TsNIIKhM, the Central Scientific Research Institute of Chemistry and Mechanics, is a Russian government-controlled research institution assessed to support the Russian armed forces with advanced research, weapons, and cyber capabilities. In cyber threat reporting it is associated with the 2017 TRITON intrusion against a Middle East petrochemical and refining environment and with subsequent activity targeting the global energy sector. A TsNIIKhM employee, Evgeny Viktorovich Gladkikh, has been publicly charged by U.S. authorities for his alleged role in this operation. TsNIIKhM is best known for the deployment of TRITON, also known as TRISIS or HatMan, an industrial malware framework designed to target Schneider Electric Triconex safety instrumented systems. The malware modified controller memory and was intended to interfere with safety functions while appearing to operate normally, creating the potential for unsafe plant conditions, physical damage, environmental impact, and loss of life. In the 2017 incident, the intrusion reportedly involved initial compromise of the victim environment, movement from IT into OT networks, access to safety controllers, and installation of malware on the safety system. Software faults in the malware triggered automatic shutdowns that exposed the operation before its intended effects were achieved. The actor has been linked to compromise of a foreign oil refinery and petrochemical facility in the Middle East, manipulation of industrial safety devices, and later attempts to research and access similar U.S. critical infrastructure environments. Public reporting also states that after the 2017 incident, the operators regained unauthorized access to collect information about the victim’s response. The activity demonstrates a capability set centered on industrial control systems, especially safety instrumented systems, with emphasis on stealthy access, lateral movement, persistence, and post-compromise manipulation of operational technology. TsNIIKhM should be distinguished from the separate FSB-linked Dragonfly or Havex activity that also targeted the energy sector during a similar period. The high-confidence association here is specifically the Russian institute tied to TRITON operations against energy-sector industrial environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian Ministry of Defense-affiliated organization whose employee and co-conspirators allegedly hacked industrial control and operational technology environments at a foreign refinery and attempted to target similar U.S. critical infrastructure using Triton/Trisis malware.
Russian government-controlled research institution attributed with deploying TRITON malware against a petrochemical plant’s safety instrumented system and continuing activity targeting the global energy sector, with capability to compromise ICS/SIS environments and potentially cause physical damage and loss of life.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.