Home/Threat Actor/Trigona
Threat Actor

Trigona

trigona_ransomware · ransomware_raas_crylock_lineage_uca_taken_down_2023 · active since 2022-06

Trigona (canonical naming, also tracked by Trend Micro as Water Ungaw internally) is a Delphi-based Ransomware-as-a-Service (RaaS) operation emerging October 2022 with binaries first observed June 2022 per Trend Micro Water Ungaw internal tracking + Ransomware Spotlight November 2023 analysis ("The Trigona ransomware, first tracked by Trend Micro as Water Ungaw, emerged in October 2022. However, binaries of the ransomware were first seen as early as June of the same year")

CryLock-offspring lineage attribution per Trend Micro ("Threat actors behind the group are known to be affiliated with CryLock due to their similarities in tactics, techniques, and procedures TTPs, ransom note file name, and email addresses used") + AhnLab ASEC April 2023 + 2024 + Arete February 2023 ManageEngine CVE-2021-40539 disclosure with circumstantial BlackCat linkage + SentinelOne In-Depth Analysis + Palo Alto Networks December 2022 + Bank Info Security + Bleeping Computer + The Record + GridInSoft + Anvilogic industry coverage.

Russian-aligned cybercrime ecosystem attribution via RAMP (Russian Anonymous Marketplace) forum network-access-broker collaboration consistent with broader Russian cybercrime ecosystem.

standalone cluster paralleling hunters_international + embargo + cactus in v0.1.160 2022-2025 post-takedown + emerging RaaS cell.

operational target profile Turkey (23.5%) + Philippines (19.6%) + Brazil (13.7%) + Germany + Thailand top 5 victimology per Trend Micro + United States + India + Israel + Italy secondary per The Record + signature government organizations 21.4% primary sector + manufacturing + finance + construction + agriculture + marketing + high-tech + healthcare + banking + education secondary sectors + 33 organizations compromised April-October 2023 per Trend Micro leak site analysis + poorly-managed externally-exposed MS-SQL servers signature initial access vector.

operational attack architecture: (1) cluster-defining Delphi programming language detection-evasion signature distinctive language choice for Windows ransomware development with Delphi-specific runtime library presence in memory dumps.

(2) cluster-defining CryLock-offspring lineage signature with shared TTPs + ransom note file name + email addresses establishing operator continuity from CryLock.

(3) cluster-defining MSSQL brute-force / dictionary attack initial access on poorly-managed exposed MS-SQL servers per AhnLab ASEC + Trend Micro April 2023 onward; (4) cluster-defining ManageEngine CVE-2021-40539 ServiceDesk Plus + ADSelfService Plus public-facing- application exploitation per Arete February 2023 with circumstantial BlackCat linkage (Trend Micro assessment of similarities as "circumstantial at best")

(5) signature Windows + Linux multi- platform capability with May 2023 Linux variant emergence.

(6) signature AES-256 + RSA-4112 OFB (Output Feedback) mode encryption with .locked file extension + how_to_decrypt.hta ransom note as valid HTA application + signature configuration data embedded with multiple AES-CBC encryption layers.

(7) cluster-defining Monero cryptocurrency payment preference + aggressive-deadline-intimidation tradecraft per SentinelOne with TOR-based payment portal + auth-key login from ransom note signature; (8) signature 20-50% affiliate revenue RaaS model per Trend Micro ("group positioned itself as running a lucrative scheme, launching global attacks and advertising revenues up to 20% to 50% for each successful attack")

(9) signature RAMP (Russian Anonymous Marketplace) forum network-access-broker collaboration for compromised-credentials sourcing consistent with Russian cybercrime ecosystem operational tradecraft.

(10) cluster-defining October 17, 2023 Ukrainian Cyber Alliance (UCA) takedown via Confluence CVE-2023-22515 exploitation by herm1t / Sean Townsend with complete infrastructure wipe ("Despite the efforts of their admins who changed passwords and shut down their infra facing the internet not TOR we were able to maintain persistent access to infra, exfiltrated all the data and wiped the servers. It included administration panel, landing page for victims, blog, leaks site, monero hot wallets, dev environment and internal team server with Rocket Chat, Confluence and Jira")

(11) signature Storm-0062 / DarkShadow / Oro0lxy adjacent Confluence CVE-2023-22515 zero-day exploitation pattern with same CVE used by Chinese APT cluster + Ukrainian hacktivist counter-cybercrime operations.

(12) cluster-defining AhnLab ASEC 2024 Mimic ransomware adoption operator-continuity signature post-UCA- takedown ("the threat actor's email address saved in the ransom note, it can be confirmed that the recently detected Trigona ransomware's threat actor is the same attacker responsible for previous cases... it is presumed that the Trigona ransomware threat actor is also using Mimic in their attacks") with Mimic exploiting Everything search tool for file-search acceleration.

