The Triton/Trisis malware campaign exposed a rare and dangerous form of industrial cyberattack: intruders targeted a petrochemical facility’s safety instrumented systems (SIS), the controls designed to prevent catastrophic accidents. Reporting on the incident described it as a watershed moment because compromising safety systems can turn a network intrusion into physical sabotage, potentially enabling equipment damage, toxic release, or loss of life. Researchers later characterized Triton as one of the most dangerous malware families seen in critical infrastructure because it was built to interact directly with industrial safety controllers rather than simply disrupt IT operations.
Subsequent investigations tied the activity to the Xenotime threat group and showed the operation was broader than the original plant intrusion. FireEye and other researchers documented the actor’s tradecraft, custom tooling, and detection opportunities, while later reporting said the group had sought additional victims and was observed probing industrial control system environments tied to U.S. electric utilities and other regions. That follow-on activity included scanning, credential stuffing, and enumeration of remote-access services and exposed network weaknesses, signaling continued interest in moving from oil and gas targets toward wider critical-infrastructure disruption.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
From late 2018 into 2019, Dragos and E-ISAC observed Xenotime conducting scanning, credential stuffing, and enumeration against remote access portals and network vulnerabilities at at least 20 U.S. electric utilities. The activity did not result in confirmed outages or ICS compromise but showed the group testing access to power-grid-related environments.
On 2019-04-10, FireEye released a technical profile of the Triton actor covering tactics, techniques, procedures, custom attack tools, detections, and ATT&CK mapping. The publication added significant technical detail to defenders' understanding of the campaign.
By late 2018, researchers were tracking the Triton-linked group Xenotime as it broadened activity beyond oil and gas environments. This marked an escalation from the original petrochemical targeting to wider industrial control system reconnaissance.
On 2017-12-15, public reporting disclosed the Triton incident and highlighted it as a major escalation because the malware targeted industrial safety systems rather than only production operations. Researchers and media characterized it as a watershed moment for critical infrastructure security.
In 2017, attackers compromised a petrochemical facility in Saudi Arabia and deployed Triton/Trisis malware against Schneider Electric safety instrumented systems. The intrusion caused safety systems to enter a fail-safe shutdown state, revealing an attempt to manipulate protections designed to prevent physical harm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceweb.archive.org
Open sourcecsoonline.com
Open sourcetechnologyreview.com
Open sourcetheguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.