TRITON, also known as TRISIS and HatMan, is ICS-focused malware designed to compromise Schneider Electric Triconex Tricon safety instrumented systems (SIS). It targets vulnerable Tricon main processor controllers by modifying in-memory firmware, enabling malicious code execution and remote manipulation of safety functions. Its intended effect is to prevent safety systems from operating correctly while making them appear to function normally, potentially preventing emergency shutdowns and creating conditions for physical damage, environmental harm, and loss of life.
TRITON was deployed against a Middle East petrochemical refinery in 2017, where faults in the malware caused SIS controllers to enter a failed state and triggered automatic emergency shutdowns. U.S. authorities attributed the operation to actors associated with Russia's Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM); the activity group is widely tracked in industry reporting as XENOTIME. The malware requires access to the safety network and successful deployment typically depends on access to an SIS engineering environment and controllers configured to permit programming.
The framework includes a Python-based deployment component and controller-resident payloads that implement the proprietary TriStation communications protocol. It can inject malicious functionality into targeted controllers, read or modify controller memory, and provide remote control of the SIS. TRITON also masqueraded as legitimate Triconex engineering software to reduce suspicion. The malware specifically affected certain legacy Tricon controller and firmware combinations; later vendor security updates added mitigations for the identified attack path. TRITON remains a significant example of malware directly targeting the final automated safety layer in industrial environments, particularly in oil, gas, petrochemical, and other critical-infrastructure sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
When a system call is made, registers are stored to a fixed memory location. Modifying the data in this location could allow attackers to gain supervisor-level access and control system states. CVE-2018-7522 has been assigned to this vulnerability. | These vulnerabilities were discovered by NCCIC and Schneider Electric during the investigation of the HatMan malware.
System calls read directly from memory addresses within the control program area without any verification. Manipulating this data could allow attacker data to be copied anywhere within memory. CVE-2018-8872 has been assigned to this vulnerability. | These vulnerabilities were discovered by NCCIC and Schneider Electric during the investigation of the HatMan malware.
select communication modules by Rockwell Automation in specific ControlLogix EtherNet/IP (ENIP) communication module models, 1756-EN2, 1756-EN3 (CVE-2023-3595)... Both CVE-2023-3595 and CVE-2023-3596 exist inside the devices’ Common Industrial Protocol (CIP) implementation and allow remote code execution with persistence on the EN2* and EN3* modules... CVE-2023-3595 allows for arbitrary manipulation of firmware memory
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dragos Inc.: TRISIS Malware: Analysis of Safety System Targeted Malware ... Mandiant: Attackers Deploy New ICS Attack Framework “TRITON” and Cause Operational Disruption to Critical Infrastructure
TRITON malware (also known as TRISIS and HatMan) was used against a Middle East–based petrochemical facility’s safety controllers. TRITON malware was designed to target a specific SIS controller model... used in critical infrastructure facilities to initiate immediate shutdown procedures in the event of an emergency.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
For example, industrial attack techniques employed by Triton and Industroyer were used by actors ranging from FIN11 to FIN6 during ransomware deployment, extortion and other activities.
Another key finding in the leak is confirmation of the existence of another delivery vector called 'Triton', which can target devices with Samsung Exynos with baseband exploits, forcing 2G downgrades to lay the ground for infection.
"Once on the SIS network, the attacker used their pre-built TRITON attack framework to interact with the SIS controllers using the TriStation protocol."
39 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack began with penetration of the IT network using well-documented [9], easily-detected attack methods.
A package called torchtriton was uploaded to the PyPI repository with the exact same name as a package shipped on the PyTorch nightly package index. The attacker took advantage of pip’s behavior, which prioritizes packages listed on PyPI over other available versions when using the extra-index-url argument.
The dropper was developed in Python and compiled inside the trilog.exe executable.
Soon after the execution, the dropper connected to the targeted Triconex, injecting the real malware payload inside its memory.
reg add " ... HKLM\ ... Software\Microsoft\Windows\CurrentVersion\Policies\System ... " /v EnableLUA /t REG_DWORD /d 0 /f
Component Firmware (T1542.002, Persistence/Defense Evasion) : модификация прошивки контроллера - наиболее серьёзный сценарий, реализованный в атаке TRITON/TRISIS группировкой XENOTIME
One of the actions taken by the dropper was to read, inject and execute these files into the memory of the Triconex.
imain.bin contained the final code that allows a remote user to gain full control of the SIS device.
Existing vulnerabilities in industrial equipment often allow threat groups to install persistent rootkits... Siemens disclosed a vulnerability in its PLC... may overwrite core PLC functions with a rootkit.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The malicious binary appears to be designed to collect information from target systems, including ... nameservers from /etc/resolv.conf.
The malicious binary appears to be designed to collect information from target systems, including ... hostname from gethostname(). | The malicious binary appears to be designed to collect information from target systems, including ... current username from getlogin().
TRITON malware’s design gave the attackers complete remote control of the SIS, providing them the capability to cause significant physical damage and loss of life if the plant were to enter an unsafe state. | In the 2017 attack, the actor gained initial access and then moved laterally through the information technology (IT) and operational technology (OT) networks onto the safety system and installed TRITON malware.
Additionally, it copies information from the following files: /etc/hosts, /etc/passwd, $HOME/*, $HOME/.gitconfig, $HOME/.ssh/.
Decoded strings (some, not everything): ... [VK_END] ... Password: ... username=.*&password=.* ... auth-attr-\d+-param1=(.*)&auth-attr-\d+-param2=([^&]*)
&scrn=1 ... Statistics: Active bots with smartcard: Screenshots (SR): ... A screenshot took by the bot
It contains the implementation of the TriStation protocol reverse-engineered by the threat actors and used to interact with the targeted device.
Cyberattacks on operational technology (OT) systems have shifted from data theft and ransom demands toward outright physical destruction.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware targeting industrial safety equipment and programmable logic/controller environments to disable or override safety functions, enabling potential physical sabotage or destructive impact in OT environments.
An ICS-focused malware/implant referenced as a comparison point for research into programmable automation controllers; the content does not describe an active Triton campaign, only a Triton-style implant recreation.
ICS malware referenced as an example of targeted sabotage causing physical process impact by manipulating industrial control systems.
ICS malware referenced as a classic energy-sector cyberattack example involving compromise of OT/safety-related infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.