(13) signature /!autorun + /!lan + /erase + /full command-line arguments + Registry Run keys persistence + SMB spreading toggleable capability + Mimikatz credential dumper tradecraft.

cluster fills the October-2022- emergence + June-2022-early-samples + Water-Ungaw- tracking + Delphi-language + CryLock-offspring + MSSQL-brute-force + ManageEngine-CVE-2021-40539 + Mimic-adoption-post-UCA + AES-256-RSA-4112-OFB + .locked + Monero-aggressive-deadline + UCA-October- 17-2023-Confluence-CVE-2023-22515-takedown + 33- organizations-compromised + Turkey-Philippines- Brazil-Germany-Thailand-victimology + RAMP-network- access-broker-collaboration position in 2022-2025 post-takedown + emerging RaaS cell.

canonical illustration of October 2022 Delphi-based RaaS + CryLock-offspring lineage + MSSQL brute-force + ManageEngine CVE-2021-40539 exploitation + multi- platform Windows + Linux variants + Monero aggressive-deadline tradecraft + 20-50% affiliate revenue RaaS + UCA October 17 2023 Confluence CVE-2023-22515 takedown + Mimic-ransomware-operator- continuity post-takedown evidence + counter- cybercrime-via-hacktivism parallel pattern cited in essentially all subsequent emerging RaaS + counter-cybercrime industry analyses through 2022- 2026 period.

ransomware_raas_crylock_lineage_uca_taken_down_2023 confidence: high 21 aliases

Profile

Trigona (canonical naming, also tracked by Trend Micro as Water Ungaw internally) is a Delphi-based Ransomware-as-a-Service (RaaS) operation emerging October 2022 (early samples June 2022) believed offspring of CryLock ransomware family. Independent RaaS with CryLock-offspring lineage attribution via Trend Micro canonical Water Ungaw tracking + AhnLab ASEC April 2023 + Arete February 2023 ManageEngine + Bank Info Security + SentinelOne industry coverage. Russian-aligned cybercrime ecosystem attribution via RAMP network-access- broker collaboration.

Operations terminated October 17 2023 via Ukrainian Cyber Alliance takedown, though AhnLab ASEC 2024 evidence suggests operator continuity via Mimic ransomware adoption. Standalone cluster paralleling hunters_international + embargo + cactus in v0.1.160 2022-2025 post- takedown + emerging RaaS cell.

Operational target profile
  • Turkey + Philippines + Brazil + Germany + Thailand primary geographic per Trend Micro.
  • United States + India + Israel + Italy secondary.
  • Government organizations 21.4% primary.
  • Manufacturing + finance + construction + agriculture + marketing + high-tech + healthcare + banking secondary.
  • 33 organizations compromised April-October 2023 per Trend Micro.
  • Poorly-managed MSSQL servers signature initial access Operational attack architecture: (1) Delphi programming language detection- evasion (cluster-defining): distinctive language choice (2) CryLock-offspring lineage (cluster-defining): shared TTPs + ransom note + email addresses (3) MSSQL brute-force / dictionary attack (cluster-defining): signature initial access on poorly-managed exposed MS-SQL servers (4) ManageEngine CVE-2021-40539 exploitation (cluster-defining): per Arete February 2023 (5) Windows + Linux multi-platform (signature): May 2023 Linux variant emergence (6) AES-256 + RSA-4112 OFB-mode encryption (signature): with .locked extension + how_to_decrypt.hta ransom note (7) Monero + aggressive-deadline intimidation (cluster-defining): signature payment + pressure tradecraft (8) 20-50% affiliate revenue RaaS + RAMP forum network-access-broker (signature): Russian cybercrime ecosystem operational signature (9) Ukrainian Cyber Alliance October 17 2023 takedown via Confluence CVE-2023-22515 (cluster- defining): complete infrastructure wipe including Monero hot wallets + Rocket Chat + Confluence + Jira (10) AhnLab ASEC 2024 Mimic ransomware adoption operator-continuity (signature): post-UCA- takedown continuation evidence via shared email signatures The cluster fills the October-2022-emergence + June- 2022-early-samples + Water-Ungaw-tracking + Delphi- language + CryLock-offspring + MSSQL-brute-force + ManageEngine-CVE-2021-40539 + Mimic-adoption-post- UCA + AES-256-RSA-4112-OFB + .locked + Monero- aggressive-deadline + UCA-October-17-2023-Confluence- CVE-2023-22515-takedown + 33-organizations + Turkey- Philippines-Brazil + RAMP-network-access-broker position in 2022-2025 post-takedown + emerging RaaS cell.

