TRITON, also known as TRISIS or HatMan, was the first publicly documented malware built to directly target a Safety Instrumented System (SIS). Investigators found it was used against Schneider Electric Triconex controllers at a Saudi Arabian petrochemical facility, where the malware caused controllers to enter a failed state and triggered an automatic shutdown. FireEye, Dragos, and U.S. government reporting said the intrusion was discovered because bugs in the malware interrupted operations before the attackers could achieve their apparent objective of manipulating safety systems in a way that could have enabled physical damage, environmental harm, or loss of life.
Technical analysis showed the framework used a Python-based dropper and components including trilog.exe, inject.bin, and imain.bin to modify controller memory and enable remote interaction with the SIS. Nozomi Networks later recreated the TriStation environment, reverse engineered the protocol, and demonstrated that similar malicious payloads could make industrial processes unsafe without requiring nation-state-exclusive capabilities. U.S. authorities later attributed the operation to Russia's TsNIIKhM, warning that older Tricon controllers remain exposed, while public repositories and advisories have since circulated malware samples, decompiled code, YARA rules, and protocol-analysis tools to help defenders detect reconnaissance and payload delivery in OT environments.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
On 24 March 2022, the FBI issued a Private Industry Notification warning that TRITON remained a threat to global critical infrastructure. The bureau attributed the 2017 attack to Russia's Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM).
The FBI notice said a U.S. indictment against a Russian national and TsNIIKhM employee involved in the TRITON attack was unsealed on 24 March 2022. The unsealing preceded the bureau's warning about the ongoing threat.
A public GitHub repository dedicated to TRISIS/TRITON/HatMan was published with original malware samples, decompiled code, YARA rules, and analysis resources. The repository author said the files had already been publicly available from at least two sources and were shared to support research and defense.
An NCCIC/CISA advisory described two critical vulnerabilities, CVE-2018-8872 and CVE-2018-7522, affecting Schneider Electric Triconex Tricon MP Model 3008 firmware 10.0 through 10.4 and stated that HatMan malware specifically targets them. The advisory said Schneider Electric recommended upgrading to Tricon CX v11.4 and provided malware detection and response support.
The FBI said Schneider Electric addressed the vulnerability affecting Tricon model 3008 versions 10.0 through 10.4 by releasing Tricon controller version 11.3. Older versions remained vulnerable to similar attacks.
The TRITON incident was publicly reported in December 2017 as the first publicly documented malware attack directly targeting a safety instrumented system. Reporting identified the target as Schneider Electric Triconex controllers at a Saudi Arabian petrochemical facility.
After the August 2017 attack, the actors regained unauthorized access to a file server at the facility. According to the FBI, they used that access to collect information about the victim's response to the incident.
Several Triconex safety controllers detected anomalies caused by bugs in TRITON, causing the facility to enter a safe state automatically. The shutdown led investigators to discover both the attackers' presence and the malware, preventing the attack from reaching its full effect.
The FBI reported a second use of TRITON in August 2017 against the same Middle East-based petrochemical facility's safety controllers. The malware was installed on the SIS and gave the attackers access to and control of Triconex devices.
The FBI said TRITON was used in June 2017 against the safety instrumented system at a Middle East-based petrochemical facility. The operation targeted Schneider Electric Triconex safety controllers after the actor moved through the victim's IT and OT networks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceus-cert.cisa.gov
Open sourcefireeye.com
Open sourcenozominetworks.com
Open sourcedragos.com
Open sourceics-cert.us-cert.gov
Open sourceics-cert.us-cert.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.