Security experts from security firms FireEye and Dragos reported the discovery of a new strain of malware dubbed Triton (aka Trisis) specifically designed to target industrial control systems. CyberX who analyzed samples of the malware believes it was likely developed by Iran and used to target an organization in Saudi Arabia. Iran was responsible for destructive attacks on Saudi Arabian IT networks in 2012 and more recently in 2017 with Shamoon, which destroyed ordinary PCs. The attack caused a shutdown at a critical infrastructure organization somewhere in the Middle East.”]
Source: http://securityaffairs.co/wordpress/66784/malware/triton-malware-iran.html