Petrochemical Plant
Saudi petrochemical plant — Triton/Trisis safety-system malware
June–August 2017
Saudi Arabia (plant identified in press reporting as Petro Rabigh)
What happened
Attackers deployed malware known as Triton, Trisis or HatMan against Schneider Electric Triconex safety instrumented systems at a Saudi petrochemical plant, attempting to reprogram the controllers that provide the last line of automated protection against dangerous plant conditions. A coding error tripped the plant into a safe shutdown in August 2017, leading to discovery. It was the first publicly known malware designed specifically to target industrial safety systems, a capability security researchers class as potentially lethal. The plant is widely identified in press reporting as Petro Rabigh; the marker is placed at the Rabigh complex.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Petrochemical Plant
- Latitude
- 22.7400°
- Longitude
- 39.0300°
Attribution
Attributed to TsNIIKhM (Russian state research institute)
The US Treasury sanctioned Russia's Central Scientific Research Institute of Chemistry and Mechanics in October 2020 for building the attack tools, and a TsNIIKhM researcher was indicted. The institute denied involvement.