Examining Triton Attack Framework: Lessons Learned in Protecting Industrial Systems

Advertisement


Recently, the infamous Triton (also known as Trisis) malware framework made news again after researchers from FireEye found evidence of the same attacker lurking in other critical infrastructure. In 2017, Triton was behind an attack that shut down Schneider Electric’s Triconex safety instrumentation system (SIS) at a petrochemical plant in Saudi Arabia — the malware went undetected for nearly a year and has been linked to a group called XENOTIME, affiliated with the Russian government. It was one of the first ever instances of a cyber physical attack aimed at targeting a safety system, the Triconex SIS platform, which is widely used in many industrial environments to monitor industrial processes and shut them down if something goes wrong.

Advertisement