Trigona ransomware attacks use custom exfiltration tool to steal data
ID: c918adc0-bef8-5094-926d-5c9d2e3be9ff
STIX ID: report--c918adc0-bef8-5094-926d-5c9d2e3be9ff
Feed Name: Bleeping Computer
Threat Score
Symantec reports that recent Trigona ransomware campaigns have incorporated a custom exfiltration utility (uploader_client.exe) to speed and stealth data theft from compromised environments as part of double‑extortion operations; the actors used kernel driver services, tools to disable endpoint protections, credential theft utilities (e.g., Mimikatz), remote access (AnyDesk), and published IoCs to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
