Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
ID: e3714832-da23-5f4a-8013-13a847faa3f7
STIX ID: report--e3714832-da23-5f4a-8013-13a847faa3f7
Feed Name: DataBreaches.Net
Threat Score
Symantec and Carbon Black observed the Trigona ransomware-as-a-service (RaaS) operation—attributed to an actor called Rhantus—using a custom-built data-theft tool in March 2026, indicating a shift away from common exfiltration utilities to proprietary tooling; Trigona has reappeared after a period of apparent dormancy, though known URLs are currently down.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
