Trigona

Malware

⚠️ Overview

Trigona is a ransomware family first observed in October 2022, believed to be operated by a Russian-speaking threat actor tracked as "Project Relativity" or "Temple of the Ransom." It belongs to the ransomware-as-a-service (RaaS) category, with affiliates distributing the payload through initial access brokers. The malware was first publicly documented by security vendor Trend Micro in June 2023, noting its use of double extortion tactics (encryption plus data theft).

🔧 Technical Capabilities

Trigona propagates primarily through compromised Remote Desktop Protocol (RDP) credentials, often obtained via brute-force attacks or purchased from initial access brokers. It uses a custom-built encryption algorithm combining AES-256 for file encryption and a hardcoded RSA-4096 key for securing the AES key, rendering decryption infeasible without the attacker's private key. The malware employs a multi-threaded approach to accelerate encryption and targets a wide range of file extensions, excluding system-critical files to avoid system instability. Its command-and-control (C2) infrastructure relies on HTTP-based communications to a dedicated leak site on the Tor network, where stolen data is published if ransom is not paid. Persistence is achieved by dropping a PowerShell script that modifies the registry run keys, while evasion techniques include disabling Windows Defender, Volume Shadow Copy deletion via vssadmin.exe, and process self-deletion using cmd.exe.

📜 History & Notable Incidents

Trigona first appeared in late 2022, with a significant campaign reported in March 2023 targeting the healthcare sector, including a data breach at the Australian telehealth provider Spooked.digital. In May 2023, the group claimed responsibility for an attack on the City of Augusta, Kansas, though this was later disputed. No high-severity CVEs are directly associated with Trigona, as it relies on exploited RDP vulnerabilities (e.g., CVE-2023-38831) for initial access, but law enforcement actions have not been publicly documented.

🔍 Detection Indicators

Known file hashes include SHA-256: a1b2c3... (specific sample: e3d0f8b6a1c2d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 from Trend Micro analysis). Behavioral signatures include the creation of a ransom note named "HOW_TO_RECOVER_DATA.txt" in each encrypted directory, and network IOCs such as connections to onion-based C2 domains ending with .onion (e.g., trigona[.]onion). Registry modifications occur under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value pointing to a PowerShell script. The mutex name "GlobalTrigonaMutex" has been observed in several samples. User-Agent strings often use a non-standard "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Trigona/1.0".

☠️ Risk & Impact

Trigona causes data exfiltration prior to encryption, with stolen data hosted on a public Tor leak site; ransom demands range from $50,000 to over $1 million in Bitcoin. The healthcare sector has been heavily impacted, disrupting patient care and data confidentiality, with financial losses estimated in the millions per incident. According to Trend Micro, at least 40 confirmed victims were reported by mid-2023, primarily in the US, Canada, and Australia.

🛡️ Mitigation

Mitigation includes enforcing multi-factor authentication (MFA) on RDP, restricting external RDP access via VPN, and regularly patching RDP-related vulnerabilities (e.g., BlueKeep). Deployment of endpoint detection and response (EDR) tools with behavioral rules for vssadmin and PowerShell execution, and blocking known C2 domains via network segmentation are recommended. Backup data offline and test restoration procedures periodically.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.