← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
Trigona ransomware affiliates have adopted a custom-developed exfiltration tool called uploader_client.exe in attacks observed during March 2026, marking a significant tactical evolution. This command-line utility features parallel data streams, connection rotation to evade network monitoring, and granular file filtering capabilities. The shift from commonly used off-the-shelf tools like Rclone to proprietary malware suggests attackers are attempting to maintain a lower profile during critical attack phases. Prior to data exfiltration, attackers deploy multiple security-disabling tools including HRSword, PCHunter, and various BYOVD utilities to terminate endpoint protection at the kernel level. Remote access is established through AnyDesk, while credential theft is conducted using Mimikatz and Nirsoft utilities. This custom tooling approach demonstrates a higher degree of technical maturity compared to typical ransomware affiliate operations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trigona
uploader_client
HRSword
PCHunter
Volgmer - S0180
YDark
WKTools
DumpGuard
StpProcessMonitorByovd
PowerRun
Mimikatz
AnyDesk
MalExtractor
GoGra
Indicators of Compromise (11 / 64 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | 1a12519bdeb372e8b1836d78ec61617bbac166aa | — | 2026-04-23 | |
| FileHash-SHA1 | 1ba499bafaa369be58e795a150403c8729ef5d95 | — | 2026-04-23 | |
| FileHash-SHA1 | 31b827dad64b2dd881b9f0ceb012e0ac6885492c | — | 2026-04-23 | |
| FileHash-SHA1 | 4df0949f634c4d74a7e1cc48b6575f9a27dc21c9 | — | 2026-04-23 | |
| FileHash-SHA1 | 73f8e5c17b49b9f2703fed59cc2be77239e904f7 | — | 2026-04-23 | |
| FileHash-SHA1 | 746710470586076bb0757e0b3875de9c90202be2 | — | 2026-04-23 | |
| FileHash-SHA1 | 8729815f87f4186fd46d52418c1b7ae2a54aebcf | — | 2026-04-23 | |
| FileHash-SHA1 | 99c4401366ad7e561ce3ac8e5bb9a7a8144aa3ea | — | 2026-04-23 | |
| FileHash-SHA1 | b67a2f9d9de2135617caea8d4a7488e2a962e3e2 | — | 2026-04-23 | |
| FileHash-SHA1 | bd48322845f8930e58e038dfd4e1e243e80a6b76 | — | 2026-04-23 | |
| FileHash-SHA1 | e43d7a6ad722d285813afb9eefe53d264af6948b | — | 2026-04-23 |