The plant had shut itself down, which is what it was built to do. In August 2017, at a petrochemical complex widely reported to be in Saudi Arabia, several of the Schneider Electric Triconex controllers that watch pressure, temperature and flow tripped into a failed-safe state and took the process down with them. Nothing burst and nobody was hurt; the owners might have logged it as a fault and moved on. Instead, investigators working through the engineering workstation found a file called trilog.exe, dressed as the legitimate Triconex utility for reviewing logs. It was nothing of the kind. On 14 December 2017 FireEye's Mandiant unit published its analysis of what it was: an attack framework, which the firm named Triton, built for the safety controllers themselves.
Triconex machines are safety instrumented systems, the layer beneath the ordinary controls whose only work is the last resort — vent the pressure, close the valve, shut everything down when the physics goes wrong. Triton spoke to them in TriStation, Schneider's proprietary and undocumented protocol, which someone had patiently reverse-engineered; it could read a controller's safety logic and write its own. It got its chance because the physical keyswitch on the front of each controller, which must sit in Program mode before the device will accept new code, had been left there. Dragos, analysing the same code that week under the name Trisis, counted it as only the fifth malware family ever tailored to industrial control systems, after Stuxnet, Havex, BlackEnergy2 and CrashOverride — and the first aimed at safety.
The mercy was in the failure. FireEye assessed that the attackers were still building — pre-positioning for an attack capable of physical damage — when their injected code failed a validation check between two redundant processing units. The controllers did the conservative thing and tripped the plant, and the shutdown that cost the owner production is what summoned the investigators. FireEye said it was moderately confident a nation-state was preparing an attack, and named no one. Within days the US ICS-CERT circulated its own analysis under a third name, HatMan, while Schneider Electric — which at first said there was no evidence a vulnerability in its product had been used — confirmed the following month that Triton had exploited a zero-day flaw in older Tricon firmware.
December's coverage filled in the scale. Reuters, citing people familiar with the inquiry, placed the plant in Saudi Arabia and counted the Triconex install base at about 18,000 sites — nuclear stations, refineries, chemical works. FireEye would not name the victim, and never has; American trade reporters later identified it as the Petro Rabigh complex on the Red Sea coast, which neither company confirmed. Later reporting also established that the plant had tripped once before, in June 2017, an outage written off at the time as a mechanical fault; August was the second time. The plant restarted and production resumed. The only casualty of the first known attack on a safety system was an assumption — that this layer, of all layers, was off limits.
Mirai's authors, by name
The plea agreements were entered quietly in federal court in Anchorage on 8 December and unsealed the following week, when the Justice Department announced them on the 13th. Paras Jha, 21, of Fanwood, New Jersey; Josiah White, 20, of Washington, Pennsylvania; and Dalton Norman, 21, of Metairie, Louisiana, admitted to creating and running Mirai, the botnet that conscripted hundreds of thousands of cameras, routers and video recorders by walking through a short list of factory-default passwords. It had grown out of the protection-racket economics of Minecraft server hosting. The three were not charged over the most famous thing done in Mirai's name: after its source code was published in September 2016, other hands used it that October against the DNS provider Dyn, breaking Twitter, Netflix and much of the American internet for a morning. Jha also pleaded guilty in New Jersey on 13 December to repeatedly downing Rutgers University's network between 2014 and 2016, timing attacks to exams and registration. In September 2018 a judge in Alaska, crediting extensive undercover work for the FBI, gave all three probation, 2,500 hours of community service and restitution — no prison.
4,700 bitcoin leave the building
On the morning of 6 December 2017, in the steepest week of bitcoin's steepest year, the Slovenian company NiceHash — a marketplace where anyone could rent out a graphics card's hashing power — halted its service and said its payment system had been compromised. Roughly 4,700 bitcoin were gone from the company's internet-connected wallet: about $64 million at that day's price, and reported as $70 million or more within a day, because the price would not hold still. The next day the chief executive, Marko Kobal, and co-founder Sasa Coh appeared on Facebook Live to say what the company knew — an employee's computer had been compromised, the attacker had used those credentials, and the intrusion had probably come from an IP address outside the European Union. Anyone could watch the coins sitting in a single public wallet address. Kobal resigned on 21 December. The service reopened before the year ended, with a promise it kept slowly and completely: repayment ran in monthly instalments for three years, until 16 December 2020, when NiceHash said the last of the stolen balance had been returned in full.
The subsidy that changed banks
Through the autumn of 2017, millions of Airtel subscribers stood in shops, pressed a thumb to a fingerprint scanner to re-verify a SIM against Aadhaar, and walked out owning a bank account they did not know existed. The same eKYC touch that verified the SIM was also being used to open an Airtel Payments Bank account; and because the government's benefit pipeline pays into the most recently Aadhaar-seeded account, cooking-gas subsidies quietly changed address. Contemporary reports put about ₹190 crore of LPG subsidy into some 31 lakh such accounts. On 16 December 2017, after months of complaints, the Unique Identification Authority of India suspended the Aadhaar eKYC licences of both Bharti Airtel and Airtel Payments Bank.
