The Triton malware is designed to target Schneider Electrics Triconex Safety Instrumented System (SIS) controllers that are used in industrial environments to monitor the state of a process and restore it to a safe state or safely shut it down if parameters indicate a potentially hazardous situation. The attack was likely developed by Iran and used to target an organization in Saudi Arabia. The malware requires the keyswitch to be in the PROGRAM mode in order to deliver its payload.”]
Source: https://securityaffairs.co/wordpress/67957/malware/triton-malware-zero-day-sis.html