Skip to content

trigona

Inactive

19 tracked victims · First seen Apr 11, 2023 · Last seen Mar 30, 2024

About

Aggregated threat-intel description

According to PCrisk, Trigona is ransomware that encrypts files and appends the ._locked extension to filenames. Also, it drops the how_to_decrypt.hta file that opens a ransom note. An example of how Trigona renames files: it renames 1.jpg to 1.jpg._locked, 2.png to 2.png._locked, and so forth.It embeds the encrypted decryption key, the campaign ID, and the victim ID in the encrypted files.

Sectors: Business Services, Manufacturing, Technology · Countries: US, MX, ID

Recent victims

View all →
VictimSectorCountryPostedStatus
ClaroBusiness ServicesMXMar 30, 2024
South Star ElectronicsTechnologyCNMar 20, 2024
IndoarsipBusiness ServicesIDMar 16, 2024
BwizerHealthcarePTMar 16, 2024
Topa PartnersNot FoundNZMar 16, 2024
ATMCoTechnologyUSMar 15, 2024
Dinamic OilManufacturingITFeb 28, 2024
Hotel Avenida, Hostal Espoz y Mina, Hostal Arriazu, Pension AlemanaHospitality and TourismESFeb 28, 2024
America MovilBusiness ServicesMXFeb 14, 2024
FALCO ElectronicsTechnologyMXFeb 14, 2024
AusaManufacturingESJan 31, 2024
Genesis MotorsManufacturingAUJan 31, 2024
CMG Drainage EngineeringBusiness ServicesUSJan 31, 2024
Daher ContractingBusiness ServicesUSJan 31, 2024
Lomma Crane & RiggingBusiness ServicesUSJan 29, 2024
Samuel Sekuritas Indonesia & Samuel Aset ManajemenFinancialIDJan 18, 2024
Premier Facility ManagementBusiness ServicesUSJan 18, 2024
Fertility NorthHealthcareAUJan 18, 2024
Vision PlastManufacturingFRJan 18, 2024

All ransomware groups · Dark web intelligence