Airtel deposited an interim penalty of ₹2.5 crore with the authority, described the subsidy diversions as the result of a technical glitch, and undertook to the National Payments Corporation of India to return the ₹190 crore, with interest, to the accounts customers had originally chosen. Refunds followed, and UIDAI provisionally allowed SIM verification to resume within the week while the payments bank stayed dark. The bank's chief executive resigned within weeks, the Reserve Bank of India added a ₹5 crore penalty for KYC failures in March 2018, and new account openings resumed only that July. The episode outlived its refunds as the canonical demonstration that in the Aadhaar ecosystem a fingerprint given for one purpose could silently serve another — the argument the Supreme Court heard through 2018, before its September judgment removed private companies from Aadhaar authentication altogether.
AlphaZero's clean sweep, and a new word
On 5 December 2017 DeepMind posted a preprint describing AlphaZero: one reinforcement-learning algorithm which, given nothing but the rules, taught itself chess, shogi and Go, and beat the strongest specialist program in each — taking a 100-game chess match off Stockfish with 28 wins, 72 draws and no losses. Grandmasters admired the sacrificial, romantic style; engine developers objected to the terms Stockfish played under; nobody much disputed the direction. Six days later, on 11 December, Motherboard reported that a reddit user posting as 'deepfakes' was using open-source machine-learning tools, a home computer and publicly available footage to paste the faces of actresses into pornographic videos they had never made. The report was sober and its implication plain: fabricated video had reached hobbyist hardware, and its first use was against women who had not consented. The pseudonym became the noun. Later editions of this archive use 'deepfake' without explanation — for fraud, for elections, for the laws eventually written against it — and this is the month the word begins.
The Kaspersky ban becomes statute
On 12 December 2017 President Trump signed the National Defense Authorization Act for fiscal 2018, and with it Section 1634: from October 2018, no part of the federal government may use hardware, software or services from Kaspersky Lab. What the GSA had done by delisting in July and DHS by directive in September, Congress had now written into statute, by name — the end of the year's long unwinding, on suspicion rather than published evidence. Kaspersky, which denied throughout that it had ever assisted any government's espionage, sued on 18 December, arguing the DHS order rested on anonymously sourced press reports and denied it due process; the courts disagreed in 2018, and by 2024 Washington had extended the ban to ordinary American customers. The defending industry had its own embarrassment that month: at Black Hat Europe in London, enSilo researchers demonstrated Process Doppelgänging, a fileless code-injection technique abusing NTFS transactions that evaded every antivirus engine tested against it, Kaspersky's included — and turned up in ransomware within months.
⏳ Time capsule — December 2017
- President Trump signed the Tax Cuts and Jobs Act on 22 December — the largest rewrite of the US tax code since 1986, and the signature legislation of his first year in office.
- Bitcoin touched $19,783 on 17 December, between the launch of Cboe's futures on the 10th and CME's on the 18th, then ended the year near $14,000.
- Star Wars: The Last Jedi opened on 15 December to a $220 million US weekend — at the time the second-largest opening ever, behind only The Force Awakens.
- In Stockholm on 10 December, Rainer Weiss, Barry Barish and Kip Thorne received the Nobel Prize in Physics for LIGO's detection of gravitational waves.
The layer that held
Triton's authors were eventually given an address. In October 2018 FireEye linked the malware's development to the Central Scientific Research Institute of Chemistry and Mechanics, a Russian government institute in Moscow; in October 2020 the US Treasury sanctioned the institute for it; in March 2022 the Justice Department unsealed charges against one of its employees, who remains in Russia, untried — allegations they are likely to stay. The same crew was found inside a second facility in 2019, and the FBI was still warning about it in 2022. The category Triton opened never closed: Pipedream, the multi-vendor control-system attack toolkit disclosed in April 2022 — the same month Ukraine caught Industroyer's successor reaching for its grid — was found before it was ever used.
The rest of the month's ledger closed, by this archive's standards, gently. The Mirai three spent their probation working for the FBI — the sentencing filings credited more than a thousand hours — and IoT botnets outlived their creators' retirement to reappear throughout these pages. NiceHash finished paying everyone back in December 2020, in a currency worth more than when it was taken. Airtel got its licences back with riders, and then the mechanism itself went: the Supreme Court's September 2018 judgment ended private Aadhaar authentication, and the consent question waited until the DPDP Act of 2023 for a statutory answer. When an American pipeline shut itself down out of caution in May 2021, the question of December 2017 had scaled up: how far do you trust the layer underneath?