logo

Report: Nation-Backed Hackers Hit Industrial Emergency Shutdown System

ID: 8a499a0f-edf4-5843-8922-d018389bedfa

STIX ID: report--8a499a0f-edf4-5843-8922-d018389bedfa

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2017-12-15

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

FireEye and Dragos reported discovery of TRITON/TRISIS, a nation-state-attributed malware framework designed to interact with Schneider Electric Triconex SIS controllers via the proprietary TriStation protocol; attackers used it to reprogram safety controllers at a Middle Eastern facility, triggering safe-state shutdowns and demonstrating a high-risk capability to cause physical impact to industrial processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.