Cyber Threat Report: 'Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours'

Report Author DFIR Report
Publication Date 2024-01-29
Original Reporting Source
Related Intrusion Sets Trigona Ransomware Group

This report by the DFIR Report outlines a Trigona Ransomware attack. It describes how the actors went from initial access (by exposed RDP) to data exfiltration and deployment of Trigona ransomware in 3 hours. The threat actor used SoftPerfect's Netscan for network discovery activities.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques