Ransomware Group intelligence
Tridentlocker
InactiveTrack Tridentlocker with 16 published victims and 2 known leak locations in a single intelligence view.
Overview
Tridentlocker is tracked by Breach House as a ransomware group with 16 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 2h ago | tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onion |
| Leak location 2 | Web location | Up checked 2h ago | tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onion/articles |
Top Activity Sectors (7)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Tridentlocker, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: tridentlocker executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: tridentlocker persists via Registry Run Keys to automatically launch ransomware components on system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: tridentlocker disables antivirus tools and modifies security software configurations to evade detection during execution.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: tridentlocker encodes ransomware binaries and configuration data to evade static analysis and sandbox detection.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: tridentlocker deletes Volume Shadow Copies and backup directories via command-line utilities to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: tridentlocker scans network shares using native tools to identify victim file structures for encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: tridentlocker moves laterally through SMB/Windows Admin Shares to compromise additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: tridentlocker encrypts victim files using custom symmetric encryption routines to maximize impact and ransom demand leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: tridentlocker halts system recovery processes by terminating critical services and blocking restore mechanisms.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: tridentlocker displays internal defacement messages and ransom notes on victim systems to pressure decryption.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (16)
Search, filter and paginate the victim timeline for Tridentlocker. Showing 1–16 of 16.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | RT Software id28603 View details | United Kingdom | Manufacturing / Engineering | ||
|
[AI generated] RT Software is a UK-based company specializing in real-time graphics and virtual studio technology for the broadcast television industry. Founded in the 1990s, it develops software solutions including tOG (The Output Generator), used for live on-air graphics, augmented reality, and virtual set production. Its clients include major broadcasters and sports networks worldwide. The company operates primarily in the media and entertainment technology sector. |
|||||
| Ransomware | Jameson Pepple Cantu PLLC id27089 View details | United States | Finance / Legal / Insurance | ||
|
[AI generated] Jameson Pepple Cantu PLLC is a boutique law firm located in Houston, Texas. This firm provides a broad range of legal services but specializes in areas related to business such as Corporate Law, Real Estate, Mergers and Acquisitions, and Securities. The team, made up of experienced professionals, prides themselves in their dedicated and personalized approach to each client's legal needs. |
|||||
| Ransomware | TMPartner id26241 View details | Japan | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | Eco Green Group id25463 View details | United Kingdom | Services | ||
|
[AI generated] The Eco Green Group focuses on providing environmentally friendly solutions for waste management. The company specializes in diverting waste from landfills via recycling and energy recovery methods, striving towards a circular economy. With their innovative approaches and technologies, they contribute significantly towards reducing carbon emissions, maintaining a sustainable environment, and fostering green living. Their services include recycling, composting, and waste-to-energy transformations. |
|||||
| Ransomware | Sedgwick Government Solutions id25227 View details | United States | Services | ||
|
[AI generated] Sedgwick Government Solutions is part of Sedgwick, a leading global company specializing in risk and benefits solutions. The company offers expertise in different sectors including, health, property, casualty, disability and productivity. It is recognized for its technology and innovation-driven approach to provide comprehensive risk and benefits solutions. |
|||||
| Ransomware | allenprinting id24910 View details | United States | Communication / Marketing | ||
|
[AI generated] Allen Printing is a Nashville-based company that offers commercial printing and direct mail services. They have been in business for over 80 years, providing a variety of services including digital printing, offset printing, bindery, and graphic design. Their clientele ranges from local businesses to renowned corporations. They pride themselves on their quality, service, and timely delivery. |
|||||
| Ransomware | noment id24385 View details | United States | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | bpost id24335 View details | Belgium | Transportation / Travel / Logistics | ||
|
[AI generated] bpost is a Belgian company that handles the sorting, collection, transportation and delivery of postal services both locally and internationally. Apart from this, they also manage electronic communications, financial transactions, and other related services. bpost operates in the mail sector as well as in the parcel and e-commerce logistics in Europe, North-America and Asia. |
|||||
| Ransomware | GuestTek id24306 View details | Canada | Communication / Marketing | ||
|
[AI generated] GuestTek is a global company that specializes in delivering and managing communications and connectivity services for the hospitality industry. They provide solutions for internet access, entertainment, and fully integrated hospitality systems, enhancing guest experience in properties around the world. The company is a pioneer and leader in providing advanced technologies for the hotel industry such as IP-PBX, Voice, IPTV, and High-Speed Internet Access. |
|||||
| Ransomware | Advantage 360 id24305 View details | United States | Communication / Marketing | ||
|
[AI generated] Advantage 360 is a software company that provides integrated customer relationship management, billing, and automation solutions. Their services are focused primarily towards telecommunications, digital service providers, and broadband providers worldwide. They offer scalable solutions which incorporate billing, customer care, fraud management, and revenue assurance. |
|||||
| Ransomware | iqs id24304 View details | Iraq | Other | ||
|
[AI generated] N/A |
|||||
| Ransomware | LMG Holdings id24303 View details | United States | Communication / Marketing | ||
|
[AI generated] LMG Holdings, Inc. is a leading provider of ignition interlock devices. Based in Raleigh, North Carolina, the company’s main mission is to provide products that continuously monitor breath alcohol and prevent operation of the vehicle when the driver’s levels are above specified limits. They aim to make the roads safer by preventing drunk driving. |
|||||
| Ransomware | EnQuest id24302 View details | United Kingdom | IT | ||
|
[AI generated] EnQuest is a leading independent oil and gas production and development company with operations concentrated in the UK North Sea. The company specializes in extending the life and extracting maximum value from maturing and underdeveloped oil and gas fields. It’s recognized for applying advanced technology and innovative techniques to enhance performance and increase value throughout its assets. |
|||||
| Ransomware | Calmec id24301 View details | Canada | Manufacturing / Engineering | ||
|
[AI generated] Calmec Precision Limited is a Canada-based company. It specializes in designing and manufacturing machinery used for cable and conductor production. They offer an extensive product line that includes armouring and stranding machines, technical consultancy, equipment installation, and after-sales service. |
|||||
| Ransomware | typecaseinc id24300 View details | United States | Services | ||
|
[AI generated] N/A |
|||||
| Ransomware | asiawba id24299 View details | Korea, Republic of | Other | ||
|
[AI generated] N/A |
|||||