Triton

MITRE ATT&CK: S1009 View on attack.mitre.org

Aliases: TRISIS, HatMan, Trisis

First seen
2017-08-01 00:00:00
Malware type
exploit-kit
Family
Malware family
Related IoCs
1 (1 malicious)
Last IoC activity
2026-03-03 18:33:47
Profile updated
2026-07-07 12:56:18

Targeted industries: energy-and-utilities

Targeted regions: country_code:sa

Context

Triton is an attack framework built to interact with Triconex Safety Instrumented System (SIS) controllers.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Triton (S1009). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 39b29c38c03868854fb972e7b18f22c2c76520cfb6edf46ba5a5618f74943eac 2026-03-03 1

Malware & tools used

  • Native API (attack-pattern)
  • Program Download (attack-pattern)
  • Masquerading (attack-pattern)
  • Broadcast Discovery (attack-pattern)
  • Indicator Removal on Host (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Modify Controller Tasking (attack-pattern)
  • Scripting (attack-pattern)
  • Change Operating Mode (attack-pattern)
  • Commonly Used Port (attack-pattern)
  • Detect Operating Mode (attack-pattern)
  • Program Upload (attack-pattern)
  • Hooking (attack-pattern)
  • Execution through API (attack-pattern)
  • Loss of Safety (attack-pattern)
  • Exploitation for Evasion (attack-pattern)
  • Standard Application Layer Protocol (attack-pattern)
  • System Firmware (attack-pattern)

Used by threat actors

  • TEMP.Veles (threat-actor)
  • C0032 (campaign)
  • Triton Safety Instrumented System Attack (campaign)

Reports & references

  • Mandiant — Attackers Deploy New Ics Attack Framework Triton (report)
  • CISA — Aa22 110A (report)
  • Kaspersky — 91897 (report)
  • Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools (report)
  • CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
  • ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
  • Mandiant — Mandiant Red Team Emulates Fin11 Tactics (report)
  • CISA — Aa22 083A (report)
  • domaintools.com — Visibility Monitoring And Critical Infrastructure Security (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Triton (report)
  • nozominetworks.com — Nozomi Networks Triton The First Sis Cyberattack (report)
  • midnightbluelabs.com — Analyzing The Triton Industrial Malware (report)
  • sans.org — Summit Archive 1538425180 (report)
  • dragos.com — Trisis 01 (report)
  • CISA — Mar 17 352 01%20Hatman%20 %20Safety%20System%20Targeted%20Malware%20%28Update%20A%29 S508C (report)
  • eenews.net — 1060123327 (report)
  • ics-cert.us-cert.gov — Mar 17 352 01%20Hatman%E2%80%94Safety%20System%20Targeted%20Malware S508C (report)
  • home.treasury.gov — Sm1162 (report)
  • github.com — Trisis Triton Hatman (report)
  • ic3.gov — 220325 (report)

External references