Aliases

21
trigona_ransomwaretrigonawater_ungawwater ungawtrigona delphi ransomwaretrigona crylock ransomware offspringtrigona october 2022 emergence june 2022 early samplestrigona mssql brute force initial accesstrigona manageengine cve-2021-40539 exploitationtrigona mimic ransomware adoption ahnlab asec post-uca-takedowntrigona ukrainian cyber alliance takedown october 17 2023trigona vx_herm1t confluence cve-2023-22515 uca exploitationtrigona monero cryptocurrency payment preferencetrigona aggressive deadlines intimidation tradecrafttrigona .locked file extension how_to_decrypt.hta ransom notetrigona aes-256 rsa-4112 ofb-mode encryptiontrigona linux variant 2023 windows linux multi-platformtrigona 20-50 percent affiliate revenue raastrigona ramp forum russian anonymous marketplacetrigona turkey philippines brazil germany thailand top victimstrigona 33 organizations compromised april-october 2023

Notable Campaigns

12
2024Trigona AhnLab ASEC 2024 Mimic Ransomware Adoption Post-UCA Continuation Signature
2023Trigona Arete February 2023 ManageEngine CVE-2021-40539 Exploitation
2023Trigona April 2023 MSSQL Server Brute-Force Targeting Signature
2023Trigona Linux Variant Multi-Platform Signature (May 2023)
2023Trigona Ukrainian Cyber Alliance October 17, 2023 Takedown Signature
2023Trigona Storm-0062 / DarkShadow Confluence CVE-2023-22515 Adjacent Exploitation Signature
2022-2026Continued Industry Reference Status (2022-2026)
2022-2023Trigona RAMP Forum Network Access Broker Collaboration Signature
2022-2023Trigona 20-50% Affiliate Revenue RaaS Model Signature
2022Trigona Origin, October 2022 Emergence + June 2022 Early Samples (Water Ungaw)
2022Trigona CryLock Ransomware Offspring Signature
2022Trigona December 2022 15 Potential Victims (Palo Alto Networks)

Attribution & Reporting

Attributed by
Trend Micro (canonical Water Ungaw + November 2023 Ransomware Spotlight Trigona + 33 organizations + 5-country victimology)AhnLab ASEC (canonical April 2023 + 2024 MS-SQL Server + Mimic-adoption disclosure)Arete (canonical February 2023 ManageEngine CVE-2021-40539 + BlackCat-linkage)SentinelOne (canonical Trigona aggressive-deadline-intimidation analysis + In-Depth Analysis Detection Mitigation)Palo Alto Networks (canonical December 2022 15 potential victims observation)Ukrainian Cyber Alliance / herm1t / Sean Townsend (canonical October 17 2023 takedown)vx_herm1t (canonical Twitter takedown announcement)Bleeping Computer (canonical October 18 2023 Ukrainian activists hack Trigona ransomware coverage)The Record / Recorded Future News (canonical Pro-Ukraine group took down Trigona coverage)Bank Info Security / Mihir Bagwe (canonical Ukrainian Hacktivists Claim Trigona Takedown coverage)Information Security Media Group (canonical herm1t interview)Anvilogic (canonical Trigona Ransomware Site Down threat report)cybersecurity-help.cz (canonical Pro-Ukraine hacktivists Trigona servers)GridInSoft (canonical Trigona Hacked by Ukrainian Cyber Alliance)NordVPN (canonical Trigona threat description)Dmitry Smilyanets / Recorded Future (canonical Trigona Leaks blog tracking)
Key reporting
reportTrend Micro: Ransomware Spotlight Trigona (November 2023), canonical Water Ungaw + 33 organizations + 5-country victimology
reportAhnLab ASEC (2024): canonical Mimic ransomware adoption continuation evidence
reportArete (February 2023): canonical ManageEngine CVE-2021-40539 + BlackCat-circumstantial linkage
reportSentinelOne: Trigona, In-Depth Analysis, Detection, and Mitigation
reportBleeping Computer (October 18, 2023): Ukrainian activists hack Trigona ransomware gang wipe servers
reportThe Record / Recorded Future News: Pro-Ukraine group took down Trigona ransomware website
reportBank Info Security / Mihir Bagwe: Ukrainian Hacktivists Claim Trigona Ransomware Takedown
reportAnvilogic: Trigona Ransomware Site Down
reportGridInSoft: Trigona Ransomware Hacked by Ukrainian Cyber Alliance
reportPalo Alto Networks: December 2022 15 potential victims observation
reportNordVPN: Trigona threat description

Operational

State sponsor

Independent Ransomware-as-a-Service (RaaS) operation believed offspring of CryLock ransomware family per Trend Micro analysis. Possible circumstantial ALPHV/ BlackCat connection per Arete February 2023 report; Trend Micro assessment that BlackCat similarities are "circumstantial at best." Russian-aligned cybercrime ecosystem attribution via RAMP (Russian Anonymous Marketplace) forum network-access-broker collaboration consistent with broader Russian cybercrime ecosystem operational signature. Operations terminated October 17 2023 via Ukrainian Cyber Alliance takedown though AhnLab ASEC 2024 evidence suggests operator continuity via Mimic ransomware adoption based on shared email signatures.

