The relatively new Trigona ransomware strain, according to Unit 42 researchers, was particularly active in December 2022, targeting industries in the manufacturing, finance, construction, agriculture, marketing, and high technology industries.
“Trigona’s threat operator engaging in behavior such as obtaining initial access to a target’s environment, conducting reconnaissance, transferring malware via remote monitoring and management (RMM) software, creating new user accounts and deploying ransomware,” Unit 42 researchers.
Companies in the United States, Australia, New Zealand, Italy, France, and Germany were affected.
From the recent analysis, researchers say that unique computer IDs (CIDs) and victim IDs are included in Trigona’s ransom notes, which are presented via an HTML application with embedded JavaScript rather than the typical text file (VID).
The ransom note’s JavaScript contains the following details:
At least 15 possible victims who were compromised in December 2022 may be found, according to experts. Also, in January 2023 and February 2023, they discovered two new Trigona ransom notes.
There was no proof that Trigona was using a leak site for double extortion when it was originally discovered. The victims were sent to their negotiating portal by their ransom message instead. A researcher identified a leak site attributable to Trigona hosted on a specific IP address.
Additionally, tactics, techniques, and procedures (TTPs) used by Trigona operators and CryLock ransomware operators coincide, indicating that the threat actors who previously used CryLock ransomware may have switched to using Trigona ransomware.
Both ransomware families drop ransom notes in HTML Application format, and the ransom message is similar, including:
Hence, by unveiling Trigona and its unusual method of obfuscating malware utilizing password-protected executables, defenders can better defend their organizations against this threat.
Network Security Checklist – Download Free E-Book
Related Read
A recent investigation by the FortiGuard Incident Response (FGIR) team has uncovered a sophisticated, long-term…
StealC, a notorious information stealer and malware downloader first sold in January 2023, has rolled…
Cybersecurity researchers at Bitdefender have identified a significant uptick in subscription-based scams, characterized by an…
SocGholish, a notorious loader malware, has evolved into a critical tool for cybercriminals, often delivering…
Cybersecurity researchers uncovered a sophisticated supply chain attack targeting the Go programming language ecosystem in…
North Korean nationals have successfully infiltrated the employee ranks of major global corporations at a…