Uptime Hamster: 12d 21h 53mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza trigona

trigona

2 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: CryLock
Ver en IntelTracker → APTTrail →
Trigona is a financially motivated ransomware group that first emerged with initial samples observed in June 2022, though it gained wider recognition in late October 2022. The group operates under a Ransomware-as-a-Service (RaaS) model and is distinct for employing a double extortion strategy where exfiltrated data is threatened for public release if the ransom is not paid. While its precise origins remain unknown, technical analysis indicates similarities in tactics, techniques, and procedures with CryLock ransomware. Trigona differentiates itself through its use of dynamic 4,112-bit RSA encryption and AES-256 in OFB mode, coupled with HTML Application (.hta) ransom notes. A notable shift in its operational model is the recent adoption of a custom-developed exfiltration tool, uploader_client.exe, to replace off-the-shelf utilities, enhancing its stealth and efficiency during data theft. Despite claims of a takedown in late 2023, Trigona affiliates quickly re-established operations, de

Aliases del actor

CryLock

Actores similares

crylockransomware · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: trigona
Tecnicas MITRE
T1543, T1562, T1110, T1133, T1555, T1547
CVEs relacionadas
CVE-2021-40539
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

AustriaAustraliaBelgiumBrazilCanadaChileChinaColombiaGermanySpain

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationManufacturingConstruction

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com