Darknet Diaries

68: Triton


Listen Later

A mysterious mechanical failure one fateful night in a Saudi Arabian chemical plant leads a cast of operational technology researchers down a strange path towards an uncommon, but grave, threat. In this episode, we hear how these researchers discovered this threat and tried to identify who was responsible for the malware behind it. We also consider how this kind of attack may pose a threat to human life wherever there are manufacturing or public infrastructure facilities around the world.

A big thanks to Julian GutmanisNaser AldossaryMarina Krotofil, and Robert M. Lee for sharing their stories with us.

Sponsors

This episode was sponsored by IT Pro TV. Get 65 hours of free training by visiting ITPro.tv/darknet. And use promo code DARKNET25.

This episode was sponsored by Linode. Linode supplies you with virtual servers. Visit linode.com/darknet and when signing up with a new account use code darknet2020 to get a $20 credit on your next project.

Sources

  • https://www.fireeye.com/blog/threat-research/2019/04/triton-actor-ttp-profile-custom-attack-tools-detections.html
  • https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html
  • https://www.fireeye.com/blog/threat-research/2018/10/triton-attribution-russian-government-owned-lab-most-likely-built-tools.html
  • https://dragos.com/wp-content/uploads/TRISIS-01.pdf
  • Video S4 TRITON - Schneider Electric Analysis and Disclosure
  • Video S4 TRITON - Mandiant Analysis at S4x18
  • Video S4 TRITON - Reverse Engineering the Tricon Controller by Dragos
  • Video S4 TRITON - A Report From The Trenches
  • Video - Safety Orientation video for the Chemical Plant
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Darknet DiariesBy Jack Rhysider

    • 4.9
    • 4.9
    • 4.9
    • 4.9
    • 4.9

    4.9

    7,727 ratings


    More shows like Darknet Diaries

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,981 Listeners

    Risky Business by Patrick Gray

    Risky Business

    364 Listeners

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    640 Listeners

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

    Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

    371 Listeners

    Hacked by Hacked

    Hacked

    181 Listeners

    CyberWire Daily by N2K Networks

    CyberWire Daily

    1,017 Listeners

    Smashing Security by Graham Cluley

    Smashing Security

    316 Listeners

    Click Here by Recorded Future News

    Click Here

    407 Listeners

    Malicious Life by Malicious Life

    Malicious Life

    925 Listeners

    Cybersecurity Today by Jim Love

    Cybersecurity Today

    163 Listeners

    Hacking Humans by N2K Networks

    Hacking Humans

    311 Listeners

    Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

    Defense in Depth

    76 Listeners

    Cyber Security Headlines by CISO Series

    Cyber Security Headlines

    128 Listeners

    Risky Bulletin by risky.biz

    Risky Bulletin

    43 Listeners

    Hacker And The Fed by Chris Tarbell & Hector Monsegur

    Hacker And The Fed

    168 Listeners