logo

Trigona Ransomware Threat Actor Uses Mimic Ransomware

ID: 280ae657-7ecd-5084-84c8-4f5436c500f2

STIX ID: report--280ae657-7ecd-5084-84c8-4f5436c500f2

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-01-30

Date Updated: 2026-04-26

Author: Sanseo

...
...

ASEC details active Trigona-related attacks that install Mimic and Trigona ransomware on poorly managed, exposed MS‑SQL servers by embedding binaries in database tables and using the MS‑SQL BCP utility to write malware to disk; attackers also deploy a launcher service (to run in Safe Mode), a port‑forwarder for RDP access, AnyDesk, and credential-theft techniques. The report provides command examples, malware behaviors, IOCs ([email protected], an .onion URL, http://2.57.149.233:3366/, several MD5 hashes), and mitigation guidance (strong passwords, firewalls, AV updates).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.