According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files. Known victims: 49 1 ransom note(s) on file
Objectives
Executive Summary
Trigona is a medium-sophistication criminal threat actor primarily motivated by organizational gain, with goals of ransomware and financial gain. The actor has been active since 2023 and has targeted at least 49 victims, encrypting files and demanding ransom. Trigona's operations are characterized by the use of ransomware that appends the ._locked extension to filenames and drops a ransom note.
Goals & Targeting
Trigona's strategic objectives appear to be centered around achieving financial gain through the deployment of ransomware. The actor's targeting profile suggests a focus on organizations or individuals capable of paying significant ransoms, although the lack of specificity regarding targeted sectors and countries implies a potentially broad scope of operations. The typical victims of Trigona are likely those with valuable data and the financial resources to meet the actor's ransom demands, highlighting the need for organizations to prioritize robust cybersecurity measures and backup strategies to mitigate the impact of such attacks.
Enhanced Description
The lack of specific information on targeted sectors and countries suggests that Trigona may not be highly selective in its targeting, potentially indicating a more opportunistic approach. However, the focus on ransomware and financial gain implies that the actor is primarily interested in targeting organizations or individuals with the capability to pay significant ransoms. Given the medium level of sophistication attributed to Trigona, it is plausible that the actor continues to evolve and refine its tactics, potentially incorporating new techniques or tools into its operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Trigona's campaign patterns are characterized by the consistent use of ransomware to encrypt files and demand ransom. The actor's operational tempo is marked by a steady stream of attacks, with at least 49 known victims since the actor's first observed activity in 2023. Notable past operations include the deployment of ransomware with the ._locked extension and the use of HTA files for ransom notes. Given the medium level of sophistication, Trigona's operations may evolve to incorporate new tactics or tools, potentially increasing the actor's effectiveness and reach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Trigona is moderate, with a clear understanding of the actor's primary goals and tactics. However, information gaps exist regarding the actor's specific targeting preferences, the full scope of their operations, and the potential for evolution in their tactics and tools. Further intelligence gathering and analysis are necessary to fully understand Trigona's capabilities and intentions.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
114
IOCs
0
Observed Data
0
Tactics