Triton

Triton / TRISIS

Triton (TRISIS)

Triton (also TRISIS or HatMan) is the malware discovered in 2017 that, for the first time, specifically attacked a safety instrumented system (SIS) — concretely the Triconex controllers from Schneider Electric in an industrial facility in the Middle East. Because it targeted exactly the protection layer meant to safeguard human lives, it marks a particularly dangerous escalation.

History & facts. Safety instrumented systems are the last protection layer of industrial plants: they bring a process to a safe shutdown when it reaches dangerous states (overpressure, overheating). Triton was tailored to manipulate exactly these Triconex systems — the attempt in 2017 inadvertently triggered an emergency shutdown and was thereby exposed. The attack required deep, plant-specific knowledge and is regarded as a blueprint for how safety systems can be attacked. It is attributed to the group XENOTIME.

Outlook & recommendation. Triton shifted the red line: an attack on the Safety Instrumented System (SIS) accepts at least death or physical destruction. Protection requires the consistent separation of the safety and process-control levels, strict access control to engineering systems and the monitoring of changes to safety controllers. Since these systems traditionally lie with engineering and not with IT security, the interlocking of both worlds is decisive — a core concern of standards-compliant Operational Technology (OT) security per IEC 61511 — Functional Safety for the Process Industry (IEC 61511)/62443.

Triton — Triton / TRISIS