TridentLocker is a ransomware-as-a-service operation first observed in late November 2025. It conducts financially motivated double-extortion attacks, combining system encryption with exfiltration and threats to publicly release stolen data through a leak site. The group has publicly claimed victims in North America and Europe, including Sedgwick Government Solutions in the United States and Belgian postal operator bpost. Its reported victimology spans government and public-sector organizations, manufacturing, information technology, and professional services. TridentLocker has also presented itself as a data broker, using public leak threats as leverage in its extortion operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against SouthernCarlson, a U.S.-based distributor of packaging, fastening, installation, and industrial supplies.
Ransomware/extortion activity targeting a government-services subsidiary; claims data theft and uses leak-site threats to coerce payment/negotiation.
Conducting ransomware attacks against government contractors.
TridentLocker is a ransomware-as-a-service group that conducts data theft and extortion operations, targeting organizations such as Sedgwick Government Solutions and claiming to exfiltrate sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.