Mysterious Trisis Malware Strikes Again
ID: 70928602-482e-5337-aa44-9ba18ecb86ea
STIX ID: report--70928602-482e-5337-aa44-9ba18ecb86ea
Feed Name: Security Ledger
Threat Score
**FireEye reports TRITON (TRISIS) has resurfaced at a Middle East critical‑infrastructure site, with attackers using persistent, stealthy reconnaissance and custom tools to access SIS engineering workstations and deploy a TRITON backdoor; FireEye links the toolset to a Russian government research institute and ties the activity to the XENOTIME actor, warning of potential disruptive or destructive consequences.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
