Trigona (Mimic) ransomware is a strain analyzed by AhnLab, known for targeting MSSQL databases. It is part of the broader ransomware ecosystem and is notable for its focus on database systems, which are often critical assets for organizations. The ransomware encrypts data and demands payment for decryption, following the typical double-extortion model. There is no direct attribution to a specific threat actor or group in the provided content, nor are there detailed indicators of compromise or infection vectors beyond the targeting of MSSQL. The analysis does not mention any unique capabilities or behaviors outside of its targeting profile. The ransomware is referenced in the context of ongoing ransomware activity affecting various sectors, but no specific industries or geographies are highlighted for Trigona (Mimic) beyond the technical focus on MSSQL databases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.