Trinity Ransomware emerged around May 2024, deploying a double extortion model from its inception. It is considered a relatively new threat actor and shares significant code and tactical similarities with the 2023Lock and Venus ransomware variants, with some researchers indicating it may be an updated version or rebranding of 2023Lock. Its operators, assessed with moderate confidence to be of Russian origin due to geo-blocking mechanisms identified in its predecessor Zeoticus, are primarily motivated by financial gain through data encryption and exfiltration to coerce ransom payments. A distinguishing characteristic of Trinity Ransomware is its close technical lineage with 2023Lock, including reportedly identical code and ransom notes.
Other Information ServicesSoftware PublishersHospitalsAccommodationAir TransportationManufacturingConstructionPublic AdministrationEducational ServicesSpace & Defense