logo

ThreatLabz

ID: acd9800e-8803-52e2-9dc6-66c9dbdc30c4

STIX ID: report--acd9800e-8803-52e2-9dc6-66c9dbdc30c4

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-12-30

Date Updated: 2026-05-01

...
...

This technical analysis of Trigona ransomware documents its capabilities and internals: supported command-line options (including erase/full for wiper behavior), an embedded double-AES-encrypted configuration format, use of large RSA keys and AES modes (CBC for config, OFB for file content) with a nonstandard residual block termination, per-file footers and naming changes, and the victim authentication/ransom portal and decryption tool workflow. The report highlights destructive features (partial/full overwrites and file deletion), a broad extension list, and how victims exchange scan.dat/keys.dat with the threat actors for recovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.