Trigona is a ransomware family and ransomware-as-a-service operation active since 2022. It targets Windows and Linux environments, with Linux variants also capable of disrupting VMware ESXi virtual machines before encrypting targeted data. Trigona encrypts files using AES-based routines, changes affected filenames, and delivers ransom instructions through an HTML application note and Tor-based negotiation infrastructure. It supports double extortion: affiliates steal selected victim data before encryption and threaten disclosure through leak-site infrastructure, including previews and auction-style features. Symantec tracks the operation as associated with a cybercrime group it calls Rhantus.
Observed intrusions have targeted internet-exposed Remote Desktop Protocol and Microsoft SQL Server systems, particularly those protected by weak or compromised credentials. Trigona activity has also been associated with exploitation of ManageEngine ADSelfService Plus vulnerability CVE-2021-40539. Operators have conducted host and network discovery, created privileged accounts, used remote-access software and RDP for lateral movement, dumped credentials with Mimikatz, and attempted to disable security products and recovery mechanisms. Some campaigns abused vulnerable kernel drivers to terminate endpoint protections.
Trigona affiliates have targeted organizations in sectors including technology, healthcare, manufacturing, finance, construction, agriculture, marketing, and high technology. In 2026, affiliates were observed using a privately developed command-line uploader to selectively exfiltrate high-value documents from network shares, replacing common public file-transfer utilities. The operation remained active after its leak-site infrastructure was disrupted in 2023.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Trigona ransomware is a relatively new ransomware family that began activities around late October 2022 — although samples of it existed as early as June 2022.
Exploitation of a critical Confluence Data Center and Server vulnerability, tracked as CVE-2023-22515, enabled UCA hacktivists to infiltrate Trigona's ransomware infrastructure last week without being detected by the ransomware group.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Trigona ransomware is a relatively new ransomware family that began activities around late October 2022 — although samples of it existed as early as June 2022.
Trigona ransomware was first observed in June 2022. It has Windows and Linux versions, which are similar in their functionality. On underground forums, threat actors announced the start of the affiliate program, meaning that Trigona operates as ransomware as a service.
Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync.
In January 2024, the group first made its mark by deploying Trigona and Mimic ransomware on MS-SQL servers exposed to the internet with weak credentials.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on AhnLab’s analysis, Trigona’s operators use CLR shell on attacks launched against MS-SQL servers.
The output code shows that the malware is able to issue Virtual Infrastructure Management commands to a VMWare ESXi server. It lists all VMs, and then kills them all. ... command = "vim-cmd vmsvc/getallvms"; ... snprintf(poweroff_cmd, sizeof(poweroff_cmd), "vim-cmd vmsvc/power.off %s", vmid); ret = shellExecute(poweroff_cmd, &command, true);
This tool is capable of multiple commands, including one that drops additional executables for privilege escalation (nt.exe).
“Trigona… change in tactics designed to hide its identity… ransom notes avoid mentioning [their leak site]… point to leak sites belonging to other ransomware groups…”
/* * The /delete option enables deletion mode in the program. * When this flag is set, instead of just scanning or analyzing files, * the program will actually remove files that match certain criteria. * ... */ bool process_command_options(const char* option) { ... if (strcmp(option, "/delete") == 0) { ... *g_deletion_enabled = true;
Trigona’s operators employ the credential dumper Mimikatz to gather the passwords and credentials found on the machines of the victims.
The commands that the threat actor first executes before creating the malware with BCP... are those that look up the infected system’s information as shown below. > hostname > whoami
It also uses Network Scanner and Advanced Port Scanner to identify network connections.
The output code shows that the malware is able to issue Virtual Infrastructure Management commands to a VMWare ESXi server. It lists all VMs, and then kills them all. ... command = "vim-cmd vmsvc/getallvms";
While many ransomware groups rely on off-the-shelf utilities such as Rclone or MegaSync to steal victim data, recent attacks involving the Trigona ransomware used a custom-developed tool designed to provide attackers with granular control over the data theft process.
This site hosts critical data stolen from victims such as documents, contracts, and other large amounts of data.
We recommend contacting us as your confidential files have been stolen and will be sold to interested parties unless you pay to remove them from our clouds and auction, or decrypt your files.
Deletes the content of the target files. (By default, only the first 512kb is erased unless the argument /full is used)
“With data secured, the attackers deploy the encryptor across as many systems as possible.”
// Power off ESXi VMs if needed if (targetPath == "/vmfs/" && doPowerOff) { ... stopVM(); } ... The output code shows that the malware is able to issue Virtual Infrastructure Management commands to a VMWare ESXi server. It lists all VMs, and then kills them all. | // Kill processes if not disabled if (getTaskKillerEnabled() && !disableKillFlag) { killTasksAndServices(); }
// Shutdown system if requested if (shutdownAfterFlag) { reboot(0x4321FEDC); // Special reboot code }
// Perform encryption or erasing priorityEncryptionOrErasing(); writeToLog("Start process..."); // Process target path String normalizedPath = osConvertSlashToBackslash(targetPath); if (fileExists(normalizedPath)) { encryptOrEraseFileByPath(targetPath, false); } else { encryptOrEraseFolderByPath(targetPath, false); }
101 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation using double extortion, cloud-based data exfiltration, and leak-site pressure tactics including release countdowns and data-sale options.
Trigona is mentioned only as prior context linking SqlShell to another ransomware-related MS-SQL compromise.
A ransomware-as-a-service operation active since late 2022, linked in the content to the Rhantus cybercrime group. Recent attacks used a custom-built exfiltration utility (uploader_client.exe) to steal sensitive data more efficiently and evade detection, alongside credential theft and security-disabling tools.
Ransomware-as-a-service malware that targets Windows and Linux systems, encrypts files with the ._locked extension, and uses double-extortion tactics including data exfiltration prior to encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.