INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Trigona Affiliates Deploy Custom Exfiltration Tool for Data Theft
| 2026-04-23 16:42 DATA BREACH
Executive Summary
AI-generated
Trigona Affiliates, a group operated by the cybercrime organization Rhantus, recently deployed a custom exfiltration tool to streamline data theft in attacks that occurred in March 2026. This marks a significant shift in tactics for Trigona affiliates, who have been using this custom-developed tool designed to provide attackers with granular control over the data theft process since their re-emergence in September 2023. The motivation behind moving away from publicly available tools remains unknown, but it is possible that the attackers are investing time and effort in proprietary malware to maintain a lower profile during critical phases of their attacks. This custom tool was used by Trigona affiliates to carry out ransomware operations, affecting an unspecified number of victims.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ra•••••.live
se•••••.com
ra•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Intelligence Sources
Data Breaches
2026-04-23