Skip to content
Trigona Ransomware

Trigona Ransomware

www.merabytes.com April 24, 2026

Real case: Company victim of Trigona Ransomware in November 2023 (client name and sector omitted for confidentiality)

Gaining persistence after initial access

The attackers started by installing TeamViewer and SplashTop on the compromised machine on November 4, 2023 at 11:41 using the local Administrator user of the exposed system to ensure persistence.

The absence of brute-force attempts and the use of valid credentials suggest that the threat actor may have obtained the local Administrator password of the exposed machine through leaks or purchase from an IAB (Initial Access Broker), especially considering other external access events in the weeks prior to the intrusion.

Lateral movement to the main SQL server

The beginning of the compromise was identified following a lateral movement from the exposed RD machine to the internal SQL server using the same local administrator user that was used for the initial access.

After gaining local administrator access on the SQL server, a file called “newuser.bat” was created that created another Local Administrator user on the SQL machine called “sys”.

newuser.bat - Creation of new user “sys” with password “t1518061-“ (Local Administrator and RDP)

Defense Evasion Tactics

After creating this user, the “sys” user was used via another batch script to modify the Windows registry and enable WDigest (credential caching), enable RDP via a Windows firewall rule, and disable Windows Defender.

zam.bat (Enables WDigest, Enables RDP, Disables Windows Defender)

Reconnaissance and lateral movement tasks

Use of NetScan (nmap alternative)

During the intrusion, the “netscan.exe” tool from SoftPerfect Ltd. was copied and executed at C:\Users\Administrador\Pictures\netscan\netscan.exe on several servers as they were being compromised, to discover other machines on the network with RDP and SMB enabled, as well as database services on other network servers.

Enabling reading of locked files via IOBit Unlocker

Four days after executing the “zam.bat” script, on November 8, 2023 at 23:09, the cybercriminals installed the software “IOBit Unlocker” to facilitate copying files and reading locked files, such as the SQL database, which cannot be copied if it is in use by another process.

Use of pCloud and exfiltration via rclone

Using this file unlocking method via IOBit Unlocker, they managed to copy and steal database and SQL server information using the private cloud service and the remote file copy program rclone.

The rclone configuration file was encrypted. The password used is encrypted with a SHA-256 hash, which produces the key to connect to the server. The hashed password is not stored in the configuration file.

This type of OPSEC demonstrates notable experience on the part of the group that a less experienced threat actor might overlook.

Use of SnipeDrive for file and directory listing

During the exfiltration phase we saw that the threat actor used a program called “sd.exe” (SnipeDrive).

The “sd.exe” program is a self-extracting binary that deploys a tool called “Snap2HTML.exe” along with a batch file designed to run this tool on each disk drive. The functionality of Snap2HTML is interesting for threat actors, as it allows taking a “snapshot” of folder structures on a hard drive and saving them as HTML files.

They used this listing to quickly identify files of interest, plan the data exfiltration, and document the file structure of the victim company.

Escalating from Local Administrator to Domain Admin

Use of mimikatz (packed, in-memory execution)

One day after installing IObit Unlocker and following data exfiltration, on November 9, 2023 at 19:44, the file “423844210.dat” was copied via SplashTop, which contained an encrypted version of the mimikatz tool which was executed in memory to evade the EDR. Following its execution, the ransomware group obtained the credentials of several domain administrators who had logged in to the SQL server with WDigest enabled.

Ransomware Detonation via RDP and SMB

On November 12, 2023 at 1:00, using the SQL server as a pivot, they established multiple RDP connections to critical systems using domain administrator credentials, including several file servers and backup servers on which they also copied and executed the Trigona ransomware.

The ransomware also initiated SMB connections to other remote hosts such as NAS devices and the primary and secondary domain controllers, encrypting them as well.

Deletion of Copies and Databases after Detonation

Deletion of Shadow Copies and Disabling Windows Recovery System

After the ransomware execution, on November 12, 2023 at 3:01, the threat actors massively deployed and executed a file called “coba.bat” to delete Shadow Copies and disable the Windows recovery system.

Use of Wise Force Deleter to delete SQL databases

After the ransomware detonation, the threat actor also used “WiseDeleter.exe” manually to delete the SQL database, which had not been encrypted by the ransomware since the SQL service was running and prevented the Trigona ransomware from writing to it.

Detection and IOCs (Indicators of Compromise)

Hashes and related files

How our Adversary-Aware SOC would have prevented this attack

Our Adversary-Aware SOC is specifically designed to identify and neutralize ransomware tactics like those used by Trigona:

Thanks to the adversary-focused mindset , our SOC understands the TTPs (Tactics, Techniques, and Procedures) of ransomware groups like Trigona. We actively monitor known IOCs, ransomware behavior patterns, and evasion techniques to stop attacks in their early stages, before they can cause significant damage.

The attack was successful because there was no adaptive defense or continuous monitoring . With Merabytes , the story would have ended differently:

If you are interested in accessing other private reports or specific rules for EDR/XDR, visit merabytes.com and request access to our advanced endpoint protection services + continuous vulnerability analysis.

An Adversary-Aware SOC goes beyond traditional security monitoring by understanding attacker tactics, techniques, and procedures (TTPs). We proactively hunt for threats using MITRE ATT&CK framework, behavioral analysis, and threat intelligence to detect attacks that bypass conventional security controls.

Traditional security tools focus on known signatures and indicators. Our behavioral detection analyzes anomalies in user activity, email patterns, network traffic, and system behavior to identify sophisticated attacks that use legitimate tools or bypass authentication controls. This caught the attacks in these case studies before significant damage occurred.

Our SOC operates 24/7 with real-time monitoring and automated response capabilities. Critical alerts trigger immediate investigation and containment actions within minutes. We provide continuous threat hunting, forensic analysis, and coordinated incident response to minimize impact and prevent lateral movement.

We combine global threat intelligence feeds with our own research from real incidents. Every attack we analyze contributes to our detection rules and IOC database, which is immediately shared across all protected environments. This means if we see a new attack pattern targeting one client, all clients are automatically protected within hours.

Absolutely. Our SOC integrates with your existing EDR, XDR, SIEM, firewalls, email security, and identity protection tools. We enhance their effectiveness by correlating events across all sources, applying adversary-aware detection logic, and providing expert human analysis that automated tools alone cannot achieve.