TRITON, also known as TRISIS and HatMan, is ICS-specific malware designed to target Schneider Electric Triconex Safety Instrumented Systems (SIS), particularly Tricon controllers using vulnerable firmware in the Tricon MP3008 family. It is the first publicly documented malware built to directly interact with and compromise an industrial safety system, with the objective of impairing the last automated layer intended to place a plant into a safe state during hazardous conditions.
The malware was deployed in 2017 against a petrochemical facility in the Middle East and caused automatic emergency shutdowns after faults exposed the intrusion. Public U.S. government attribution linked the operation to actors associated with Russia’s Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM). The activity is widely associated with the XENOTIME intrusion set. TRITON has also been referenced in U.S. criminal indictments concerning attacks on a foreign refinery and attempted follow-on targeting of similar infrastructure.
TRITON was engineered to communicate with Triconex controllers using the proprietary TriStation protocol and to modify controller memory and in-memory firmware to add malicious functionality. Recovered components included a Python-based dropper masquerading as legitimate Triconex engineering software, supporting Python modules implementing controller communications, and shellcode and payload components used to inject code into SIS controllers. Its design enabled remote interaction with, and potentially complete remote control over, targeted safety controllers. Successful operation could prevent safety functions from working correctly while making the system appear normal, creating the possibility of unsafe operating conditions, physical equipment damage, environmental consequences, and loss of life.
Deployment required substantial prior access to the victim environment. Reporting indicates the operators first compromised enterprise systems, moved laterally into OT networks, and then reached the SIS environment. Successful payload deployment required access to the safety network and conditions permitting controller programming. TRITON also employed masquerading for defense evasion by presenting itself as legitimate Triconex-related software.
The malware is narrowly tailored rather than broadly opportunistic. It targeted specific controller models and firmware versions and relied on deep knowledge of industrial safety engineering and controller internals. Its discovery prompted vendor mitigations, firmware updates, and heightened focus on isolating SIS networks, restricting engineering access, and monitoring for unauthorized controller interaction. TRITON remains a landmark example of malware intended to manipulate industrial safety systems for disruptive or destructive effect.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states. CVE-2018-7522 has been assigned to this vulnerability. | These vulnerabilities were discovered by NCCIC and Schneider Electric during the investigation of the HatMan malware.
System calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory. CVE-2018-8872 has been assigned to this vulnerability. | These vulnerabilities were discovered by NCCIC and Schneider Electric during the investigation of the HatMan malware.
select communication modules by Rockwell Automation in specific ControlLogix EtherNet/IP (ENIP) communication module models, 1756-EN2, 1756-EN3 (CVE-2023-3595)... Both CVE-2023-3595 and CVE-2023-3596 exist inside the devices’ Common Industrial Protocol (CIP) implementation and allow remote code execution with persistence on the EN2* and EN3* modules... CVE-2023-3595 allows for arbitrary manipulation of firmware memory
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragos Inc.: TRISIS Malware: Analysis of Safety System Targeted Malware ... Mandiant: Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructure
TRITON malware (also known as TRISIS and HatMan) was used against a Middle East–based petrochemical facility’s safety controllers. TRITON malware was designed to target a specific SIS controller model... used in critical infrastructure facilities to initiate immediate shutdown procedures in the event of an emergency.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Another key finding in the leak is confirmation of the existence of another delivery vector called 'Triton', which can target devices with Samsung Exynos with baseband exploits, forcing 2G downgrades to lay the ground for infection.
"Once on the SIS network, the attacker used their pre-built TRITON attack framework to interact with the SIS controllers using the TriStation protocol."
35 distinct techniques documented for this family, organized by ATT&CK tactic.
The dropper was developed in Python and compiled inside the trilog.exe executable.
Soon after the execution, the dropper connected to the targeted Triconex, injecting the real malware payload inside its memory.
reg add " ... HKLM\ ... Software\Microsoft\Windows\CurrentVersion\Policies\System ... " /v EnableLUA /t REG_DWORD /d 0 /f
Component Firmware (T1542.002, Persistence/Defense Evasion) : модификация прошивки контроллера - наиболее серьёзный сценарий, реализованный в атаке TRITON/TRISIS группировкой XENOTIME
One of the actions taken by the dropper was to read, inject and execute these files into the memory of the Triconex.
imain.bin contained the final code that allows a remote user to gain full control of the SIS device.
Existing vulnerabilities in industrial equipment often allow threat groups to install persistent rootkits... Siemens disclosed a vulnerability in its PLC... may overwrite core PLC functions with a rootkit.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
TRITON malware’s design gave the attackers complete remote control of the SIS, providing them the capability to cause significant physical damage and loss of life if the plant were to enter an unsafe state. | In the 2017 attack, the actor gained initial access and then moved laterally through the information technology (IT) and operational technology (OT) networks onto the safety system and installed TRITON malware.
Decoded strings (some, not everything): ... [VK_END] ... Password: ... username=.*&password=.* ... auth-attr-\d+-param1=(.*)&auth-attr-\d+-param2=([^&]*)
&scrn=1 ... Statistics: Active bots with smartcard: Screenshots (SR): ... A screenshot took by the bot
Another water utility serving 2 million people in North Texas said Tuesday that it is also dealing with a cybersecurity incident that caused operational issues...
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS malware referenced as an example of targeted sabotage causing physical process impact by manipulating industrial control systems.
ICS malware referenced as a classic energy-sector cyberattack example involving compromise of OT/safety-related infrastructure.
ICS malware associated with attacks on safety instrumented systems in industrial environments; mentioned here as historical precedent for physical-impact OT attacks.
ICS malware associated with attacks on safety instrumented systems in petrochemical environments; mentioned as historical context for OT impact.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.