logo

Report: Hacker group behind Trisis Malware expanding Activity in Middle East

ID: f0ebe5f5-f025-519c-9df0-8dfeb18aa376

STIX ID: report--f0ebe5f5-f025-519c-9df0-8dfeb18aa376

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2018-05-25

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Dragos warns that XENOTIME (widely assessed as Iran-linked) has developed and deployed TRITON/TRISIS malware capable of communicating with and reprogramming Schneider Electric Triconex Safety Instrumented System (SIS) controllers via the proprietary TriStation protocol; an incident in the Middle East caused SIS controllers to enter a failed-safe state, and Dragos assesses the group is maturing and expanding capabilities that could enable future disruptive or destructive attacks against critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.