Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors trigona

Description

According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files. Known victims: 49 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

Trigona is a medium-sophistication criminal threat actor primarily motivated by organizational gain, with goals of ransomware and financial gain. The actor has been active since 2023 and has targeted at least 49 victims, encrypting files and demanding ransom. Trigona's operations are characterized by the use of ransomware that appends the ._locked extension to filenames and drops a ransom note.

Goals & Targeting

Trigona's strategic objectives appear to be centered around achieving financial gain through the deployment of ransomware. The actor's targeting profile suggests a focus on organizations or individuals capable of paying significant ransoms, although the lack of specificity regarding targeted sectors and countries implies a potentially broad scope of operations. The typical victims of Trigona are likely those with valuable data and the financial resources to meet the actor's ransom demands, highlighting the need for organizations to prioritize robust cybersecurity measures and backup strategies to mitigate the impact of such attacks.

Enhanced Description

The lack of specific information on targeted sectors and countries suggests that Trigona may not be highly selective in its targeting, potentially indicating a more opportunistic approach. However, the focus on ransomware and financial gain implies that the actor is primarily interested in targeting organizations or individuals with the capability to pay significant ransoms. Given the medium level of sophistication attributed to Trigona, it is plausible that the actor continues to evolve and refine its tactics, potentially incorporating new techniques or tools into its operations.

Key Capabilities

  • Ransomware development and deployment
  • File encryption and decryption key management
  • Ransom note creation and distribution
  • Victim identification and tracking
  • Data embedding within encrypted files

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware
HTA files for ransom notes

Campaigns & Victims

Trigona's campaign patterns are characterized by the consistent use of ransomware to encrypt files and demand ransom. The actor's operational tempo is marked by a steady stream of attacks, with at least 49 known victims since the actor's first observed activity in 2023. Notable past operations include the deployment of ransomware with the ._locked extension and the use of HTA files for ransom notes. Given the medium level of sophistication, Trigona's operations may evolve to incorporate new tactics or tools, potentially increasing the actor's effectiveness and reach.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Ransomware with the ._locked extension
  • Use of HTA files for ransom notes

Recommended Actions

  • Implement robust backup and disaster recovery strategies
  • Utilize anti-ransomware solutions and endpoint protection
  • Conduct regular security audits and vulnerability assessments
  • Educate users on phishing and ransomware threats

Suggested Tags

Ransomware
Financial gain
Criminal
Medium sophistication

Confidence Assessment

The confidence level in the available data on Trigona is moderate, with a clear understanding of the actor's primary goals and tactics. However, information gaps exist regarding the actor's specific targeting preferences, the full scope of their operations, and the potential for evolution in their tactics and tools. Further intelligence gathering and analysis are necessary to fully understand Trigona's capabilities and intentions.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

114

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 11, 2023
Last Seen
Mar 30, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.