Triton (malware)
Triton is malware first discovered at a Saudi Arabian petrochemical plant in 2017. It can disable safety instrumented systems, which can then contribute to a plant disaster.
Background
In December 2017, it was reported that the safety systems of an unidentified power station, believed to be in Saudi Arabia, were compromised when the Triconex industrial safety technology made by Schneider Electric SE was targeted in what is believed to have been a state sponsored attack. The computer security company Symantec claimed that the malware, known as "Triton", exploited a vulnerability in computers running the Microsoft Windows operating system to access a computer connected to the Triconex system.While the attack wasn’t reported until December 2017, the first signs appeared in June 2017 when the attackers triggered the plant’s safety system, temporarily shutting down the plant. The shutdown was believed at the time to be a mechanical issue with the safety system. In August 2017, the plant shut down a second time, prompting investigation which led to the discovery of the malware.
The attack was found to be exploiting a zero-day vulnerability to create a backdoor to easily access the Triconex systems. It was discovered also that one of the major factors that led to the attack on the plant was that several physical keys had been left in a state by which the Triconex systems could be accessed. The malware was found to be capable of creating a situation where the safety systems could be disabled, potentially leading to unsafe conditions for workers at the plant. Due to this possibility, Triton is often credited as the first piece of malware created to target industrial safety systems with the primary intention of causing human death.
In 2018, FireEye, a company that researches cyber-security, reported that the malware most likely came from the Central Scientific Research Institute of Chemistry and Mechanics, a research entity in Russia.
It was reported by Wired that Triton's attacks were registered in North America, China, and Russia.