Skip to main content
Back to Ransomware Database
Ransomware Group

trigona

According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.

Known victims49

Threat Level

MEDIUM

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DiscoveryEnum

  • Advanced Port Scanner
  • SoftPerfect NetScan

Exfiltration

  • MEGA
  • RClone

Offsec

  • Cobalt Strike

RMM-Tools

  • AnyDesk
  • LogMeIn
  • ScreenConnect
  • Splashtop
  • TeamViewer
0

Check If You’re Affected

Search our database to see if your organization appears in trigona’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request