◇ SIGN IN
← all actors
ransomware

Trigona

defunctmedium confidence
Ransomware
Trigona Ransomware
Attribution
Financially motivated (unattributed; links to CryLock/ALPHV-affiliated activity reported)
Origin
Unknown
First seen
2022
Last active
2023
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
Oman
Sectors
Luxury goods/perfumery

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting Oman (Luxury goods/perfumery sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

Trigona was a ransomware operation active from late 2022 until October 2023, when the pro-Ukraine Ukrainian Cyber Alliance breached its infrastructure via a Confluence exploit and wiped its servers; the group has remained dormant/defunct since.

History

Trigona emerged in late 2022 as a double-extortion ransomware operation, encrypting victims and threatening to publish stolen data via a Tor leak site. Researchers documented reasonably capable tooling and some reporting associated its activity with prior CryLock ransomware and access-broker ecosystems.

In October 2023 the Ukrainian Cyber Alliance (UCA), a pro-Ukraine hacktivist group, announced it had compromised Trigona's environment by exploiting CVE-2023-22515 in Atlassian Confluence Data Center and Server. On 17 October 2023 the UCA reported exfiltrating data and then wiping Trigona's infrastructure, including its administrative panel, blog, internal and developer servers, and cryptocurrency wallets.

Trigona has remained dormant with no credible resurgence since the 2023 takedown and is generally assessed defunct as of 2025, though its codebase influenced later families (see BlackNevas, a Trigona-family variant). Its MENA-relevant claim includes Oman. Any pre-takedown victim listings are extortion claims and should be treated as unverified unless confirmed by a reputable source.

Notable campaigns

2023
Ukrainian Cyber Alliance takedown
UCA exploited Confluence CVE-2023-22515 to breach and wipe Trigona's servers in October 2023, ending operations.

Claimed victims · 49 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

DateVictimCountrySector
ClaroMXProfessional Services
South Star ElectronicsCNTechnology
IndoarsipIDProfessional Services
BwizerPTHealthcare
Topa PartnersNZProfessional Services
Dinamic OilITManufacturing
Hotel Avenida, Hostal Espoz y Mina, Hostal Arriazu, Pension AlemanaESHospitality
ATMCoUSTechnology
FALCO ElectronicsMXTechnology
CMG Drainage EngineeringUSProfessional Services
Daher ContractingUSProfessional Services
Genesis MotorsAUManufacturing