PULSE NAME
Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
WHITE Rhantus AlienVault 2026-04-23 Modified: 2026-04-24
64
IOCs
HIGH VOLUME
Trigona ransomware affiliates have adopted a custom-developed exfiltration tool called uploader_client.exe in attacks observed during March 2026, marking a significant tactical evolution. This command-line utility features parallel data streams, connection rotation to evade network monitoring, and granular file filtering capabilities. The shift from commonly used off-the-shelf tools like Rclone to proprietary malware suggests attackers are attempting to maintain a lower profile during critical attack phases. Prior to data exfiltration, attackers deploy multiple security-disabling tools including HRSword, PCHunter, and various BYOVD utilities to terminate endpoint protection at the kernel level. Remote access is established through AnyDesk, while credential theft is conducted using Mimikatz and Nirsoft utilities. This custom tooling approach demonstrates a higher degree of technical maturity compared to typical ransomware affiliate operations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trigona uploader_client HRSword PCHunter Volgmer - S0180 YDark WKTools DumpGuard StpProcessMonitorByovd PowerRun Mimikatz AnyDesk MalExtractor GoGra
Indicators of Compromise (11 / 64 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1dfe0e65f3fb60ee4e46cf8125ad67ca 2026-04-23
FileHash-MD5 23516ea1f2cc771f705807c2fc7d163e 2026-04-23
FileHash-MD5 58bb9dab4e9b3aa2fd1e7a7b17d2eeb1 2026-04-23
FileHash-MD5 8f2fde9aa0eb6f6c83c30608061691cc 2026-04-23
FileHash-MD5 97e045bc056b5f68f18ea4fbbb9cc64a 2026-04-23
FileHash-MD5 ab06eeb603656d3943cd30396f82a45f 2026-04-23
FileHash-MD5 c73e71825adbfb9821b9fa6e8672903c 2026-04-23
FileHash-MD5 d611f824074a57e7fd1d08341edeb559 2026-04-23
FileHash-MD5 f3d20449bab41301aefad304cb02773b 2026-04-23
FileHash-MD5 fae1061813f2148296767d28262d2c25 2026-04-23
FileHash-MD5 fc3b93e042de5fa569a8379d46bce506 2026-04-23