2017 · Oil & Gas / Petrochemical
TRITON / TRISIS
Malware that targeted a safety instrumented system controller, attempting to modify safety logic. The intrusion was discovered when the safety system tripped the process to a safe state.
What happened
After extended access to the environment, attackers reached a safety controller and attempted to reprogram it. A logic error caused controllers to fail safe and shut down the plant, revealing the intrusion.
Who
Public reporting has linked the activity to a research institution associated with a nation state; assessments differ in phrasing.
Where
A petrochemical facility in the Middle East.
Why
Assessed objective: obtain the ability to manipulate or disable a protection layer — one of the highest-consequence goals in OT.
How
Extended access through the IT and then OT environments, reaching a safety engineering workstation and using the safety system's own programming capability — Schneider TriStation 1131 over 1502/UDP — against a Triconex Tricon controller whose physical keyswitch had been left in PROGRAM. The keyswitch is the control that would have stopped it: with it in RUN, the download is refused in hardware. See the Schneider Electric vendor page for the full Triconex control set.
Timeline
- 2014–2017Assessed period of access development and reconnaissance
- June 2017First plant trip attributed later to the activity
- August 2017Second trip prompting investigation that discovered the malware
- December 2017Public disclosure and technical analysis
Attack path
Described at the level required to build detection and controls.
Initial Access
AssessedNot fully public; IT environment access assessed
IT foothold
ReportedPersistence and reconnaissance
IT/OT boundary
ReportedReached the OT environment
Engineering environment
ReportedSafety engineering workstation access
Control systems
ReportedAttempted safety controller reprogramming
Physical consequence
ReportedProcess tripped to a safe state
Impact
Technology involved
ATT&CK techniques
Vulnerabilities and weaknesses exploited
- A vulnerability in a specific safety controller firmware version was reported as part of the attack chain
Control failures
- Safety controller keyswitch left in program mode
- Safety engineering workstation reachable from the wider network
- No alerting on safety logic changes
Where earlier detection was possible
- Alarm on any safety controller mode or program change
- Strict monitoring of safety engineering workstation activity
- Network monitoring between the control zone and safety systems
Defensive lessons
- Safety systems are a target and must be treated as the highest-consequence assets
- Physical keyswitch discipline is a real security control
- A trip is a security signal, not just an operations event
Why should I care?
Case studies are only useful if they change something. Pick one lesson above and check whether the control exists in your own environment this week.
Sources & further reading