• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • US Department of Homeland Security alert Malware Targeting Industrial Safety Systems
  • Malware

US Department of Homeland Security alert Malware Targeting Industrial Safety Systems

Ddos December 21, 2017 3 minutes read
Industrial Safety Systems

Network security companies FireEye and Dragos reported last week that the new malware, Triton, and Trisis, shut down some Middle East agencies by damaging the widely used Schneider Electric Triconex safety controller in key infrastructure. It is reported that Cyber Cyber company CyberX speculated on the basis of speculation that the behind-the-scenes blackmailing of this cyber attack may be planned by Iran and its target is an important agency suspected of being in Saudi Arabia. The National Security and Communications Integration Center (NCCIC) of the Department of Homeland Security (DHS) released an analysis of malware for the industrial security system on Monday.

the US Department of Homeland Security ( DHS ) researchers have found another new malware in the investigation in the near future Hatman, aimed against the state industrial control system ( ICS launched attacks). Subsequently, the National Network Security and Communications Integration Center ( NCCIC ) provided mitigation and YARA rules in a malware analysis released this Monday to reduce the loss of national industrial control systems. 

Surveys show that HatMan malware written in Python is primarily targeted at Schneider Electric’s Triconex Safety Instrumented System (SIS) controllers and is designed to monitor processes and restore them to a safe state or perform safety shutdowns when potentially dangerous situations are identified. In addition, HatMan communicates with SIS controllers via proprietary TriStation protocols and allows attackers to manipulate devices by adding new ladder logic. However, as the hacker terminated the operation after triggering the SIS controller to start the “Safe Shutdown” feature, FireEye experts speculated that the attacker could inadvertently trigger the controller during the detection phase, with the ultimate goal being to simply inflict high SIS physical damage Interested.

Schneider Electric’s Triconex Safety Monitoring System (SIS) controller is designed to provide continuous safety interlocking and protection, process monitoring and safe parking where necessary, for safety and critical units in nuclear, oil refining, petrochemical, chemical and other process industries.

It is noteworthy that NCCIC pointed out in its report that the malware mainly has two components: one is to interact with the safety controller after the damaged PC is running, and the other is to run directly on the controller. The researchers said that although HatMan itself did not do any dangerous actions and the downgraded infrastructure security system did not directly manipulate the entire control process, it could be extremely harmful if flawed security systems were infected with malware. In addition, it is safe to say that although HatMan may become an important tool for monitoring ICS in the future, it may only be used to affect industrial processes or other dangerous operations. All in all, the building of different components in malware means that an attacker needs to be very familiar with the ICS environment, especially with Triconex controllers, and it needs a longer development cycle to refine this sophisticated attack.

Schneider Electric has investigated the incident. Officials said there is currently no evidence that the malware exploits any loopholes in the product. However, security experts advise customers not to easily place the device in “Program” mode because an attacker could potentially send the payload via malware when the controller is set to “Program” mode.

Emily S. Miller, director of the National Security Agency, said: “Attackers have the ability to access critical infrastructure security instrumentation and are likely to make potential changes to device firmware, so this reminder gives key owners and operators critical infrastructure The warning. ”

Source: Securityweek 

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. IcedID Banking Trojan combine with Ursnif/Dreambot for expansion
  2. BlueDelta: GRU-Linked Cyber Espionage Group Targets Critical European Networks
  3. Rafel RAT Malware: A Growing Cybersecurity Threat to Android Devices
  4. Cryptocurrency Scams: How Fake Binance Ads Steal Your Data
  5. Fancy Bear Returns: APT28 Exploits Office Flaw in “Operation Neusploit”
Tags: Industrial Safety Systems

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
  • CVE-2026-9435CVSS 9.8
    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9434CVSS 9.8
    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is...
  • CVE-2026-9433CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-2651CVSS 9.0
    A vulnerability in MLflow versions
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.