Tactical Evolution: Trigona Ransomware Debuts Custom Exfiltration Armory
ID: d8d9465a-e3d2-5944-abf8-e20f52e95449
STIX ID: report--d8d9465a-e3d2-5944-abf8-e20f52e95449
Feed Name: securityonline.info
The report describes Trigona (Rhantus) affiliates shifting from off-the-shelf exfiltration tools to a proprietary high-performance uploader (uploader_client.exe) observed in March 2026; the utility uses parallel streaming, connection rotation, extension-based filtering, and shared-key authentication to stealthily exfiltrate high-value files. Operators are observed disabling security at the kernel level (installing HRSword and leveraging tools like PCHunter/Gmer/YDark), then using AnyDesk and Mimikatz to gain remote access and harvest credentials for lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