Attribution chain: (1) Trend Micro canonical Water Ungaw + Trigona tracking + CryLock-offspring assessment: per Trend Micro: "The Trigona ransomware, first tracked by Trend Micro as Water Ungaw, emerged in October 2022. However, binaries of the ransomware were first seen as early as June of the same year... Threat actors behind the group are known to be affiliated with CryLock due to their similarities in tactics, techniques, and procedures (TTPs), ransom note file name, and email addresses used." (2) AhnLab ASEC canonical April 2023 + 2024 Mimic-adoption-evidence: per ASEC: "Trigona ransomware is developed in Delphi and uses RSA and AES encryption algorithms when encrypting files.

A report by Arete in February 2023 confirmed a case of Trigona attacking the ManageEngine vulnerability (CVE-2021-40539)... it is presumed that the Trigona ransomware threat actor is also using Mimic in their attacks based on multiple circumstances." (3) Trend Micro canonical victimology April- October 2023: per Trend Micro: "Turkey and the Philippines topped the Trigona attack detections at 23.5% and 19.6%, respectively, while Brazil followed closely at 13.7%. Germany and Thailand rounded up the top five countries targeted by Trigona during its time of activity... threat actors behind Trigona targeted government organizations the most, with attack attempts making up 21.4% of total detections... Trigona ransomware compromised a total of 33 organizations within the aforementioned period." (4) Ukrainian Cyber Alliance / herm1t canonical October 17 2023 takedown disclosure: per Bleeping Computer + The Record + Bank Info Security: "Ukrainian Cyber Alliance hackers gained access to Trigona ransomware's infrastructure by using a public exploit for CVE-2023-22515, a critical vulnerability in Confluence Data Center and Server." Per herm1t: "Despite the efforts of their admins who changed passwords and shut down their infra facing the internet (not TOR) we were able to maintain persistent access to infra, exfiltrated all the data and wiped the servers.

It included administration panel, landing page for victims, blog, leaks site, monero hot wallets, dev environment and internal team server (with Rocket Chat, Confluence and Jira)." (5) Arete February 2023 canonical ManageEngine CVE-2021-40539 + BlackCat-circumstantial linkage: per Bank Info Security: "Cybersecurity firm Arete in February said Trigona had exploited ManageEngine vulnerability CVE-2021-40539 for initial access. An Arete report found evidence linking Trigona with BlackCat, also known as Alphv.

" Operational target profile
  • Turkey + Philippines + Brazil + Germany + Thailand primary geographic per Trend Micro.
  • United States + India + Israel + Italy secondary per The Record.
  • Government organizations 21.4% primary sector.
  • Manufacturing + finance + construction + agriculture + marketing + high-tech + healthcare + tech + banking secondary.
  • 33 organizations compromised April-October 2023 per Trend Micro.
  • Poorly-managed externally-exposed MS-SQL servers signature initial access The cluster fills the October-2022-emergence + June-2022-early-samples + Water-Ungaw-tracking + Delphi-language + CryLock-offspring + MSSQL-brute- force + ManageEngine-CVE-2021-40539 + Mimic-adoption- post-UCA + AES-256-RSA-4112-OFB + .locked + Monero- aggressive-deadline + UCA-October-17-2023-Confluence- CVE-2023-22515-takedown + 33-organizations + Turkey- Philippines-Brazil + RAMP-network-access-broker position in 2022-2025 post-takedown + emerging RaaS cell.
Motivations
financially_motivated_ransomware_as_a_service_double_extortion, crylock_ransomware_offspring_lineage_signature, mssql_server_brute_force_initial_access_signature, manageengine_cve_2021_40539_exploitation_signature, mimic_ransomware_adoption_post_uca_continuation_signature, aggressive_deadline_intimidation_monero_signature_tradecraft, 20_50_percent_affiliate_revenue_raas_model_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MANAGEENGINE CVE-2021-40539 SERVICEDESK PLUS + ADSELFSERVICE PLUS EXPLOITATIONMIMIC RANSOMWARE EVERYTHING SEARCH TOOL EXPLOITATION ACCELERATIONMIMIC RANSOMWAREMONERO CRYPTOCURRENCY PAYMENT PREFERENCEMSSQL SERVER BRUTE FORCE / DICTIONARY ATTACK INITIAL ACCESSSMB SPREADING CAPABILITY TOGGLEABLE

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin