PULSE NAME
Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
WHITE Rhantus AlienVault 2026-04-23 Modified: 2026-04-24
64
IOCs
HIGH VOLUME
Trigona ransomware affiliates have adopted a custom-developed exfiltration tool called uploader_client.exe in attacks observed during March 2026, marking a significant tactical evolution. This command-line utility features parallel data streams, connection rotation to evade network monitoring, and granular file filtering capabilities. The shift from commonly used off-the-shelf tools like Rclone to proprietary malware suggests attackers are attempting to maintain a lower profile during critical attack phases. Prior to data exfiltration, attackers deploy multiple security-disabling tools including HRSword, PCHunter, and various BYOVD utilities to terminate endpoint protection at the kernel level. Remote access is established through AnyDesk, while credential theft is conducted using Mimikatz and Nirsoft utilities. This custom tooling approach demonstrates a higher degree of technical maturity compared to typical ransomware affiliate operations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trigona uploader_client HRSword PCHunter Volgmer - S0180 YDark WKTools DumpGuard StpProcessMonitorByovd PowerRun Mimikatz AnyDesk MalExtractor GoGra
Indicators of Compromise (11 / 64 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1a12519bdeb372e8b1836d78ec61617bbac166aa 2026-04-23
FileHash-SHA1 1ba499bafaa369be58e795a150403c8729ef5d95 2026-04-23
FileHash-SHA1 31b827dad64b2dd881b9f0ceb012e0ac6885492c 2026-04-23
FileHash-SHA1 4df0949f634c4d74a7e1cc48b6575f9a27dc21c9 2026-04-23
FileHash-SHA1 73f8e5c17b49b9f2703fed59cc2be77239e904f7 2026-04-23
FileHash-SHA1 746710470586076bb0757e0b3875de9c90202be2 2026-04-23
FileHash-SHA1 8729815f87f4186fd46d52418c1b7ae2a54aebcf 2026-04-23
FileHash-SHA1 99c4401366ad7e561ce3ac8e5bb9a7a8144aa3ea 2026-04-23
FileHash-SHA1 b67a2f9d9de2135617caea8d4a7488e2a962e3e2 2026-04-23
FileHash-SHA1 bd48322845f8930e58e038dfd4e1e243e80a6b76 2026-04-23
FileHash-SHA1 e43d7a6ad722d285813afb9eefe53d264af6948b 2026-04-23