Trihash is an online criminal persona named alongside LAPSUS$, Scattered Spider, IntelBroker, and several other handles in a public claim that those actors were "going dark." Available high-confidence information ties Trihash only to that self-referential claim and to broader boasting about disruptive intrusions and possible data breaches against major companies and government-related systems. Those claims included alleged activity affecting large enterprises in aviation, luxury goods, automotive manufacturing, cloud and security technology, and possible law-enforcement data exposure, but the reporting also assessed the statement as likely containing substantial disinformation. On the currently available evidence, Trihash cannot be reliably separated from the surrounding cluster of aliases or confidently attributed to a specific intrusion set, country of origin, victimology pattern, or operational tradecraft. The persona should therefore be treated as an unverified criminal handle with insufficient corroborated detail for stronger attribution.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.