Netskope Threat Labs

Trisis

ATP Sandbox Adv. Heuristics

Trisis (a.k.a. TRITON and HatMan) is a malware framework that targeted industrial safety instrumented systems, specifically Schneider Electric Triconex controllers, in an attack on a Saudi petrochemical plant in 2017. The intrusion is a landmark in operational technology threats because its goal was to tamper with the safety systems that prevent catastrophic industrial failures, and researchers have linked it to a Russian state sponsored institution.

First seen
April 2022
Last seen
October 2026
Alert Name
Script-Python.Trojan.Trisis
Win32.Trojan.Trisis