Triton
MITRE ATT&CK: S1009 View on attack.mitre.org
Aliases: TRISIS, HatMan, Trisis
- First seen
- 2017-08-01 00:00:00
- Malware type
- exploit-kit
- Family
- Malware family
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-03-03 18:33:47
- Profile updated
- 2026-07-07 12:56:18
Targeted industries: energy-and-utilities
Targeted regions: country_code:sa
Context
Triton is an attack framework built to interact with Triconex Safety Instrumented System (SIS) controllers.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Triton (S1009). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 39b29c38c03868854fb972e7b18f22c2c76520cfb6edf46ba5a5618f74943eac | 2026-03-03 | 1 |
Malware & tools used
- Native API (attack-pattern)
- Program Download (attack-pattern)
- Masquerading (attack-pattern)
- Broadcast Discovery (attack-pattern)
- Indicator Removal on Host (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Modify Controller Tasking (attack-pattern)
- Scripting (attack-pattern)
- Change Operating Mode (attack-pattern)
- Commonly Used Port (attack-pattern)
- Detect Operating Mode (attack-pattern)
- Program Upload (attack-pattern)
- Hooking (attack-pattern)
- Execution through API (attack-pattern)
- Loss of Safety (attack-pattern)
- Exploitation for Evasion (attack-pattern)
- Standard Application Layer Protocol (attack-pattern)
- System Firmware (attack-pattern)
Used by threat actors
- TEMP.Veles (threat-actor)
- C0032 (campaign)
- Triton Safety Instrumented System Attack (campaign)
Reports & references
- Mandiant — Attackers Deploy New Ics Attack Framework Triton (report)
- CISA — Aa22 110A (report)
- Kaspersky — 91897 (report)
- Mandiant — Triton Attribution Russian Government Owned Lab Most Likely Built Tools (report)
- CISA — Aa22 110A Joint Csa Russian State Sponsored And Criminal Cyber Threats To Critical Infrastructure 4 20 22 Final (report)
- ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
- Mandiant — Mandiant Red Team Emulates Fin11 Tactics (report)
- CISA — Aa22 083A (report)
- domaintools.com — Visibility Monitoring And Critical Infrastructure Security (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Triton (report)
- nozominetworks.com — Nozomi Networks Triton The First Sis Cyberattack (report)
- midnightbluelabs.com — Analyzing The Triton Industrial Malware (report)
- sans.org — Summit Archive 1538425180 (report)
- dragos.com — Trisis 01 (report)
- CISA — Mar 17 352 01%20Hatman%20 %20Safety%20System%20Targeted%20Malware%20%28Update%20A%29 S508C (report)
- eenews.net — 1060123327 (report)
- ics-cert.us-cert.gov — Mar 17 352 01%20Hatman%E2%80%94Safety%20System%20Targeted%20Malware S508C (report)
- home.treasury.gov — Sm1162 (report)
- github.com — Trisis Triton Hatman (report)
- ic3.gov — 220325 (report)
External references
- mitre-attack — S1009
- Blake Johnson, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, Christopher Glyer December 2017
- DHS CISA February 2019
- Dragos December 2017
- Jos Wetzels January 2018
- Julian Gutmanis March 2019
- Schneider December 2018
- Schneider Electric January 2018
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy