Summary
TRITON (Mandiant) / TRISIS (Dragos), disclosed on 14 December 2017, is an attack framework built to interact with Schneider Electric Triconex safety instrumented system (SIS) controllers. An SIS is the last automated layer of protection. It shuts a process down safely when pressure, temperature or flow leaves safe limits.
The attackers reached an SIS engineering workstation at a petrochemical facility and deployed trilog.exe, named to masquerade as Triconex’s legitimate TriLog application, together with payloads to inject into the controllers. They spoke Triconex’s proprietary TriStation protocol, which they had reverse engineered. No zero-day was needed.
A fault in the attackers’ code caused some SIS controllers to enter a failed-safe state, which automatically shut the industrial process down and triggered the investigation. Mandiant assessed with moderate confidence that the attacker “inadvertently shutdown operations while developing the ability to cause physical damage.”
In March 2022 the U.S. Department of Justice unsealed an indictment against Evgeny Viktorovich Gladkikh, an employee of the Russian Ministry of Defence’s Central Scientific Research Institute of Chemistry and Mechanics (TsNIIKhM). It charges him with conspiring in 2017 to deploy Triton on a foreign refinery’s safety systems. Dragos tracks the activity group as XENOTIME.
Apa maksudnya untuk Malaysia? 🇲🇾
Malaysia’s oil, gas and petrochemical industry (Kertih, Gebeng, Pengerang, Bintulu and offshore) depends on safety instrumented systems from several vendors. TRITON matters regardless of brand: the safety layer itself can be targeted, and a compromised SIS turns a cyber incident into a process-safety incident.
- Physically lock SIS controllers in RUN mode. Triconex controllers have a key switch, and the malware needed the controller in a programmable state. Treat any request to switch to PROGRAM mode as a change-controlled event.
- Isolate SIS engineering workstations. They should not share a network with the DCS or corporate IT, and remote access to them should be exceptional and supervised.
- Treat unexplained SIS trips as a possible security event, not only an instrumentation fault. That is exactly how TRITON was found.
Details / TTPs (ATT&CK for ICS)
| Technique | Name | Observed behavior |
|---|---|---|
| T0869 | Standard Application Layer Protocol | Reverse-engineered TriStation protocol to talk to the SIS |
| T0849 | Masquerading | trilog.exe posing as Triconex TriLog |
| T0868 | Detect Operating Mode | Checked controller state before acting |
| T0843 | Program Download | Payloads written to the Triconex controllers |
| T0821 | Modify Controller Tasking | Injected code into controller memory |
| T1693.001 | System Firmware | Modified controller firmware in memory to add attacker functionality |
| T0880 | Loss of Safety | Objective: disable the safety function |
Detection guidance
- Alert on any TriStation (or other SIS engineering) traffic outside approved maintenance windows.
- Monitor SIS key-switch position and mode changes; many controllers expose this to the DCS or historian.
- Hash-check and allow-list software on SIS engineering workstations, and alert on new executables there.
IoCs
File names and hashes (e.g. trilog.exe, library.zip, inject.bin, imain.bin) are published in the referenced Mandiant report.
References
- Mandiant (Google Cloud), Attackers Deploy New ICS Attack Framework “TRITON” (14 Dec 2017): https://cloud.google.com/blog/topics/threat-intelligence/attackers-deploy-new-ics-attack-framework-triton/
- U.S. DOJ, Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide (24 Mar 2022): https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical