TRITON (TRISIS) Malware
TRITON, also known as TRISIS, is malware discovered in 2017 that targeted Triconex safety instrumented system controllers at an industrial facility, the first publicly known attack designed to compromise industrial safety systems.
TRITON, also known as TRISIS or HatMan, is malware discovered in 2017 that targeted Schneider Electric Triconex safety instrumented system (SIS) controllers at an industrial facility in the Middle East. It is the first publicly known malware designed to attack safety systems, whose role is to bring a process to a safe state when dangerous conditions occur.
The attackers gained access to the plant's network, reached the SIS engineering workstation and attempted to reprogram the safety controllers with malicious code using the Triconex communication protocol. An error in the attack caused some controllers to enter a safe failure state, shutting down the process, which led to the intrusion being investigated and discovered. Had the attack succeeded, the safety system could have been prevented from responding to a hazardous event.
TRITON shows why safety systems must be protected as a separate, tightly controlled zone, why physical key switches on safety controllers should stay in the run position except during authorised work, and why engineering access to safety systems needs strict control and monitoring. IEC 61511 requires a security risk assessment for safety instrumented systems, and TRITON illustrates why. Work on safety systems remains governed by the OEM documentation, functional safety standards and qualified personnel.
Key points
- Discovered in 2017 after it caused safety controllers to trip a plant
- Targeted Schneider Electric Triconex safety instrumented system controllers
- Attackers reached the controllers through a safety engineering workstation
- Shows why safety systems need separate zones and controlled programming access
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- Safety and Security InterplayOT & Industrial Cybersecurity
- Engineering Workstation SecurityOT & Industrial Cybersecurity
- Controller Write ProtectionOT & Industrial Cybersecurity
- Zones and ConduitsOT & Industrial Cybersecurity
- OT Incident ResponseOT & Industrial Cybersecurity
- StuxnetOT & Industrial Cybersecurity