Trigona is a ransomware-as-a-service (RaaS) operation first observed in 2022 and publicly branded under the Trigona name in late 2022. It is associated in some reporting with the Rhantus cybercrime group and has operated a double-extortion model in which victim data is stolen before encryption and victims are pressured through a leak site and negotiation portal. Trigona has targeted both Windows and Linux environments and has been observed affecting organizations across sectors including manufacturing, finance, construction, agriculture, marketing, technology, and other industrial enterprises. Trigona is notable for repeatedly targeting internet-exposed Microsoft SQL Server environments with weak or guessable credentials. In these intrusions, operators have used brute-force and dictionary attacks to obtain access, then leveraged SQL Server functionality and CLR-based SQL shell tooling to execute commands, stage payloads, and deploy follow-on malware. Reporting also describes use of the Bulk Copy Program to reconstruct malware from database-stored content onto victim systems. Post-compromise activity has included system discovery, credential theft, privilege escalation, lateral movement, remote access enablement, and deployment of ransomware. Observed Trigona tradecraft includes use of legitimate and dual-use tools for remote administration, exfiltration, and defense evasion. Affiliates have been seen using remote access software, Remote Desktop Protocol, credential theft utilities, and multiple security-disabling tools, including bring-your-own-vulnerable-driver-style utilities to terminate endpoint protections. Trigona has also been linked to use of FileZilla for exfiltration and to acquisition or use of specialized security-neutralization tooling sold within the ransomware ecosystem. The ransomware itself has Windows and Linux variants with broadly similar functionality. Public technical reporting describes configurable execution via command-line arguments, selective encryption of local and network resources, persistence mechanisms, deletion of backups and shadow copies, and destructive options such as file erasure and free-space wiping. Encrypted files are typically renamed with the ._locked extension, and ransom notes direct victims to a Tor-based negotiation portal that has accepted Monero payments. Trigona has advertised affiliate-style operations and supporting infrastructure consistent with a mature RaaS program. By 2026, Trigona affiliates were observed shifting from common public exfiltration utilities toward a custom-built command-line data theft tool designed for faster transfer, selective targeting of high-value documents, and improved stealth through connection management and filtering. This evolution suggests continued investment in proprietary tooling and operational security. Trigona’s infrastructure suffered a major disruption in October 2023 when the Ukrainian Cyber Alliance claimed to have compromised and wiped the group’s servers after exploiting CVE-2023-22515 in Atlassian Confluence. Reporting indicates the intrusion exposed internal systems, panels, source code, and other operational data. Despite that disruption, subsequent reporting indicates Trigona or affiliates continued operations, resurfaced with modified tactics, and remained active into 2024, 2025, and 2026. Trigona is primarily a financially motivated cybercriminal threat actor rather than a nation-state actor. It has also appeared in broader ransomware ecosystem reporting involving affiliates, service sharing, and overlap with other criminal operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation using a custom-built command-line data exfiltration tool to steal data faster and evade detection during ransomware attacks.
Conducting ransomware attacks using double-extortion tactics and, as of March 2026, using a custom data-exfiltration tool (uploader_client.exe) instead of relying solely on public tools.
Conducting ransomware operations under a RaaS model and using a custom-built data exfiltration tool ('uploader_client.exe') to steal targeted high-value documents such as financial invoices and PDFs. The group also used defense-evasion and credential-theft tooling prior to exfiltration.
A ransomware-as-a-service operation active since late 2022, observed in March 2026 using a custom-developed data theft tool instead of common off-the-shelf exfiltration utilities, indicating a shift in tradecraft by its affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.