Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
ID: fe36ec69-28f6-50d2-9e4d-34d7e18dc9e2
STIX ID: report--fe36ec69-28f6-50d2-9e4d-34d7e18dc9e2
Feed Name: The DFIR Report
In late December 2022 threat actors gained access to an exposed RDP host using legitimate Administrator credentials, used SoftPerfect Netscan for network discovery, staged rclone to exfiltrate files to Mega, disabled Windows Defender via commands and scripts, and executed Trigona ransomware which spread over SMB to encrypt network-accessible hosts, producing a double-extortion outcome; the report includes IOCs (IPs, hashes, filenames), recovered scripts, and detection rules (Sigma/Yara).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
