Skip to main content

2017 · Oil & Gas / Petrochemical

TRITON / TRISIS

Malware that targeted a safety instrumented system controller, attempting to modify safety logic. The intrusion was discovered when the safety system tripped the process to a safe state.

Direct OT impactMiddle East

What happened

After extended access to the environment, attackers reached a safety controller and attempted to reprogram it. A logic error caused controllers to fail safe and shut down the plant, revealing the intrusion.

Who

Public reporting has linked the activity to a research institution associated with a nation state; assessments differ in phrasing.

Where

A petrochemical facility in the Middle East.

Why

Assessed objective: obtain the ability to manipulate or disable a protection layer — one of the highest-consequence goals in OT.

How

Extended access through the IT and then OT environments, reaching a safety engineering workstation and using the safety system's own programming capability — Schneider TriStation 1131 over 1502/UDP — against a Triconex Tricon controller whose physical keyswitch had been left in PROGRAM. The keyswitch is the control that would have stopped it: with it in RUN, the download is refused in hardware. See the Schneider Electric vendor page for the full Triconex control set.

Timeline

  1. 2014–2017Assessed period of access development and reconnaissance
  2. June 2017First plant trip attributed later to the activity
  3. August 2017Second trip prompting investigation that discovered the malware
  4. December 2017Public disclosure and technical analysis

Attack path

Described at the level required to build detection and controls.

Initial Access

Assessed

Not fully public; IT environment access assessed

IT foothold

Reported

Persistence and reconnaissance

IT/OT boundary

Reported

Reached the OT environment

Engineering environment

Reported

Safety engineering workstation access

Control systems

Reported

Attempted safety controller reprogramming

Physical consequence

Reported

Process tripped to a safe state

Impact

OT impactAttempted modification of safety logic; controllers entered a failed-safe state.
Safety impactThe protection layer functioned and the process went to a safe state, but the intent placed safety at risk.
Operational impactUnplanned plant shutdowns and a lengthy investigation.
Detected byInvestigation triggered by the plant trip itself.

Technology involved

Schneider Electric Triconex Tricon safety controllerTriStation 1131 safety engineering software (1502/UDP)Safety engineering workstationWindows systems in the OT environment

ATT&CK techniques

T0858T0880T0843T0862

Vulnerabilities and weaknesses exploited

  • A vulnerability in a specific safety controller firmware version was reported as part of the attack chain

Control failures

  • Safety controller keyswitch left in program mode
  • Safety engineering workstation reachable from the wider network
  • No alerting on safety logic changes

Where earlier detection was possible

  • Alarm on any safety controller mode or program change
  • Strict monitoring of safety engineering workstation activity
  • Network monitoring between the control zone and safety systems

Defensive lessons

  • Safety systems are a target and must be treated as the highest-consequence assets
  • Physical keyswitch discipline is a real security control
  • A trip is a security signal, not just an operations event

Why should I care?

Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.