Skip to content
June 23, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Malware
  • US Department of Homeland Security alert Malware Targeting Industrial Safety Systems
  • Malware

US Department of Homeland Security alert Malware Targeting Industrial Safety Systems

Do Son December 21, 2017 3 minutes read
Industrial Safety Systems
Add as a preferred
source on Google

Network security companies FireEye and Dragos reported last week that the new malware, Triton, and Trisis, shut down some Middle East agencies by damaging the widely used Schneider Electric Triconex safety controller in key infrastructure. It is reported that Cyber Cyber company CyberX speculated on the basis of speculation that the behind-the-scenes blackmailing of this cyber attack may be planned by Iran and its target is an important agency suspected of being in Saudi Arabia. The National Security and Communications Integration Center (NCCIC) of the Department of Homeland Security (DHS) released an analysis of malware for the industrial security system on Monday.

the US Department of Homeland Security ( DHS ) researchers have found another new malware in the investigation in the near future Hatman, aimed against the state industrial control system ( ICS launched attacks). Subsequently, the National Network Security and Communications Integration Center ( NCCIC ) provided mitigation and YARA rules in a malware analysis released this Monday to reduce the loss of national industrial control systems. 

Surveys show that HatMan malware written in Python is primarily targeted at Schneider Electric’s Triconex Safety Instrumented System (SIS) controllers and is designed to monitor processes and restore them to a safe state or perform safety shutdowns when potentially dangerous situations are identified. In addition, HatMan communicates with SIS controllers via proprietary TriStation protocols and allows attackers to manipulate devices by adding new ladder logic. However, as the hacker terminated the operation after triggering the SIS controller to start the “Safe Shutdown” feature, FireEye experts speculated that the attacker could inadvertently trigger the controller during the detection phase, with the ultimate goal being to simply inflict high SIS physical damage Interested.

Schneider Electric’s Triconex Safety Monitoring System (SIS) controller is designed to provide continuous safety interlocking and protection, process monitoring and safe parking where necessary, for safety and critical units in nuclear, oil refining, petrochemical, chemical and other process industries.

It is noteworthy that NCCIC pointed out in its report that the malware mainly has two components: one is to interact with the safety controller after the damaged PC is running, and the other is to run directly on the controller. The researchers said that although HatMan itself did not do any dangerous actions and the downgraded infrastructure security system did not directly manipulate the entire control process, it could be extremely harmful if flawed security systems were infected with malware. In addition, it is safe to say that although HatMan may become an important tool for monitoring ICS in the future, it may only be used to affect industrial processes or other dangerous operations. All in all, the building of different components in malware means that an attacker needs to be very familiar with the ICS environment, especially with Triconex controllers, and it needs a longer development cycle to refine this sophisticated attack.

Schneider Electric has investigated the incident. Officials said there is currently no evidence that the malware exploits any loopholes in the product. However, security experts advise customers not to easily place the device in “Program” mode because an attacker could potentially send the payload via malware when the controller is set to “Program” mode.

Emily S. Miller, director of the National Security Agency, said: “Attackers have the ability to access critical infrastructure security instrumentation and are likely to make potential changes to device firmware, so this reminder gives key owners and operators critical infrastructure The warning. ”

Source: Securityweek 

Related coverage

  • Silver Fox Strikes with Fake Installers: Sainbox RAT and Hidden Rootkit Target Chinese Speakers
  • Tiny FUD: Fully Undetectable macOS Backdoor Discovered
  • WikiLoader Malware Evolves with SEO Poisoning, Targets GlobalProtect Users
  • SpyMax – A New Android RAT Targeting Telegram Users
  • New IoT Botnet DoubleDoor use two flaws to bypass firewall

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Industrial Safety Systems

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-54157CVSS 9.0
    LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent...
  • CVE-2026-53662CVSS 9.6
    immich is a high performance self-hosted photo and video management solution. From...
  • CVE-2026-54350CVSS 10.0
    ## Summary `enrichContext` at `packages/server/src/sdk/workspace/queries/queries.ts:121-138` substitutes parameter values into the raw JSON...
  • CVE-2026-55255CVSS 9.9
    Langflow is a tool for building and deploying AI-powered agents and workflows....
  • CVE-2026-55447CVSS 9.6
    Langflow is a tool for building and deploying AI-powered agents and workflows....
  • CVE-2026-55450CVSS 9.3
    Langflow is a tool for building and deploying AI-powered agents and workflows....
  • CVE-2026-48519CVSS 9.6
    Langflow is a tool for building and deploying AI-powered agents and workflows....
  • CVE-2026-52813CVSS 10.0
    ### Summary Organization names containing path traversal sequences (`../`) are accepted by...
  • CVE-2026-52811
    Summary `(*Repository).UploadRepoFiles` checks for symlinks only on the **leaf** of the upload...
  • CVE-2026-52806CVSS 9.9
    # Gogs: RCE via `git rebase --exec` Argument Injection in PR Merge...
Powered by CVE WATCHTOWER

🚨 Active Exploits in the Wild

  • CVE-2026-20230CVSS 8.6
    A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified...
  • CVE-2026-4020CVSS 7.5
    The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and...
  • CVE-2026-10735
    Multiple plugins by ShapedPlugin contain a backdoor in various versions. This makes it possible for unauthenticated attackers to...
  • CVE-2026-20262CVSS 6.5
    A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,...
  • CVE-2026-54420CVSS 8.5
    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a...
  • CVE-2026-53435CVSS 8.8
    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize...
  • CVE-2026-10795CVSS 8.1
    The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions...
  • CVE-2026-11645
    Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker...
  • CVE-2026-50751CVSS 9.3
    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows...
  • CVE-2026-20245CVSS 7.8
    A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local...
Powered by CVE Watchtower

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.