TRIPLESTRENGTH is a financially motivated threat actor tracked since 2023 for opportunistic attacks against cloud environments, particularly for cryptojacking, and for ransomware activity affecting on-premises systems. The actor has been associated with theft of credentials and session cookies, including use of credentials obtained from Raccoon infostealer logs, followed by hijacking of cloud service accounts to provision compute resources for cryptocurrency mining. Reported tradecraft includes abuse of highly privileged cloud identities and billing permissions, including adding attacker-controlled billing contacts and using that access to create larger cloud compute instances for mining operations. TRIPLESTRENGTH has also been linked to use of unMiner to deploy bundled cryptocurrency miners. The group’s observed behavior centers on post-compromise monetization through unauthorized cloud resource consumption and ransomware, with emphasis on account hijacking, cloud abuse, and credential-driven intrusion rather than bespoke espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cloud abuse actor that steals credentials and session cookies, hijacks cloud service accounts, adds attacker-controlled billing contacts, and creates Compute Engine instances for cryptocurrency mining.
Financially motivated actor opportunistically targeting cloud environments for cryptojacking and on-premises environments for ransomware deployment.
Financially motivated group targeting cloud environments for cryptojacking and on-premises systems for ransomware and extortion. Also sells access to compromised cloud platforms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.