logo

Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft

ID: e3714832-da23-5f4a-8013-13a847faa3f7

STIX ID: report--e3714832-da23-5f4a-8013-13a847faa3f7

Feed Name: DataBreaches.Net

Threat Score
70/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Dissent

...
...

Symantec and Carbon Black observed the Trigona ransomware-as-a-service (RaaS) operation—attributed to an actor called Rhantus—using a custom-built data-theft tool in March 2026, indicating a shift away from common exfiltration utilities to proprietary tooling; Trigona has reappeared after a period of apparent dormancy, though known URLs are currently down.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.