Trigona is a ransomware-as-a-service operation active since 2022 that deploys both Windows and Linux ransomware and uses double-extortion tactics. The operation emerged publicly under the Trigona name in late 2022, after earlier unbranded samples had already been observed, and has been linked in some reporting to the Rhantus cybercrime group. Trigona has remained operationally active across multiple periods despite disruption of parts of its infrastructure in 2023. Trigona has repeatedly targeted internet-exposed Microsoft SQL Server environments, especially poorly managed servers with weak credentials. Reported initial access methods include brute-force and dictionary attacks against MS-SQL, use of previously compromised accounts obtained from access brokers, and exploitation of CVE-2021-40539 in ManageEngine products. Post-compromise activity has included abuse of SQL Server features and tooling such as CLR-based SQL shells and the Bulk Copy Program to reconstruct and deploy payloads from database contents onto disk. Observed Trigona intrusions include reconnaissance, creation of new user accounts, credential theft, privilege escalation, lateral movement, defense evasion, data exfiltration, and ransomware deployment. Operators and affiliates have used tools such as Mimikatz for credential dumping, Splashtop and RDP for remote access and lateral movement, AnyDesk for persistent interactive access, network and port scanners for discovery, and batch scripts to stop security services, clear logs, and delete shadow copies. More recent activity also shows use of security-disabling utilities and bring-your-own-vulnerable-driver techniques, including tools such as HRSword, PCHunter, GMER, and related process-termination tooling, as well as PowerRun for elevated execution. In 2026, Trigona affiliates were observed replacing common public exfiltration utilities with a custom uploader to steal selected high-value documents more efficiently and with lower detection risk. The ransomware itself is commonly described as Delphi-based and supports extensive command-line control over encryption behavior. Across reporting, Trigona encrypts files and appends the ._locked extension, drops HTML-based ransom notes, supports persistence through autorun mechanisms, and can target local and network-accessible data. Variants for both Windows and Linux have been documented. The operation maintains negotiation and leak infrastructure and has used a leak site with victim listings and auction-style pressure mechanisms as part of its extortion model. Victimology spans multiple sectors, with repeated reporting on technology, healthcare, manufacturing, finance, construction, agriculture, marketing, and high-technology organizations. Geographic reporting most consistently identifies victims in the United States, Italy, France, Germany, Australia, and New Zealand, while telemetry also showed detections in India, Israel, Turkey, Brazil, and elsewhere. Trigona has also appeared in reporting on attacks against industrial organizations. Operationally, Trigona has shown overlap with broader Russian-speaking cybercrime ecosystems. Some reporting noted similarities with CryLock tradecraft, while other reporting identified individuals who allegedly worked as Trigona affiliates alongside other major ransomware programs. In October 2023, the Ukrainian Cyber Alliance claimed to have compromised and wiped Trigona infrastructure, including administrative systems and source code repositories, but subsequent reporting indicates the operation or its affiliates later resumed activity and re-established leak-site presence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as background in connection with prior SqlShell malware use on MS-SQL compromises.
Ransomware-as-a-Service operation using a custom-built command-line data exfiltration tool to steal data faster and evade detection during ransomware attacks.
Conducting ransomware attacks using double-extortion tactics and, as of March 2026, using a custom data-exfiltration tool (uploader_client.exe) instead of relying solely on public tools.
Conducting ransomware operations under a RaaS model and using a custom-built data exfiltration tool ('uploader_client.exe') to steal targeted high-value documents such as financial invoices and PDFs. The group also used defense-evasion and credential-theft tooling prior to exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.