logo

Analysis of Trigona Threat Actor’s Latest Attack Cases

ID: 1524d9e7-5e06-5a7e-b462-201d8286e84d

STIX ID: report--1524d9e7-5e06-5a7e-b462-201d8286e84d

Feed Name: ASEC

Threat Score
75/100

Date Published: 2025-10-23

Date Updated: 2026-04-26

Author: ATCP

...
...

ASEC reports that the Trigona threat actor is actively attacking MS‑SQL servers via brute‑force/dictionary attacks against weak credentials, deploying malware by exporting binaries stored in database tables via BCP and using downloaders (curl, bitsadmin, PowerShell). The actor installs remote access tools (AnyDesk, RDP accounts, likely Teramind), employs custom scanners written in Rust and Go for RDP/MS‑SQL discovery and brute forcing, and uses various deletion and persistence scripts; the report includes multiple IoCs (MD5 hashes, IPs, URLs) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.