Cyber Attacks Against the Oil and Gas Sector.

Triton changed what an attack on this sector means: not stolen data, but a safety instrumented system told to stand down. This report walks the malware, the activity groups behind it, and the controls that hold in an ICS environment.

OT/ICS

Critical Infrastructure

Anand Papad, Amit Musale
Pages:
25
Format:
PDF
Level:
Intermediate
Updated:
Oct 2026
Pages:
25
Format:
PDF
Level:
Intermediate
Updated:
Oct 2026

Key Takeaways

  • The ICS malware that has hit this sector directly: Triton and Trisis against safety instrumented systems, plus Havex and Flame, and what each one did once inside.
  • The activity groups that reached Stage 2 of the ICS Cyber Kill Chain: XENOTIME, MAGNALLIUM and CHRYSENE, with the incidents attributed to each.
  • How OEM, third-party vendor and supply chain dependencies turn into ICS exposure, with vendor product vulnerabilities as worked examples.
  • Purdue model segmentation, perimeter firewall placement, IDS and IPS coverage, and the standards to align to: ISA/IEC 62443, the NIST framework, API 1164 and IEC 27019.

What's inside

Oil and gas run on control systems designed for availability and safety, not for adversaries. The attacks that matter here do not end at data theft. Triton targeted a safety instrumented system, which is the last control standing between a process upset and a physical incident.

This report evaluates the attacks the sector has actually taken, names the activity groups behind them, and works through the supply chain paths that keep reopening. The recommendations are written for ICS and SCADA environments and mapped to the Purdue model, not carried over from enterprise IT.

What the 25 pages cover

01
Cyber attacks against the oil and gas sector
p. 4
Why this sector is targeted, and what an attacker gains by reaching the process layer.
02
Evaluation of attacks on the sector
p. 6
What has been attempted, what succeeded, and the pattern across incidents.
03
Threats that can compromise the industry
p. 11
Phishing, uncontrolled external email, and supply chain compromise as entry paths.
04
ICS malware and supply chain exposure
p. 13
Triton, Flame, Havex, and the OEM and vendor scenarios that carried them in.
05
Activity groups and detailed attack analysis
p. 16
XENOTIME, MAGNALLIUM, CHRYSENE, and a breakdown of infrastructure attacks.
06
Recommendations and the standards to follow
p. 16
Purdue segmentation, firewalls, IDS and IPS, logging, and the guidelines to align to.

Look inside

A sample spread — the level of detail in every chapter.
Written by Payatu's OT security practice
Former Director at Payatu, working on OT/ICS and critical infrastructure security and web and application security. Has authored 3 blogs, 2 talks/webinars for Payatu.
Dark background with a smooth, flowing red wave shape across the image.

Keep the attack map on your desk

The full 25-page PDF, written to be printed and annotated. Malware and activity groups on one side, the recommendations and standards on the other.
Keep going

More from the Payatu library

Securing Salesforce: Pentesting and Config Review.
PDF:
59
pages
Cloud & SaaS
Securing Salesforce: Pentesting and Config Review.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Akanksha Prasad, Prajyot Chemburkar
All You Need to Know About the ISA/IEC 62443 Standard.
PDF:
36
pages
OT & ICS
All You Need to Know About the ISA/IEC 62443 Standard.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Amit Musale, Rohit Kumar
Cybersecurity Playbook for IPO-Bound Fintech Companies in India.
PDF:
38
pages
GRC & Compliance
Cybersecurity Playbook for IPO-Bound Fintech Companies in India.
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.
Team Payatu