The Ukrainian Cyber Alliance (UCA) said it breached the Trigona ransomware gang’s infrastructure, exfiltrated internal data, and wiped and defaced servers, knocking the group’s public-facing services offline. According to reports, the activists gained initial access by exploiting CVE-2023-22515, a critical vulnerability in Atlassian Confluence Data Center and Server, then remained undetected while mapping Trigona’s environment and extracting data from administration and victim panels, internal tools, source code repositories, databases, developer systems, leak-site infrastructure, and cryptocurrency hot wallets.
The stolen data reportedly included hundreds of gigabytes of backups and documents, and may also contain decryption keys that could aid victims. Trigona, a ransomware operation active since 2022, had targeted organizations in sectors including manufacturing and finance and had previously used exposed Microsoft SQL servers as an intrusion vector. Following the intrusion, Trigona’s websites and operational services were reported offline, with UCA claiming the action effectively dismantled the gang’s infrastructure.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Following the server compromise and wiping, Trigona's public websites and related services were reported offline.
UCA then wiped and defaced Trigona's servers, an action reported to have taken the ransomware operation offline and dismantled its infrastructure.
After gaining access, UCA reportedly stole hundreds of gigabytes of data from Trigona's administration and victim panels, internal tools, source code repositories, databases, backups, and cryptocurrency hot wallets; the haul may also have included decryption keys.
The Ukrainian Cyber Alliance said it gained initial access to Trigona infrastructure through a public exploit for CVE-2023-22515, a critical Atlassian Confluence Data Center and Server vulnerability, and remained undetected while mapping the environment.
Earlier in 2023, Trigona used exposed Microsoft SQL servers as an intrusion vector in attacks against organizations across multiple sectors.
The Trigona ransomware operation was publicly branded and identified in late October 2022 after earlier malware activity had already been observed.
Malware samples associated with the Trigona ransomware operation were first seen in early 2022, marking the earliest known activity tied to the group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.