Don’t do SECURITY. Do business SECURELY.

Triton malware found targeting industrial safety systems

Researchers revealed Triton, malware built to tamper with industrial safety systems, after an incident at a Middle East facility.

Security firms FireEye and Dragos disclosed Triton (also called Trisis), malware designed to attack safety instrumented systems made by Schneider Electric. It was discovered after it caused an industrial facility in the Middle East to shut down.

What happened

  • Safety instrumented systems are designed to shut down industrial processes safely when dangerous conditions arise.
  • The malware targeted Schneider Electric’s Triconex controllers, and the attack was uncovered when some controllers entered a safe state and halted operations.
  • The victim was later widely reported to be a petrochemical plant in Saudi Arabia.
  • In 2018 FireEye linked the malware to a Russian government-owned research institute, which the US Treasury sanctioned in 2020.

Why it mattered

Triton was the first known malware built to target safety systems, raising the prospect of cyber attacks designed to cause physical harm. Researchers warned that similar techniques could be used against other industrial sectors.

Lessons for organisations

Operators of industrial systems should separate safety systems from other networks, keep controllers in secure modes, and monitor operational technology for unusual activity. Incident response plans for industrial sites should consider how to act safely if safety systems cannot be trusted.

Source: SecurityWeek

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights