Petrochemical Plant

Saudi petrochemical plant — Triton/Trisis safety-system malware

June–August 2017

Saudi Arabia (plant identified in press reporting as Petro Rabigh)

What happened

Attackers deployed malware known as Triton, Trisis or HatMan against Schneider Electric Triconex safety instrumented systems at a Saudi petrochemical plant, attempting to reprogram the controllers that provide the last line of automated protection against dangerous plant conditions. A coding error tripped the plant into a safe shutdown in August 2017, leading to discovery. It was the first publicly known malware designed specifically to target industrial safety systems, a capability security researchers class as potentially lethal. The plant is widely identified in press reporting as Petro Rabigh; the marker is placed at the Rabigh complex.

Evidence
Documented
Confidence
High
Infrastructure
Petrochemical Plant
Latitude
22.7400°
Longitude
39.0300°

Attribution

Attributed to TsNIIKhM (Russian state research institute)

The US Treasury sanctioned Russia's Central Scientific Research Institute of Chemistry and Mechanics in October 2020 for building the attack tools, and a TsNIIKhM researcher was indicted. The institute denied involvement.

Sources

  1. U.S. Treasury Sanctions Russian Institute Linked to Triton MalwareSecurityWeek · Incident reporting