Trinity

Inactive
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
18 Victims
Jun 5, 2024 First Discovered
Mar 16, 2025 Last Discovered
549 Days Inactive
0% Infostealer
0/1 Sites Online
Known Locations (1)
rans
txtggyng5euqkyzl2knbejwpm4rlq575jn2egqldu27osbqytrj6ruyd.onion
Intelligence
Victims (18)

Detailed victim list temporarily unavailable

This group has 18 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.