Trigona ransomware adopts custom tool to steal data and evade detection
ID: 7f4b3532-62e3-53de-9305-caf035dfa41b
STIX ID: report--7f4b3532-62e3-53de-9305-caf035dfa41b
Feed Name: Security Affairs
Trigona ransomware affiliates have begun using a proprietary command-line exfiltration tool (uploader_client.exe) that performs parallel, rotating TCP connections and file filtering to accelerate and stealthily steal sensitive documents from network drives; attackers also disable security products (via HRSword, PCHunter, GMER and vulnerable kernel drivers), remotely access systems with AnyDesk, and harvest credentials with Mimikatz and Nirsoft utilities, indicating a more sophisticated and stealth-focused evolution of the group's tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
