Security firms FireEye and Dragos disclosed Triton (also called Trisis), malware designed to attack safety instrumented systems made by Schneider Electric. It was discovered after it caused an industrial facility in the Middle East to shut down.
What happened
- Safety instrumented systems are designed to shut down industrial processes safely when dangerous conditions arise.
- The malware targeted Schneider Electric’s Triconex controllers, and the attack was uncovered when some controllers entered a safe state and halted operations.
- The victim was later widely reported to be a petrochemical plant in Saudi Arabia.
- In 2018 FireEye linked the malware to a Russian government-owned research institute, which the US Treasury sanctioned in 2020.
Why it mattered
Triton was the first known malware built to target safety systems, raising the prospect of cyber attacks designed to cause physical harm. Researchers warned that similar techniques could be used against other industrial sectors.
Lessons for organisations
Operators of industrial systems should separate safety systems from other networks, keep controllers in secure modes, and monitor operational technology for unusual activity. Incident response plans for industrial sites should consider how to act safely if safety systems cannot be trusted.
Source: SecurityWeek
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.