TRITON is a threat actor designation referenced in the provided content in connection with tooling and TTPs associated with the TRITON intrusion set, and also with the TRITON malware engineered to target safety instrumented systems (SIS) in industrial environments. The content explicitly states that TRITON malware was designed to target the SIS of a petrochemical plant, with the potential to cause a catastrophic industrial accident, placing it in the ICS/OT threat landscape. Supporting material includes discovery rules for TRITON actor TTPs and notes artifacts reportedly seen used heavily by the actor, including modified Bitvise/OpenSSH binaries, Cryptcat variants, and characteristic PDB path patterns. The content also cites Triton (Fibbit) as an example of malware using steganography. Based on the provided material, TRITON is associated with industrial targeting, particularly petrochemical/critical infrastructure environments, and with customized administrative and tunneling tooling. Known alias directly mentioned in the content: Fibbit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/activity cluster explicitly listed as using steganography in attacks.
TRITON is a malware specifically designed to target safety instrumented systems in industrial environments, with the potential to cause catastrophic physical damage.
The content describes detection/hunting logic for TRITON’s tradecraft, highlighting repeated use of modified/masqueraded remote-access tooling (Bitvise SSH Server/client artifacts, modified OpenSSH binaries including hard-coded private key strings, customized Cryptcat with default/custom passwords) and developer-artifact leakage in Windows PE PDB paths (e.g., Visual Studio 2010 and C:\Users\user\). Also includes network signatures for Bitvise SSH banners on non-standard ports/443 and an RDP default-hostname pattern.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.