PULSE NAME
Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
WHITE Trigona AlienVault 2026-05-01 Modified: 2026-05-04
76
IOCs
HIGH VOLUME
Trigona ransomware affiliates deployed a custom exfiltration tool called uploader_client.exe during attacks in March 2026, marking a tactical shift from relying on off-the-shelf utilities like Rclone. The tool features parallel streams with five default connections, connection rotation after 2,048 MB transfers to evade network monitoring, and granular filtering to exclude low-value files. Prior to exfiltration, attackers disabled security defenses using kernel-level tools including HRSword, PCHunter, Gmer, YDark, and WKTools with vulnerable drivers. Remote access was established via AnyDesk, while credentials were harvested using Mimikatz and Nirsoft utilities. The custom tooling demonstrates higher technical maturity compared to typical ransomware operations, providing enhanced stealth capabilities while requiring greater development resources. Targeted data included invoices and high-value PDF documents from networked drives.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trigona uploader_client.exe HRSword PCHunter Volgmer - S0180 YDark WKTools DumpGuard StpProcessMonitorByovd PowerRun Mimikatz AnyDesk MalExtractor ParsVbs StartBat GoGra
Indicators of Compromise (17 / 76 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 23516ea1f2cc771f705807c2fc7d163e 2026-05-01
FileHash-MD5 44bd492dfb54107ebfe063fcbfbddff5 2026-05-01
FileHash-MD5 58bb9dab4e9b3aa2fd1e7a7b17d2eeb1 2026-05-01
FileHash-MD5 716c04b0eaa8106b542d4041ad065ef5 2026-05-01
FileHash-MD5 957f2d9e3370212548a57020233e6ba7 2026-05-01
FileHash-MD5 97e045bc056b5f68f18ea4fbbb9cc64a 2026-05-01
FileHash-MD5 987b65cd9b9f4e9a1afd8f8b48cf64a7 2026-05-01
FileHash-MD5 9b1ae658c91d5883d7743130c6ca0523 2026-05-01
FileHash-MD5 ab06eeb603656d3943cd30396f82a45f 2026-05-01
FileHash-MD5 b9b514e817a9e1cc2e86e3c00b555873 2026-05-01
FileHash-MD5 c48b572a659a1ade4190421ab2280d87 2026-05-01
FileHash-MD5 d28f0cfae377553fcb85918c29f4889b 2026-05-01
FileHash-MD5 d611f824074a57e7fd1d08341edeb559 2026-05-01
FileHash-MD5 dc6252f2be3256e4202e46e6ffd4383b 2026-05-01
FileHash-MD5 df218168bf83d26386dfd4ece7aef2d0 2026-05-01
FileHash-MD5 e9dc058440d321aa17d0600b3ca0ab04 2026-05-01
FileHash-MD5 fad7bc52b93328305f4bd52fe1ca498a 2026-05-01