, not only as a technical fault
- Manage functional safety and security together โ IEC 61511 now explicitly requires a security risk assessment of the SIS
๐ง Why is an attack on a safety system so dangerous?
A process installation has several layers of protection. The SIS is the last automatic layer before physical damage:
| Layer | Function | Example |
|---|---|---|
| Process control (DCS/PLC) | Keeps the process within normal limits | Temperature control of a reactor |
| Alarms and operator | Intervenes on deviations | Operator reduces the feed |
| Safety system (SIS) | Automatically shuts down safely when danger arises | Emergency shutdown on overpressure |
| Mechanical protection | Last physical barrier | Relief valve, bursting disc |
| Emergency response | Limits the consequences | Fire brigade, evacuation |
TRITON aimed to disable or manipulate the SIS layer. Combined with a second attack on process control, this could have led to an explosion or a toxic release without the automatic protection intervening. That makes TRITON fundamentally different from attacks that โonlyโ halt production.
โ Frequently asked questions
What is the difference between TRITON and TRISIS?
TRITON and TRISIS are two names for the same malware. FireEye (now Mandiant) called it TRITON, Dragos used the name TRISIS, and the US ICS-CERT referred to it as HatMan. All names refer to the 2017 attack on Triconex safety controllers at a petrochemical plant.
Who was behind the TRITON attack?
FireEye researchers linked the TRITON attack to the Russian Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM). The United States sanctioned the institute in October 2020 and formally charged an employee in 2022. Dragos tracks the group under the name XENOTIME.
Which systems did TRITON attack?
TRITON targeted Schneider Electric Triconex safety controllers, used worldwide in oil, gas and chemical installations, among others. The malware entered through a Windows engineering workstation and communicated with the controllers via the proprietary TriStation protocol. Schneider Electric has since fixed the vulnerabilities.
Could an attack like TRITON happen again?
Yes, the techniques behind TRITON are not specific to one brand. Dragos reported that the group behind TRITON later also probed installations in North America. Any safety system that can be programmed over the network and is not properly isolated faces a similar risk.
What is an SIS and why does it matter?
An SIS, or Safety Instrumented System, is an independent automatic system that shuts a process down safely when it leaves safe limits, for example on excessive pressure or temperature. The SIS is designed in line with IEC 61511 and forms the last automatic defence against explosions, fire and toxic releases.
๐ In summary
TRITON (TRISIS) was, in 2017, the first malware to attack a safety system, aiming to disable the last line of defence against physical disasters. The attack shows that safety and security cannot be protected in isolation from each other.
