TRITON/TRISIS Malware attack against Triconex Safety System in Middle East Petrochemical Facility

Incident Impacts Business Disruption, Manipulation of Safety Systems
Affected Sector Energy, Utilities
Associated Intrusion Sets XENOTIME

In August 2017 the XENOTIME intrusion set compromised a Triconex Safety Instrumented System (SIS) engineering workstation. According to reporting from Dragos and FireEye (Mandiant), the attacker used the TRITON/TRISIS malware to reprogram SIS controllers, causing some to enter a failed safe state and automatically initiate a shutdown of the industrial process.

The US government subsequently linked the attack to the State Research Center of the Russian Federation FGUP Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM).

Cyber Threat Graph Context

Explore how this cyber incident relates to the wider threat graph
