Triton, also known as TRISIS and HatMan, is specialized industrial malware developed to target Safety Instrumented Systems (SIS), particularly Schneider Electric Triconex safety controllers used in petrochemical and other critical infrastructure environments. It is widely regarded as the first publicly known malware built specifically to manipulate a safety system whose purpose is to place industrial processes into a safe state during dangerous conditions.
The malware operated from Windows engineering workstations in the target environment and communicated with Triconex controllers over the proprietary TriStation protocol. Its core objective was to interact with and modify SIS controller logic, enabling attackers to interfere with emergency shutdown functions and potentially create conditions for physical damage or loss of life. In the known 2017 incident at a Middle Eastern petrochemical facility, a payload error caused controllers to enter a fail-safe state and triggered an emergency shutdown, which exposed the intrusion before the intended effects were achieved.
Triton is associated with the threat actor commonly tracked as XENOTIME and has also been linked by U.S. government sanctions to the Russian state research institute TsNIIKhM. Reporting on the intrusion indicates the operators first gained access through phishing, then moved through the victim’s IT environment, crossed into OT networks via weak segmentation and compromised remote-access pathways, and ultimately reached engineering systems connected to the SIS environment. The campaign demonstrated a full IT-to-OT intrusion chain culminating in direct manipulation of industrial safety controls.
The malware has also been noted for defense-evasion behavior, including masquerading as legitimate Triconex-related software on engineering hosts. Triton remains a landmark case in OT threat history because it showed that adversaries were willing and able to target safety functions directly rather than only process control or business systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Атаки группировок Sandworm (Industroyer / Industroyer2 - энергосистемы Украины) и XENOTIME (TRITON / TRISIS - Safety Instrumented Systems нефтехимического объекта) показали полную цепочку: adversary целенаправленно проходит через IT-сеть, пересекает DMZ, добирается до инженерных станций и модифицирует логику контроллеров.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Another key finding in the leak is confirmation of the existence of another delivery vector called 'Triton', which can target devices with Samsung Exynos with baseband exploits, forcing 2G downgrades to lay the ground for infection.
"Once on the SIS network, the attacker used their pre-built TRITON attack framework to interact with the SIS controllers using the TriStation protocol."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
Another water utility serving 2 million people in North Texas said Tuesday that it is also dealing with a cybersecurity incident that caused operational issues...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
57 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ICS malware referenced as a classic energy-sector cyberattack example involving compromise of OT/safety-related infrastructure.
ICS malware associated with attacks on safety instrumented systems in industrial environments; mentioned here as historical precedent for physical-impact OT attacks.
ICS malware associated with attacks on safety instrumented systems in petrochemical environments; mentioned as historical context for OT impact.
ICS malware targeting Safety Instrumented System controllers, with emphasis on impact to physical safety.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.