TRITON, also known as TRISIS and HatMan, is an industrial control system attack framework targeting Schneider Electric Triconex Tricon safety instrumented systems. It is designed to manipulate controller memory and in-memory firmware, impairing safety functions while making the systems appear to operate normally. Its Python-based TsLow module discovers controllers using the TriStation protocol. It also masquerades as the legitimate Triconex Trilog application and attempts to write a dummy program into controller memory if a reset fails.
TRITON targets memory-handling vulnerabilities CVE-2018-8872 and CVE-2018-7522 in Tricon MP Model 3008 controllers running firmware versions 10.0–10.4. These flaws permit attacker-controlled memory writes and supervisor-level access, enabling arbitrary code execution and manipulation of system states. Successful payload deployment requires unrestricted access to the safety network, through remote or physical access, and the controller key switch to be in PROGRAM mode.
TRITON was deployed against a Saudi Arabian petrochemical facility in 2017. The deployment caused faults that triggered two automatic emergency shutdowns, rather than successfully suppressing the facility’s protective functions. The operation is associated with XENOTIME, also tracked as TEMP.Veles, and Russian actors linked to TsNIIKhM, a research institute affiliated with Russia’s Ministry of Defense. Its targeting of industrial safety systems creates the potential for unsafe physical conditions in critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states.
System calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory.
select communication modules by Rockwell Automation in specific ControlLogix EtherNet/IP (ENIP) communication module models, 1756-EN2, 1756-EN3 (CVE-2023-3595)... Both CVE-2023-3595 and CVE-2023-3596 exist inside the devices’ Common Industrial Protocol (CIP) implementation and allow remote code execution with persistence on the EN2* and EN3* modules... CVE-2023-3595 allows for arbitrary manipulation of firmware memory
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
XENOTIME, the group behind the 2017 Triton/Trisis malware attack on a Saudi Arabian petrochemical plant.
TRITON malware (also known as TRISIS and HatMan) was used against a Middle East–based petrochemical facility’s safety controllers. TRITON malware was designed to target a specific SIS controller model... used in critical infrastructure facilities to initiate immediate shutdown procedures in the event of an emergency.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Another key finding in the leak is confirmation of the existence of another delivery vector called 'Triton', which can target devices with Samsung Exynos with baseband exploits, forcing 2G downgrades to lay the ground for infection.
"Once on the SIS network, the attacker used their pre-built TRITON attack framework to interact with the SIS controllers using the TriStation protocol."
39 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack began with penetration of the IT network using well-documented [9], easily-detected attack methods.
A package called torchtriton was uploaded to the PyPI repository with the exact same name as a package shipped on the PyTorch nightly package index. The attacker took advantage of pip’s behavior, which prioritizes packages listed on PyPI over other available versions when using the extra-index-url argument.
The dropper was developed in Python and compiled inside the trilog.exe executable.
Soon after the execution, the dropper connected to the targeted Triconex, injecting the real malware payload inside its memory.
reg add " ... HKLM\ ... Software\Microsoft\Windows\CurrentVersion\Policies\System ... " /v EnableLUA /t REG_DWORD /d 0 /f
Component Firmware (T1542.002, Persistence/Defense Evasion) : модификация прошивки контроллера - наиболее серьёзный сценарий, реализованный в атаке TRITON/TRISIS группировкой XENOTIME
One of the actions taken by the dropper was to read, inject and execute these files into the memory of the Triconex.
imain.bin contained the final code that allows a remote user to gain full control of the SIS device.
Existing vulnerabilities in industrial equipment often allow threat groups to install persistent rootkits... Siemens disclosed a vulnerability in its PLC... may overwrite core PLC functions with a rootkit.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The malicious binary appears to be designed to collect information from target systems, including ... nameservers from /etc/resolv.conf.
The malicious binary appears to be designed to collect information from target systems, including ... hostname from gethostname(). | The malicious binary appears to be designed to collect information from target systems, including ... current username from getlogin().
TRITON malware’s design gave the attackers complete remote control of the SIS, providing them the capability to cause significant physical damage and loss of life if the plant were to enter an unsafe state. | In the 2017 attack, the actor gained initial access and then moved laterally through the information technology (IT) and operational technology (OT) networks onto the safety system and installed TRITON malware.
Additionally, it copies information from the following files: /etc/hosts, /etc/passwd, $HOME/*, $HOME/.gitconfig, $HOME/.ssh/.
Decoded strings (some, not everything): ... [VK_END] ... Password: ... username=.*&password=.* ... auth-attr-\d+-param1=(.*)&auth-attr-\d+-param2=([^&]*)
&scrn=1 ... Statistics: Active bots with smartcard: Screenshots (SR): ... A screenshot took by the bot
It contains the implementation of the TriStation protocol reverse-engineered by the threat actors and used to interact with the targeted device.
Cyberattacks on operational technology (OT) systems have shifted from data theft and ransom demands toward outright physical destruction.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
89 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical example of an attack involving safety-instrumented systems that caused two shutdowns at a petrochemical facility. The example supports the article's discussion of consequence-based risk assessment and engineering-mitigation activation frequency.
Malware/intrusion targeting safety-instrumented systems at a Saudi petrochemical plant, cited as an example of cyber activity reaching safety-critical physical infrastructure.
Malware targeting industrial safety equipment and programmable logic/controller environments to disable or override safety functions, enabling potential physical sabotage or destructive impact in OT environments.
An ICS-focused malware/implant referenced as a comparison point for research into programmable automation controllers; the content does not describe an active Triton campaign, only a Triton-style implant recreation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.