Statue of Triton, son of Neptune, Nicola Salvi's Trevi Fountain, Italy. Photo: DeAgostini/Getty Images

The attackers who launched TRITON, a notorious industrial-system-focused malware only known to have been used once, have struck a second target, according to researchers at FireEye presenting at the Kaspersky Lab SAS Summit in Singapore.

Why it matters: FireEye was the first to discover TRITON, which startled researchers by amassing an uncommon amount of control over industrial systems. Due to a mistake in the attack, it inadvertently led to a plant shutdown and nearly caused a deadly explosion. While no one expected TRITON to be a one-time affair, its resurgence is jarring.

Background: The victim of the first attack was not identified by FireEye, but a harrowing account of the attack in E&E News revealed it to be the Petro Rabigh refinery in the Red Sea.

  • FireEye later attributed the design of components of the TRITON malware to a research institute in Moscow.

Details: The new victim, also not identified by FireEye, revealed the use of hacking tools not seen in the first attack.

  • The tools appear to date from as far back as 2014, though FireEye has never seen them in use in the past.
  • FireEye reported indicators and recommended techniques defenders can use to identify and thwart future TRITON attacks.
  • "[W]e strongly encourage industrial control system (ICS) asset owners to leverage the indicators, TTPs [tactics, techniques and procedures], and detections," FireEye wrote in its official report.

Go deeper

Updated 1 hour ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 5 p.m. ET: 12,382,748 — Total deaths: 557,241 — Total recoveries — 6,796,045Map.
  2. U.S.: Total confirmed cases as of 5 p.m. ET: 3,163,505 — Total deaths: 133,847 — Total recoveries: 969,111 — Total tested: 38,032,966Map.
  3. Public health: The reality of the coronavirus bites.
  4. Trade: Trump says he's no longer considering phase-two trade deal with China because the pandemic damaged the two countries' relationship.
  5. 🎧 Podcast: Rural America has its own coronavirus problem.
1 hour ago - Health

Reality of the coronavirus bites

National Airport in D.C. Photo: Daniel Slim/AFP/Getty Images

It feels like mid-March in America again. The coronavirus is surging, deaths are climbing and the country is dreading a wave of disruptions, less than four months since the first round started.

The big picture: Lingering under all the happy talk of future plans is the reality of this virus — which thrives in potential super-spreader conditions like mass gatherings.

2 hours ago - Podcasts

Rural America has its own coronavirus problem

It's often easier to socially distance in rural America, but it can simultaneously be more challenging to get medical care.

Axios Re:Cap digs into the pandemic's urban-rural divide with microbiologist Amber Schmidtke, who has found that coronavirus-related morbidity is higher in many of Georgia's rural counties than in Atlanta.