PULSE NAME
Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
WHITE Trigona AlienVault 2026-05-01 Modified: 2026-05-04
76
IOCs
HIGH VOLUME
Trigona ransomware affiliates deployed a custom exfiltration tool called uploader_client.exe during attacks in March 2026, marking a tactical shift from relying on off-the-shelf utilities like Rclone. The tool features parallel streams with five default connections, connection rotation after 2,048 MB transfers to evade network monitoring, and granular filtering to exclude low-value files. Prior to exfiltration, attackers disabled security defenses using kernel-level tools including HRSword, PCHunter, Gmer, YDark, and WKTools with vulnerable drivers. Remote access was established via AnyDesk, while credentials were harvested using Mimikatz and Nirsoft utilities. The custom tooling demonstrates higher technical maturity compared to typical ransomware operations, providing enhanced stealth capabilities while requiring greater development resources. Targeted data included invoices and high-value PDF documents from networked drives.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Trigona uploader_client.exe HRSword PCHunter Volgmer - S0180 YDark WKTools DumpGuard StpProcessMonitorByovd PowerRun Mimikatz AnyDesk MalExtractor ParsVbs StartBat GoGra
Indicators of Compromise (17 / 76 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1a12519bdeb372e8b1836d78ec61617bbac166aa 2026-05-01
FileHash-SHA1 1ca08190c945786c974156f75262d4fd55a868b0 2026-05-01
FileHash-SHA1 239e671ea09e4c5154ffb3ed2a78aac1139ed3ef 2026-05-01
FileHash-SHA1 32e24780735a0148c3cc4ce7dda30ed9365397a9 2026-05-01
FileHash-SHA1 397a5701384f1ec1ded95f71dc69c0903935a9ad 2026-05-01
FileHash-SHA1 4a3418d78d8fe36b39d1ee5435796369b88a8762 2026-05-01
FileHash-SHA1 539c228b6b332f5aa523e5ce358c16647d8bbe57 2026-05-01
FileHash-SHA1 5d275449228e6464410aaefc58d7f3732e279fad 2026-05-01
FileHash-SHA1 5f1cbc3d99558307bc1250d084fa968521482025 2026-05-01
FileHash-SHA1 8729815f87f4186fd46d52418c1b7ae2a54aebcf 2026-05-01
FileHash-SHA1 92862afc2fb4c2e5d624d7e1b1ee2d9f0692b6f6 2026-05-01
FileHash-SHA1 99c4401366ad7e561ce3ac8e5bb9a7a8144aa3ea 2026-05-01
FileHash-SHA1 9f7835b3cdc7cbc641904b1923d7de4a72b3c437 2026-05-01
FileHash-SHA1 b67a2f9d9de2135617caea8d4a7488e2a962e3e2 2026-05-01
FileHash-SHA1 e43d7a6ad722d285813afb9eefe53d264af6948b 2026-05-01
FileHash-SHA1 e61f7aca50ca1eb9857dadec2f601a113ade907c 2026-05-01
FileHash-SHA1 ea5cd55a44b8be532af602002f498717fc192818 2026-05-01