Analysis of Trigona Threat Actor’s Latest Attack Cases
ID: 1524d9e7-5e06-5a7e-b462-201d8286e84d
STIX ID: report--1524d9e7-5e06-5a7e-b462-201d8286e84d
Feed Name: ASEC
ASEC reports that the Trigona threat actor is actively attacking MS‑SQL servers via brute‑force/dictionary attacks against weak credentials, deploying malware by exporting binaries stored in database tables via BCP and using downloaders (curl, bitsadmin, PowerShell). The actor installs remote access tools (AnyDesk, RDP accounts, likely Teramind), employs custom scanners written in Rust and Go for RDP/MS‑SQL discovery and brute forcing, and uses various deletion and persistence scripts; the report includes multiple IoCs (MD5 hashes, IPs, URLs) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
