Trigona Ransomware Group Deploys Custom Exfiltration Tool to Steal Data and Evade Detection

The Trigona ransomware group has added a new weapon to its offensive arsenal: a bespoke data exfiltration tool engineered for speed and stealth. The latest activity, observed in March 2026, confirms that this criminal collective — despite having taken significant blows in the past — has never stopped evolving.

Who Is Trigona?

Trigona is a ransomware-as-a-service (RaaS) operation that surfaced in October 2022. Like many of its peers in the organized cybercrime ecosystem, it runs a double-extortion model: encrypting victims’ data while threatening to publish it unless a ransom is paid — exclusively in Monero, chosen for its robust anonymity features.

In October 2023, Ukrainian hacktivists dealt a serious blow to the group’s infrastructure, breaching its servers and making off with both source code and operational databases. It was a significant setback — but not a fatal one. Trigona regrouped, updated its tools and tactics, and resumed operations.

The New Tool: uploader_client.exe

At the heart of Trigona’s latest campaigns is a custom command-line utility called uploader_client.exe, purpose-built to maximize exfiltration efficiency while minimizing forensic traces on compromised systems.

The tool’s technical characteristics are particularly noteworthy:

  • Five simultaneous connections per file, dramatically accelerating data transfer speeds;
  • TCP rotation after every 2 GB transmitted, a technique that makes malicious traffic harder to fingerprint and flag by network monitoring systems;
  • Selective file exfiltration, allowing operators to cherry-pick exactly which data to steal, reducing operational noise;
  • Authentication key enforcement, ensuring the tool can only be used by authorized actors within the affiliate chain.

This bespoke approach reflects a broader trend across the ransomware landscape: the gradual replacement of well-known public tools — such as Rclone — with proprietary alternatives that are far harder for traditional security solutions to detect and classify.

A Broader Toolkit

uploader_client.exe doesn’t operate in isolation. Researchers found it deployed alongside several other tools, each playing a distinct role in the attack chain:

  • AnyDesk: used to establish persistent remote access to compromised systems;
  • Mimikatz: deployed for credential harvesting and privilege escalation;
  • HRSword: leveraged to disable endpoint security solutions.

Together, these tools allow Trigona affiliates to move laterally through a network, harvest credentials, neutralize defenses, and then carry out coordinated exfiltration and encryption operations.

Defensive Implications

In light of these tactical upgrades, organizations need to sharpen their detection and response strategies. Key priorities include:

Block known IoCs: Both uploader_client.exe and HRSword are already featured in indicators-of-compromise lists published by Symantec and other vendors.

Behavioral endpoint monitoring: EDR solutions capable of withstanding driver-based termination attempts — a technique frequently exploited via tools like PCHunter or Gmer — are essential for catching suspicious activity even when specific signatures are absent.

Network segmentation and privilege controls: Limiting lateral movement remains one of the most effective countermeasures against RaaS actors.

Multi-factor authentication and least-privilege principles: Foundational measures for combating credential theft and abuse.

Proactive threat hunting: Monitoring for patterns of parallel TCP connections and anomalous traffic rotation can help identify active exfiltration before the damage becomes irreversible.

Trigona is a reminder that ransomware groups should never be underestimated. Even after direct strikes against their infrastructure, these criminal outfits have demonstrated a consistent ability to regroup and refine their capabilities. The defensive response must be equally dynamic.


L’evoluzione di gruppi come Trigona, capaci di rinnovarsi rapidamente dopo gravi colpi alla propria infrastruttura, sottolinea quanto sia critico per le organizzazioni condividere tempestivamente informazioni sulle minacce. Piattaforme come IsacChain rispondono a questa esigenza abilitando la condivisione sicura di threat intelligence tra organizzazioni, con tracciabilità e integrità garantite dalla verifica blockchain. Al tempo stesso, la compliance NIS2 automatizzata integrata nella piattaforma consente di allineare le misure difensive ai requisiti normativi senza oneri aggiuntivi, trasformando la condivisione delle informazioni in un vantaggio strategico concreto. Scopri come IsacChain può aiutare la tua organizzazione su www.isacchain.com