logo

Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours

ID: fe36ec69-28f6-50d2-9e4d-34d7e18dc9e2

STIX ID: report--fe36ec69-28f6-50d2-9e4d-34d7e18dc9e2

Feed Name: The DFIR Report

Threat Score
78/100

Date Published: 2024-01-29

Date Updated: 2026-04-19

Author: editor

...
...

In late December 2022 threat actors gained access to an exposed RDP host using legitimate Administrator credentials, used SoftPerfect Netscan for network discovery, staged rclone to exfiltrate files to Mega, disabled Windows Defender via commands and scripts, and executed Trigona ransomware which spread over SMB to encrypt network-accessible hosts, producing a double-extortion outcome; the report includes IOCs (IPs, hashes, filenames), recovered scripts, and detection rules (Sigma/Yara).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.