logo

Trigona ransomware attacks use custom exfiltration tool to steal data

ID: c918adc0-bef8-5094-926d-5c9d2e3be9ff

STIX ID: report--c918adc0-bef8-5094-926d-5c9d2e3be9ff

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Bill Toulas

...
...

Symantec reports that recent Trigona ransomware campaigns have incorporated a custom exfiltration utility (uploader_client.exe) to speed and stealth data theft from compromised environments as part of double‑extortion operations; the actors used kernel driver services, tools to disable endpoint protections, credential theft utilities (e.g., Mimikatz), remote access (AnyDesk), and published IoCs to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.