Cyber Attacks Against the Oil and Gas Sector.
OT/ICS
Critical Infrastructure

Key Takeaways
- The ICS malware that has hit this sector directly: Triton and Trisis against safety instrumented systems, plus Havex and Flame, and what each one did once inside.
- The activity groups that reached Stage 2 of the ICS Cyber Kill Chain: XENOTIME, MAGNALLIUM and CHRYSENE, with the incidents attributed to each.
- How OEM, third-party vendor and supply chain dependencies turn into ICS exposure, with vendor product vulnerabilities as worked examples.
- Purdue model segmentation, perimeter firewall placement, IDS and IPS coverage, and the standards to align to: ISA/IEC 62443, the NIST framework, API 1164 and IEC 27019.
What's inside
Oil and gas run on control systems designed for availability and safety, not for adversaries. The attacks that matter here do not end at data theft. Triton targeted a safety instrumented system, which is the last control standing between a process upset and a physical incident.
This report evaluates the attacks the sector has actually taken, names the activity groups behind them, and works through the supply chain paths that keep reopening. The recommendations are written for ICS and SCADA environments and mapped to the Purdue model, not carried over from enterprise IT.
What the 25 pages cover
Look inside













