triton
TRITON is a threat actor and associated malware activity set linked in the provided content to industrial control system targeting. The content describes discovery rules for TRITON actor TTPs, including artifacts reportedly seen used heavily by TRITON such as modified or repurposed Bitvise SSH, OpenSSH, and Cryptcat tools, unusual PE metadata, embedded OpenSSH private key material, and characteristic PDB path patterns including Visual Studio 2010 Documents paths and C:\Users\user. Related network detections in the content include Bitvise SSH Server banners on non-standard ports, including port 443, and an RDP pattern consistent with default Windows hostnames. The content also states that TRITON malware was engineered to target the safety instrumented systems (SIS) of a petrochemical plant, with the potential to cause a catastrophic industrial accident. No additional aliases, sub-groups, or nation-state attribution are directly stated in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
3 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TRITON is a malware specifically designed to target safety instrumented systems in industrial environments, with the potential to cause catastrophic physical damage.
The content describes detection/hunting logic for TRITON’s tradecraft, highlighting repeated use of modified/masqueraded remote-access tooling (Bitvise SSH Server/client artifacts, modified OpenSSH binaries including hard-coded private key strings, customized Cryptcat with default/custom passwords) and developer-artifact leakage in Windows PE PDB paths (e.g., Visual Studio 2010 and C:\Users\user\). Also includes network signatures for Bitvise SSH banners on non-standard ports/443 and an RDP default-hostname pattern.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.