trinity
RansomwareAbout the group
Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Impact and victims
The group trinity has 1 known ransomware victims. See the most affected sectors and countries and recent victims.
1known victims
1in Brazil
1sectors hit
Most attacked sectors
Technology1
Most affected countries
🇧🇷 Brasil1
Recent victims
FoccoERP
trinity uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →