logo

Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data

ID: 3a507a87-6d9d-5e0d-bbf2-8c38361af35e

STIX ID: report--3a507a87-6d9d-5e0d-bbf2-8c38361af35e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Tushar Subhra Dutta

...
...

Symantec researchers observed Trigona ransomware affiliates using a custom command-line exfiltration tool (uploader_client.exe) to selectively steal high-value financial and PDF documents; attackers paired this with kernel-level defense evasion (HRSword, PCHunter, Gmer), credential theft (Mimikatz, Nirsoft tools), and AnyDesk remote access. The uploader optimizes speed and stealth via parallel connections, connection rotation, and exclusion flags, while the campaign's RaaS model and proprietary tooling raise detection difficulty and risk to organizations handling sensitive financial records.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.