Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On October 23, 2020, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) designated the Russian government-controlled research institute TsNIIKhM under Section 224 of the Countering America’s Adversaries Through Sanctions Act (CAATSA). Treasury said the institute supported the 2017 Triton attack on an industrial safety system. The designation was an administrative sanctions action—not a criminal court finding.

What is Triton malware?

Triton, also known as TRISIS and HatMan, is malware designed to target industrial safety systems. These systems monitor industrial processes and can trigger an emergency shutdown when conditions become unsafe. Treasury said the malware was designed to give attackers control over infected systems, creating the potential for physical damage and loss of life. Treasury’s October 23, 2020 account describes the malware and the institute’s alleged role.

What did Triton do to the refinery’s safety system?

Treasury placed the attack in August 2017 at a petrochemical facility in the Middle East. Its account says operators initially delivered the malware through phishing and then tried to manipulate industrial control system controllers. Several controllers entered a fail-safe state and automatically shut down the facility. That response prevented the malware from achieving its full functionality and helped prompt the investigation that uncovered it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a 2022 announcement summarizing a June 2021 indictment, the Department of Justice (DOJ) said prosecutors alleged that TsNIIKhM employee Evgeny Gladkikh and co-conspirators installed Triton on a Schneider Electric safety system at a foreign refinery, causing two automatic emergency shutdowns. DOJ also said the indictment alleged later unsuccessful attempts to hack systems belonging to a U.S. company. Those are allegations in a criminal case, not findings that the conduct was proved in court. DOJ states that defendants are presumed innocent unless proven guilty beyond a reasonable doubt. Read DOJ’s March 24, 2022 announcement.

#1 Best Overall
Sale
Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment
  • Industrial Cybersecurity: Efficiently monitor the cybersecurity posture of your ICS environment, 2nd Edition
  • ABIS BOOK
  • Packt Publishing

Why did the U.S. sanction TsNIIKhM?

Treasury said TsNIIKhM—a Russian government-controlled research institution formally named the State Research Center of the Russian Federation FGUP Central Scientific Research Institute of Chemistry and Mechanics—supported the Triton attack. Treasury described it as responsible for building customized tools that enabled the attack. OFAC designated the institution on October 23, 2020 under CAATSA Section 224, citing significant activities that knowingly undermined cybersecurity on behalf of the Russian government. The designation and Treasury’s attribution are administrative government actions; they should not be confused with a criminal verdict.

Treasury also reported that the actors behind Triton were reported in 2019 to have scanned and probed at least 20 U.S. electric utilities for vulnerabilities. This is a figure Treasury attributed to reported activity, not a count of successful intrusions. In its statement announcing the designation, Treasury Secretary Steven T. Mnuchin said: “The Russian Government continues to engage in dangerous cyber activities aimed at the United States and our allies,” and added, “This Administration will continue to aggressively defend the critical infrastructure of the United States from anyone attempting to disrupt it.” Treasury’s release also characterized the threat actors using a description it attributed to private cybersecurity industry: “the most dangerous threat activity publicly known.”

How the Treasury designation differs from the DOJ case

The events involve separate legal processes and should not be treated as interchangeable:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Action What it means
OFAC designation of TsNIIKhM, October 23, 2020 An administrative sanctions action under CAATSA Section 224. Treasury stated the institute supported the Triton attack.
DOJ indictment announced March 24, 2022 A criminal prosecution based on allegations against Gladkikh and co-conspirators. An indictment is not proof of guilt; DOJ says defendants are presumed innocent unless proven guilty beyond a reasonable doubt.

DOJ Deputy Attorney General Lisa O. Monaco said: “Russian state-sponsored hackers pose a serious and persistent threat to critical infrastructure both in the United States and around the world.” That statement accompanied DOJ’s announcement; it does not change the evidentiary status of the indictment’s allegations.

What does an OFAC blocking designation mean?

Treasury said the designation blocks TsNIIKhM property and interests in property that are within the United States or in the possession or control of U.S. persons. U.S. persons are generally prohibited from transacting with the designated entity unless an authorization applies. OFAC’s 50 Percent Rule also means an entity owned, directly or indirectly, 50 percent or more in aggregate by one or more blocked persons is itself blocked, even if it is not separately named on the list. Treasury warned that some transactions by non-U.S. persons may also create sanctions exposure. For the agency’s general information, visit OFAC.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changed in 2022, and how to check current status

On April 20, 2022, Treasury announced additional CAATSA Section 224(a)(1)(B) designations of Gladkikh, TsNIIKhM general director Sergei Bobkov, and deputy general director Konstantin Malevany, saying they acted or purported to act for or on behalf of the institute. This was a later Treasury action, distinct from the institute’s 2020 designation. The announcement does not establish whether any person remains listed today. Treasury’s April 20, 2022 announcement describes that action.

Sanctions lists, licenses, and guidance can change. Before making a present-day compliance decision, check current OFAC materials and search the official Sanctions List Search record. A historical press release is not a substitute for checking current status or obtaining advice for a specific transaction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.