Symantec reported that Trigona ransomware affiliates used a custom-built data theft utility, uploader_client.exe, in recent intrusions, replacing common exfiltration tools such as Rclone and MegaSync. The command-line tool connected to a hardcoded attacker-controlled server and was designed to steal high-value files from network drives, including invoices and PDFs, while lowering detection risk. Reported capabilities included parallel upload streams, TCP connection rotation after large transfers, file-extension filtering, and shared-key authentication, indicating a more mature and deliberate approach to exfiltration by affiliates tied to the Rhantus ransomware-as-a-service operation.
The attacks also involved a broader toolset to weaken defenses and expand access before data theft. Investigators said the actors attempted to disable security controls with utilities including HRSword, PCHunter, Gmer, YDark, WKTools, DumpGuard, and StpProcessMonitorByovd, often abusing vulnerable kernel drivers and using PowerRun for elevated execution. They then used AnyDesk for remote access and Mimikatz plus Nirsoft password recovery tools for credential theft. The activity suggests Trigona, which had lower visibility after disruption in 2023, has remained active and resumed operations with more customized and stealthy tradecraft.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
On April 23, 2026, Symantec publicly reported that recent Trigona attacks used custom-built exfiltration malware, assessing this as a sign of greater technical maturity and a shift toward lower-profile data theft. The disclosure also noted the activity suggests Trigona has resumed operations.
During the March 2026 attacks, the operators attempted to disable security tools using HRSword, PCHunter, Gmer, YDark, WKTools, DumpGuard, and StpProcessMonitorByovd, often via vulnerable kernel drivers and PowerRun. They also used AnyDesk for remote access and Mimikatz plus Nirsoft password recovery tools for credential theft.
In March 2026, Symantec observed Trigona-linked intrusions using a custom command-line exfiltration utility named uploader_client.exe instead of common tools like Rclone or MegaSync. The tool used a hardcoded attacker-controlled server, parallel uploads, connection rotation, file-type filtering, and shared-key authentication to steal targeted documents from network drives.
Reporting cited by DataBreaches indicated Trigona continued conducting attacks in 2024 even though its known URLs were down and public signs of activity were limited. This showed the group had not fully ceased operations after the 2023 disruption.
Trigona's operations were disrupted by Ukrainian cyber activists in October 2023. Afterward, the group had limited public visibility and was at times thought to have disappeared.
Trigona first appeared in late 2022 as a double-extortion ransomware-as-a-service operation. Symantec tracks the operation behind it as Rhantus.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcesecurity.com
Open sourcebleepingcomputer.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.