TridentLocker is a ransomware-as-a-service operation that emerged in late November 2025. The group is associated with double-extortion intrusions in which victim data is exfiltrated and victims are threatened with public disclosure on a leak site, alongside claims of system encryption. Reported victimology indicates activity across government, manufacturing, information technology, and professional services, with operations affecting organizations in North America and Europe. Publicly claimed victims include Belgium’s postal operator bpost and Sedgwick Government Solutions, a U.S. federal contractor subsidiary. TridentLocker has publicly presented itself as a ransomware group and has been described as using a leak site to pressure victims after theft of sensitive data. Its observed behavior supports capabilities including initial access, data exfiltration, post-exploitation, and extortion. The group has been linked to theft from isolated file-transfer environments and publication of stolen samples to increase coercive pressure. Available reporting characterizes TridentLocker as an emerging criminal enterprise rather than a state-directed actor. No high-confidence attribution to a specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion activity targeting a government-services subsidiary; claims data theft and uses leak-site threats to coerce payment/negotiation.
Conducting ransomware attacks against government contractors.
TridentLocker is a ransomware-as-a-service group that conducts data theft and extortion operations, targeting organizations such as Sedgwick Government Solutions and claiming to exfiltrate sensitive data.
TridentLocker is a ransomware-as-a-service group that emerged in late November 2025. It conducts double-extortion ransomware attacks, encrypting victim systems and threatening to leak exfiltrated data. The group has claimed at least 12 victims across manufacturing, government, IT, and professional services, primarily in North America and Europe.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.