logo

Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft

ID: f527f9c9-8d02-576e-ac98-1b2c6cd72eb8

STIX ID: report--f527f9c9-8d02-576e-ac98-1b2c6cd72eb8

Feed Name: security.com

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

Symantec-tracked Trigona ransomware affiliates (Rhantus) conducted March 2026 intrusions using a custom exfiltration tool (uploader_client.exe) that implements parallel streams, connection rotation, granular filtering, and shared authentication; attackers preceded exfiltration by disabling endpoint protections via kernel-level tools/driver exploits, used AnyDesk for remote access, and harvested credentials with Mimikatz, with numerous file-hash IOCs and an identified C2 IP (163.172.105.82).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.