{
  "id": "case-triton-schneider",
  "slug": "triton-schneider-triconex-sabotage",
  "title": "TRITON / HatMan Petrochemical Safety Instrumented System Attack",
  "summary": "Russian state research institute (Central Scientific Research Institute of Chemistry and Mechanics / TsNIIKhM) deployed the TRITON (HatMan) malware framework inside a Saudi Arabian petrochemical plant, directly manipulating Schneider Electric Triconex Safety Instrumented System (SIS) controllers to cause emergency plant shutdowns with the potential for physical explosion.",
  "case_number": "1:21-cr-00107",
  "court": "U.S. District Court for the District of Columbia",
  "district": "D.D.C.",
  "country": "Saudi Arabia / United States",
  "opened_at": "2017-08-01",
  "status": "charged",
  "victim_sector": "Chemical & Petrochemical Manufacturing",
  "victim_country": "Saudi Arabia",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Emergency plant shutdowns, extensive safety controller replacement, and global safety engineering reviews.",
  "first_seen_at": "2017-05-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "temp-veles",
  "defendant_slugs": [
    "evgeny-gladkikh"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T0858",
      "evidence_excerpt": "TRITON connected to Triconex controllers via proprietary TriStation network protocol (UDP port 1502), injecting malicious code into Tricon MP communication modules.",
      "evidence_locator": "CISA Advisory MAR-17-352-01",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Alert: HatMan - Safety System Targeted Malware",
      "source_url": "https://www.cisa.gov"
    },
    {
      "technique_id": "T0806",
      "evidence_excerpt": "The malware attempted to reprogram safety logic to suppress automatic emergency shutdowns, inadvertently triggering controller self-diagnostic alarms that tripped the plant.",
      "evidence_locator": "DOJ Indictment: U.S. v. Evgeny Viktorovich Gladkikh \u00b6 18",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment of Russian Research Institute Staff",
      "source_url": "https://www.justice.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2017-06-20",
      "description": "Attacker initiates Triconex controller firmware injection, triggering safety trips."
    },
    {
      "event_type": "discovery",
      "event_date": "2017-08-04",
      "description": "Second safety trip halts plant operations, initiating forensic investigation that uncovers TRITON."
    },
    {
      "event_type": "sanction",
      "event_date": "2020-10-23",
      "description": "U.S. Treasury OFAC designates Russian state research institute TsNIIKhM under CAATSA."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Chemical & Petrochemical Manufacturing networks. Russian state research institute (Central Scientific Research Institute of Chemistry and Mechanics / TsNIIKhM) deployed the TRITON (HatMan) malware framework inside a Saudi Arabian petrochemical plant, directly manipulating Schneider Electric Triconex Safety Instrumented System (SIS) controllers to cause emergency plant shutdowns with the potential for physical explosion.",
    "blast_radius": "Emergency plant shutdowns, extensive safety controller replacement, and global safety engineering reviews. Impacted Chemical & Petrochemical Manufacturing infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Chemical & Petrochemical Manufacturing sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "Russian state research institute (Central Scientific Research Institute of Chemistry and Mechanics / TsNIIKhM) deployed the TRITON (HatMan) malware framework inside a Saudi Arabian petrochemical plant, directly manipulating Schneider Electric Triconex Safety Instrumented System (SIS) controllers to cause emergency plant shutdowns with the potential for physical explosion.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}