Report: Hacker group behind Trisis Malware expanding Activity in Middle East
ID: f0ebe5f5-f025-519c-9df0-8dfeb18aa376
STIX ID: report--f0ebe5f5-f025-519c-9df0-8dfeb18aa376
Feed Name: Security Ledger
Dragos warns that XENOTIME (widely assessed as Iran-linked) has developed and deployed TRITON/TRISIS malware capable of communicating with and reprogramming Schneider Electric Triconex Safety Instrumented System (SIS) controllers via the proprietary TriStation protocol; an incident in the Middle East caused SIS controllers to enter a failed-safe state, and Dragos assesses the group is maturing and expanding capabilities that could enable future disruptive or destructive attacks against critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
