TridentLocker
0 incidentes
0 paises
0 sectores
apt US Ultimo: -
TridentLocker is a ransomware group that emerged in late 2025, operating a Ransomware-as-a-Service (RaaS) model. The group's primary motivation is financial, achieved through double-extortion tactics. What distinguishes TridentLocker is its immediate operational maturity, launching with a fully functional Tor-based leak site to publish exfiltrated data shortly after initial compromise, a capability uncommon for newly identified ransomware operations. The group strategically targets organizations managing large volumes of regulated or third-party data, including government services, telecommunications, and engineering firms. TridentLocker also identifies itself as a data broker, which highlights its focus on data exfiltration as a core component of its extortion strategy.
Canales, DLS e infraestructura asociada
Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.
Sectores objetivo (SOCRadar)
Public AdministrationOil & GasTelecommunicationsInsuranceEducational Support ServicesPrintingElectronics and Appliance StoresFreight Transportation ArrangementMotion Picture and Video ProductionComputer Systems Design and Related Services