216.73.216.6

Analysis of Trigona Threat Actor's Latest Attack Cases

· Published 29/10/2025 10:50 · Modified 29/10/2025 18:32

Export JSON

Essential information

Published
29/10/2025 10:50
Modified
29/10/2025 18:32
Tags
2025-10-29 ransomware remote-control trigona
Related entities
5 observables, 1 intrusion sets (apt), 18 techniques (mitre), 2 malware

Description

The threat actor continues to target MS-SQL servers through brute-force and dictionary attacks, exploiting weak credentials. They use CLR Shell for additional payloads and employ various tools like BCP, Curl, Bitsadmin, and PowerShell to install malware. The attackers utilize remote control tools such as AnyDesk, RDP, and possibly Teramind. New scanner malware written in Rust targets RDP and MS-SQL services. The threat actor also uses tools like SpeedTest and a custom StressTester. Various privilege escalation and file manipulation tools are employed. To protect against these attacks, administrators should use complex passwords, regularly update security software, and implement firewalls to control access to database servers.

External references