TRITON is an industrial intrusion threat associated with malware engineered to target safety instrumented systems (SIS) in petrochemical and other industrial control system environments. The operation is widely tracked in connection with the TRITON malware, also known as Triton or associated in some reporting with Fibbit. Its tradecraft is notable for focusing on operational technology rather than conventional enterprise objectives, with the potential to cause physical process disruption and catastrophic safety consequences. TRITON-related activity has been linked to tooling and procedures used after initial compromise inside Windows-based environments that support industrial operations. Reported discovery artifacts associated with the actor include modified or repurposed remote administration and tunneling utilities, customized SSH tooling, altered Cryptcat variants, and binaries bearing characteristic PDB path patterns. These behaviors indicate post-compromise operational capability including persistence, lateral movement, remote access enablement, and defense evasion through use of legitimate or dual-use software. The actor has also been associated with steganographic techniques in malware tradecraft, including use of hidden data within image files as part of covert payload delivery or command-and-control concealment. In the broader ICS context, TRITON stands out because its malware was specifically designed to interact with SIS environments, distinguishing it from most threat activity that targets only IT networks or standard OT visibility and control layers. TRITON is best understood as a high-consequence industrial threat actor or intrusion set centered on sabotage-capable malware for safety systems. Publicly available information in this dataset supports its role as an ICS-focused actor, but does not provide high-confidence attribution to a specific country or enumerate a broader alias set beyond Triton and Triton_actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/activity cluster explicitly listed as using steganography in attacks.
TRITON is a malware specifically designed to target safety instrumented systems in industrial environments, with the potential to cause catastrophic physical damage.
The content describes detection/hunting logic for TRITON’s tradecraft, highlighting repeated use of modified/masqueraded remote-access tooling (Bitvise SSH Server/client artifacts, modified OpenSSH binaries including hard-coded private key strings, customized Cryptcat with default/custom passwords) and developer-artifact leakage in Windows PE PDB paths (e.g., Visual Studio 2010 and C:\Users\user\). Also includes network signatures for Bitvise SSH banners on non-standard ports/443 and an RDP default-hostname pattern.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.