logo

Tactical Evolution: Trigona Ransomware Debuts Custom Exfiltration Armory

ID: d8d9465a-e3d2-5944-abf8-e20f52e95449

STIX ID: report--d8d9465a-e3d2-5944-abf8-e20f52e95449

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Ddos

...
...

The report describes Trigona (Rhantus) affiliates shifting from off-the-shelf exfiltration tools to a proprietary high-performance uploader (uploader_client.exe) observed in March 2026; the utility uses parallel streaming, connection rotation, extension-based filtering, and shared-key authentication to stealthily exfiltrate high-value files. Operators are observed disabling security at the kernel level (installing HRSword and leveraging tools like PCHunter/Gmer/YDark), then using AnyDesk and Mimikatz to gain remote access and harvest credentials for lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.