Credential Theft
- Mimikatz
Trigona is a ransomware family and ransomware-as-a-service operation first observed in 2022, with public branding emerging in late 2022 and earlier samples dating back to mid-2022.
Profile source: Mallory opens in a new tabTrigona
Trigona is a ransomware family and ransomware-as-a-service operation first observed in 2022, with public branding emerging in late 2022 and earlier samples dating back to mid-2022. It targets both Windows and Linux environments, including VMware ESXi-related Linux deployments, and has been associated with double-extortion activity in which data is stolen before encryption and victims are pressured through leak and negotiation portals. Security reporting has linked operation of the service to a cybercrime group tracked by some researchers as Rhantus.
Trigona encrypts victim files and commonly appends the ._locked extension. Windows samples have been described as Delphi-based and use AES together with embedded or encrypted configuration data. Variants support extensive command-line control over encryption scope, debugging, persistence, and destructive actions. Reported behaviors include partial or full-file encryption, filename encryption, ransom-note deployment, autorun persistence, deletion of shadow copies and backups, disabling recovery options, and in some variants file erasure or free-space wiping. Linux variants expose similar functionality and have been observed supporting options for path selection, fast versus full encryption, optional command execution, task and service termination, self-deletion, and ESXi virtual machine disruption through powering off guest systems before encryption.
Observed intrusions show Trigona operators and affiliates using multiple access paths. High-confidence reporting ties the group to compromises of externally exposed Microsoft SQL Server systems with weak credentials, including brute-force or dictionary attacks and abuse of SQL Server features and utilities to stage payloads. Trigona has also been reported exploiting CVE-2021-40539 in ManageEngine products for initial access, and separate incident reporting has documented deployment following compromise of publicly exposed RDP services using valid accounts. In SQL Server-focused cases, attackers used CLR-based SQL shell tooling, the Bulk Copy Program utility, and supporting malware to reconstruct or launch payloads on compromised hosts.
Post-compromise tradecraft includes reconnaissance, credential theft, lateral movement, persistence, and defense evasion. Reported tooling and behaviors include Mimikatz, Nirsoft password recovery tools, AnyDesk, Splashtop, network and port scanners, batch-script automation, creation of privileged local accounts, disabling or terminating security products, and use of vulnerable drivers to kill endpoint protections. Recent reporting from 2026 indicates Trigona affiliates shifted from common public exfiltration utilities to a custom command-line uploader designed for faster and stealthier theft of selected high-value documents, suggesting continued investment in proprietary tooling.
Victimology has included organizations in technology, healthcare, manufacturing, finance, construction, agriculture, marketing, and high-technology sectors across multiple countries. Trigona infrastructure was disrupted in 2023 by Ukrainian hacktivists, but subsequent reporting indicates the malware family and affiliated activity continued after that event, including later Windows and Linux samples and renewed exfiltration-focused intrusions.
f78073b1b2de009645a0254507b87a377f7c78fb5d9fdee28996a3f12bd00fef68635ad9d12f683071611bfd34c1ec34b59a9174ff768633e2cf5dfb16e516a82c83e59eea3e6890d31adc7c518e3702c62620dc472f8e2835ad3abc6acd6e35c28b33f7365f9dc72cc291d13458f3342c31a750240788f924ef64a2fb4fdf3b5f3407dedd4b9bf1e57209cc2178b8dc21477e62d5ddebf6fcb1ecb8002d0c8cReported operators
The Trigona ransomware is a relatively new ransomware family that began activities around late October 2022 — although samples of it existed as early as June 2022.
Trigona ransomware was first observed in June 2022. It has Windows and Linux versions, which are similar in their functionality. On underground forums, threat actors announced the start of the affiliate program, meaning that Trigona operates as ransomware as a service.
Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync.
In January 2024, the group first made its mark by deploying Trigona and Mimic ransomware on MS-SQL servers exposed to the internet with weak credentials.
Exploited software
MITRE ATT&CK
Reporting
Threat actors have been targeting poorly secured, internet-exposed Microsoft SQL Server instances to deliver Mimic and Trigona ransomware, using brute-force or weak credentials and, in some cases, xp_cmdshell for command execution. Researchers reported that one actor used the SQL Server Bulk Copy Program (BCP) utility to rebuild malware from database contents onto disk, while other intrusions relied on PowerShell download cradles, mounted SMB shares, and remote access tools including AnyDesk. In multiple cases, the attackers established persistence, created administrator accounts, enabled credential theft opportunities such as the WDigest\UseLogonCredential registry setting, and deployed tooling including Mimikatz, PsExec, Advanced Port Scanner, Defender Control, and SDelete.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.