Pro-Ukraine hacktivists reportedly hijacked Trigona ransomware servers

Pro-Ukraine hacktivists reportedly hijacked Trigona ransomware servers

A group of pro-Ukraine hacktivists known as Ukrainian Cyber Alliance has reportedly commandeered a data leak site of the Trigona ransomware, exfiltrated data and wiped the servers.

"Trigona is gone. The servers of the Trigona ransomware have been exfiltrated and wiped. Welcome to the world you created for others," reads the message on the defaced Trigona website.

Trigona is a relatively new ransomware operation first spotted in 2022. By April 2023, Trigona began targeting compromised MSSQL servers by stealing credentials via brute force techniques.

The threat actors behind Trigona are thought to be the same group behind the CryLock ransomware due to similarities in tools, tactics, and procedures (TTPs). The gang has also been linked to the ALPHV group (also known as BlackCat), though researchers believe that any similarities between Trigona and BlackCat ransomware are only circumstantial at best. The two groups may have been collaborating at one point but the ALPHV group was not involved with Trigona’s development and operation.

Trigona is written in the Delphi programming language. The operation uses double extortion tactics combining data exfiltration with file encryption. The ransomware has been regularly updated with new capabilities including a new data wiper feature.


Back to the list

Latest Posts

Cyber Security Week in Review: June 13, 2025

Cyber Security Week in Review: June 13, 2025

In brief: Microsoft fixes zero-day exploited by the Stealth Falcon APT, the Graphite spyware targets journalists via an iMessage exploit, and more.
13 June 2025
Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

The campaign, first observed on June 5, involves brute-force login attempts originating from hundreds of unique IP addresses.
12 June 2025
ConnectWise rotates digital certificates due to security risks

ConnectWise rotates digital certificates due to security risks

The company said that this is a preventive action and not related to any recent security incident.
11 June 2025