logo

Trigona ransomware adopts custom tool to steal data and evade detection

ID: 7f4b3532-62e3-53de-9305-caf035dfa41b

STIX ID: report--7f4b3532-62e3-53de-9305-caf035dfa41b

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-26

Date Updated: 2026-04-26

Author: Pierluigi Paganini

...
...

Trigona ransomware affiliates have begun using a proprietary command-line exfiltration tool (uploader_client.exe) that performs parallel, rotating TCP connections and file filtering to accelerate and stealthily steal sensitive documents from network drives; attackers also disable security products (via HRSword, PCHunter, GMER and vulnerable kernel drivers), remotely access systems with AnyDesk, and harvest credentials with Mimikatz and Nirsoft utilities, indicating a more sophisticated and stealth-focused evolution of the group's tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.