ATT&CKCampaignsTriton Safety Instrumented System Attack

Triton Safety Instrumented System Attack

C0030

Campaign, Jun 2017 to Aug 2017.View on attack.mitre.org

About this campaign

Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical organization. The malware and techniques used within this campaign targeted specific Triconex Safety Controllers within the environment. The incident was eventually discovered due to a safety trip that occurred as a result of an issue in the malware.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1003.001
LSASS Memory

In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz.

T1027.005
Indicator Removal from Tools

In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates.

T1036.005
Match Legitimate Resource Name or Location

In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files.

T1053.005
Scheduled Task

In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files.

T1056.003
Web Portal Capture

In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled.

T1059.001
PowerShell

In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant.

T1573
Encrypted Channel

In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic.

T1587.001
Malware

In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software.

T1588.002
Tool

In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software.

T1595
Active Scanning

In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest.

Attributed groups1

Software1

References3

  1. FireEye TRITON 2017 Open source
    Johnson, B, et. al. (2017, December 14). Attackers Deploy New ICS Attack Framework "TRITON" and Cause Operational Disruption to Critical Infrastructure. Retrieved January 6, 2021.
  2. FireEye TRITON 2018 Open source
    Miller, S. Reese, E. (2018, June 7). A Totally Tubular Treatise on TRITON and TriStation. Retrieved November 17, 2024.
  3. Triton-EENews-2017 Open source
    Blake Sobczak. (2019, March 7). The inside story of the world’s most dangerous malware. Retrieved March 25, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.