Trigona — Ransomware Profile
Trigona ransomware targets MSSQL servers for initial access, attacking organizations across multiple sectors globally.Tools & malware
- Advanced Port Scanner network-discovery
- Cobalt Strike post-exploitation
- MEGA exfiltration
- Mimikatz credential-access
- Rclone exfiltration
- SoftPerfect NetScan network-discovery
- Splashtop remote-access
- Trigona (ransomware encryptor) ransomware
Recent claimed victims
- Claro 2024-03-30
- South Star Electronics 2024-03-20
- Bwizer 2024-03-16
- Indoarsip 2024-03-16
- Topa Partners 2024-03-16
- ATMCo 2024-03-15
- Dinamic Oil 2024-02-28
- Hotel Avenida, Hostal Espoz y Mina, Hostal Arriazu, Pension Alemana 2024-02-28
- America Movil 2024-02-14
- FALCO Electronics 2024-02-14
- Daher Contracting 2024-01-31
- Genesis Motors 2024-01-31
- CMG Drainage Engineering 2024-01-31
- Ausa 2024-01-31
- Lomma Crane & Rigging 2024-01-29
- Fertility North 2024-01-18
- Samuel Sekuritas Indonesia & Samuel Aset Manajemen 2024-01-18
- Premier Facility Management 2024-01-18
- Vision Plast 2024-01-18
Vendor research
- Bee-Ware of Trigona, An Emerging Ransomware Strain Unit 42 (Palo Alto Networks)
- Observations on New Trigona Ransomware Arete
- Ukrainian activists hack Trigona ransomware gang, wipe servers BleepingComputer
- Pro-Ukraine group says it took down Trigona ransomware website The Record (Recorded Future News)