Trigona

Inactive
According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.
49 Victims
Apr 11, 2023 First Discovered
Mar 30, 2024 Last Discovered
901 Days Inactive
0% Infostealer
0/4 Sites Online
Known Locations (4)
Trigona is Gone
trigonax2zb3fw34rbaap4cqep76zofxs53zakrdgcxzq6xzt24l5lqd.onion
Trigona is Gone
3x55o3u2b7cjs54eifja5m3ottxntlubhjzt6k6htp5nrocjmsxxh7ad.onion
Blog
krsbhaxbki6jr4zvwblvkaqzjkircj7cxf46qt3na5o5sj2hpikbupqd.onion
Blog
6n5tfadusp4sarzuxntz34q4ohspiaya2mc6aw6uhlusfqfsdomavyyd.onion
Tools Used
CredentialTheft
Mimikatz
DiscoveryEnum
Advanced Port Scanner, SoftPerfect NetScan
Exfiltration
MEGA, RClone
Offsec
Cobalt Strike
RMM-Tools
AnyDesk, LogMeIn, ScreenConnect, Splashtop, TeamViewer
Intelligence
Victims (49)

Detailed victim list temporarily unavailable

This group has 49 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.