Campaign, Jun 2017 to Aug 2017.View on attack.mitre.org
Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical organization. The malware and techniques used within this campaign targeted specific Triconex Safety Controllers within the environment. The incident was eventually discovered due to a safety trip that occurred as a result of an issue in the malware.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
In the Triton Safety Instrumented System Attack, TEMP.Veles used Mimikatz. |
| T1027.005 Indicator Removal from Tools |
In the Triton Safety Instrumented System Attack, TEMP.Veles modified files based on the open-source project cryptcat in an apparent attempt to decrease anti-virus detection rates. |
| T1036.005 Match Legitimate Resource Name or Location |
In the Triton Safety Instrumented System Attack, TEMP.Veles renamed files to look like legitimate files, such as Windows update files or Schneider Electric application files. |
| T1053.005 Scheduled Task |
In the Triton Safety Instrumented System Attack, TEMP.Veles installed scheduled tasks defined in XML files. |
| T1056.003 Web Portal Capture |
In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled. |
| T1059.001 PowerShell |
In the Triton Safety Instrumented System Attack, TEMP.Veles used a publicly available PowerShell-based tool, WMImplant. |
| T1573 Encrypted Channel |
In the Triton Safety Instrumented System Attack, TEMP.Veles used cryptcat binaries to encrypt their traffic. |
| T1587.001 Malware |
In the Triton Safety Instrumented System Attack, TEMP.Veles developed, prior to the attack, malware capabilities that would require access to specific and specialized hardware and software. |
| T1588.002 Tool |
In the Triton Safety Instrumented System Attack, TEMP.Veles used tools such as Mimikatz and other open-source software. |
| T1595 Active Scanning |
In the Triton Safety Instrumented System Attack, TEMP.Veles engaged in network reconnaissance against targets of interest. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.