top of page

TRITON/TRISIS: The First Malware Built to Target Safety Systems

7 days ago
4 min read

Most industrial cyber incidents aim at production: turning things off, taking control, causing disruption. TRITON, also called TRISIS, was different and more alarming. It targeted the safety instrumented system, the independent layer meant to bring a process to a safe state when something goes badly wrong. An attack on that layer is an attack on the protection people rely on when everything else fails.

What happened

In 2017, a petrochemical facility in Saudi Arabia experienced unexpected plant shutdowns. Investigators eventually traced them to malware that targeted Schneider Electric Triconex safety instrumented system (SIS) controllers.

The attackers appear to have been inside the environment for some time, working to reach and manipulate the safety controllers. What stopped them was the safety system doing its job: the Triconex controllers detected a problem, entered a safe state and triggered an automatic shutdown of the process. That shutdown is what prompted the facility to investigate, and the investigation is what uncovered the malware. In other words, the attack was discovered because it tripped the very protection it was trying to subvert.

Security firms publicly disclosed the malware in December 2017. It was quickly recognized as the first known malware built specifically to interact with safety instrumented systems.

How it worked, at a high level

Layered diagram showing corporate IT, the process control network and an isolated safety instrumented system zone with a key switch in RUN position
The safety instrumented system (SIS) is meant to be an independent backstop; TRITON showed that attackers will try to reach it.

The important points can be described without any attack recipe:

  • It aimed at the safety layer, not production. Safety controllers are normally separate from the control system precisely so they can act as an independent backstop. TRITON tried to reach into that layer.

  • It needed a path to the safety controllers. The attack depended on being able to communicate with the SIS, which in a well-separated plant should be very difficult.

  • A controller setting mattered. The Triconex controllers have a physical key switch that governs whether their logic can be changed. Reporting on the incident highlighted that leaving such controllers in a programming-enabled state makes unauthorized changes far easier. Keeping them in the locked, run state except during planned, supervised changes is a simple and effective barrier.

  • The goal was capability, not a single event. Analysts assessed that the attackers were working toward the ability to cause a physical consequence, which is why interfering with the safety system was central to their approach.

Who was behind it

In October 2020, the US Treasury sanctioned a Russian government research institute, the State Research Center FGUP Central Scientific Research Institute of Chemistry and Mechanics, known by its Russian initials TsNIIKhM, in connection with the TRITON activity. In 2022, the US Department of Justice separately charged an employee of that institute in connection with the attack and with later probing of other facilities. This reflects the formal, government-level attribution.

What it taught the industry

TRITON forced a hard conversation about the one layer many plants had assumed was untouchable:

  1. Safety systems are now in scope for attackers. The assumption that the SIS is too specialized or too separate to be targeted no longer holds.

  2. Separation is the key protection. A safety system that is genuinely isolated from the control network and from general IT is far harder to reach.

  3. Safe states are a feature, not just an inconvenience. The shutdown that disrupted production is also what saved the plant and exposed the attack.

  4. Small operational habits carry weight. Something as basic as the position of a key switch can be the difference between a blocked attempt and a successful change.

Practical defensive lessons

  • Keep the SIS separate. Safety systems should be isolated from the process control network and from IT, with any necessary data flows kept to a minimum and tightly controlled. Avoid dual-homed workstations that can reach both the control system and the safety system.

  • Use the key switch. Keep safety controllers in their locked, run-only state. Only move them to a programmable state during scheduled, authorized work, and return them afterwards. Audit the key state regularly.

  • Control access to safety assets. Tightly restrict who can reach safety controllers and their programming tools, physically and over the network, and log that access.

  • Watch the safety network. Passive monitoring of traffic to and from the SIS can reveal unexpected connections or commands without interfering with its operation.

  • Treat safe shutdowns as signals. An unexplained trip or safe-state event should be investigated as a potential security matter, not written off as a nuisance fault.

Key takeaways

  • TRITON/TRISIS, disclosed in December 2017, was the first known malware built to target safety instrumented systems, at a petrochemical facility in Saudi Arabia.

  • The attack was discovered because the Triconex safety controllers detected a problem and triggered a safe shutdown.

  • The US Treasury in 2020 sanctioned the Russian institute TsNIIKhM in connection with the activity.

  • Strong separation of the safety system and disciplined use of the controller key switch are among the most effective defences.

  • An unexplained safe shutdown deserves a security review, not just a maintenance fix.

How QBits Networks can help

Protecting the safety layer comes down to separation and disciplined access, which is exactly what our network segmentation reviews and IEC 62443 gap assessments examine. We can check whether your safety instrumented systems are genuinely isolated from the control network and IT, and whether access and change controls around them hold up. Tell us what you need through our contact page and we'll scope it with you.

bottom of page