trigona

Ransomware
Sourceransomware.live

About the group

According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group trigona has 1 known ransomware victims. See the most affected sectors and countries and recent victims.

1known victims
1in Brazil
1sectors hit
Most attacked sectors
Healthcare1
Most affected countries
🇧🇷 Brasil1
Recent victims
UnimedHealthcare · BR · 2023-09-05

trigona uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →