Ransomware Group intelligence
Trinity
InactiveTrack Trinity with 18 published victims and 1 known leak locations in a single intelligence view.
Overview
Trinity is tracked by Breach House as a ransomware group with 18 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | txtggyng5euqkyzl2knbejwpm4rlq575jn2egqldu27osbqytrj6ruyd.onion |
Top Activity Sectors (10)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Trinity, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: trinity executes malicious commands via PowerShell scripts to stage payloads and evade detection.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: trinity leverages registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: trinity disables antivirus tools and security software to prevent system recovery and hinder investigations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: trinity inserts junk code into legitimate binaries to evade static analysis and detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: trinity deletes Volume Shadow Copies and backup directories via command-line utilities to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: trinity discovers remote systems across the network to propagate ransomware across victim infrastructure.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: trinity scans network shares using native tools to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1560.001 Archive via Utility Collection
What they do: trinity archives stolen data using utility tools prior to exfiltration for extortion demands.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: trinity encrypts victim files and data using custom ransomware binaries to maximize impact.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: trinity displays internal defacement messages on victim systems to pressure organizations into paying ransoms.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README.txt
TRINITY LOCKER We downloaded to our servers and encrypted all your databases and personal information! to contact us download TOR https://www.torproject.org/download/ follow this link http://txtggyng5euqkyzl2knbejwpm4rlq575jn2egqldu27osbqytrj6ruyd.onion follow the instructions on the website or e-mail: [email protected] IMPORTANT INFORMATION! If you do not write to us within 24 hours, we will start publishing and selling your data on the darknet on hacker sites and offer the information to your competitors. Guarantee:If we don't provide you with a decryptor or delete your data after you pay,no one will pay us in the future. We value our reputation. Guarantee key:To prove that the decryption key exists, we can test the file (not the database and backup) for free. Do not try to decrypt your data using third party software, it may cause permanent data loss. Don't go to recovery companies - they are essentially just middlemen.Decryption of your files with the help of third parties may cause increased price (they add their fee to our) we're the only ones who have the decryption keys.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (18)
Search, filter and paginate the victim timeline for Trinity. Showing 1–18 of 18.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Kairav Chemofarbe Industries id18453 View details | India | Healthcare / Pharma | ||
|
[AI generated] Kairav Chemofarbe Industries Ltd is a pharmaceutical company based in Mumbai, India. Founded in 1983, the company specializes in the manufacture of chemical products targeting the pharmaceutical and chemical industries. Some of their products include both intermediates and APIs. The company is known for its research and development abilities which have led to the creation of competitive products in the global market. |
|||||
| Ransomware | consultoria-consultores.es id18452 View details | Spain | Other | ||
|
219GB |
|||||
| Ransomware | ROBONG-WINMINI id18451 View details | Other | |||
|
[AI generated] N/A |
|||||
| Ransomware | Lake Psychological Services id18450 View details | United States | Services | ||
|
190Gb |
|||||
| Ransomware | CANAM Realty Group id18449 View details | United States | Construction / Real Estate | ||
|
[AI generated] CANAM Realty Group is a full-service real estate company based in Arizona, United States. They provide numerous services, such as property management, investment consulting, residential leasing, and home sales. The company has a team of dedicated real estate professionals skilled in different aspects of the industry. They focus on serving their clients' needs whether they are homeowners, renters, or investors, offering precise, professional, and personal service. |
|||||
| Ransomware | CNS id18448 View details | China | Other | ||
|
[redacted] |
|||||
| Ransomware | la-z-boy id18447 View details | United States | Communication / Marketing | ||
|
[AI generated] La-Z-Boy is a renowned furniture company based in the USA, most known for their iconic recliners. Founded in 1927, they offer a wide range of home furniture including sofas, chairs, lift chairs, loveseats, and sleepers. Additionally, they provide home accessories such as rugs, lamps, and tables. They focus on creating comfortable, long-lasting furnishings while offering personalized custom order options. |
|||||
| Ransomware | Agencia Tributaria AEAT id15783 View details | Spain | Public Sector | ||
|
560Gb - Revenue: 38$mln - Publication date: 2024-12-31 |
|||||
| Ransomware | Barnes & Cohen id14577 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
15Gb - Revenue: <$5 Million - Publication date: 2024-11-04 |
|||||
| Ransomware | FoccoERP id14559 View details | Brazil | Public Sector | ||
|
Data base 300 GB - Revenue: $ 20 Million - Publication date: 2024-11-01 |
|||||
| Ransomware | Fabrica Industrial Machinery & Equipment id14412 View details | Argentina | Manufacturing / Engineering | ||
|
Data base 20+tb - Revenue: $ 59.2 Million - Publication date: 2024-10-23 |
|||||
| Ransomware | INTERNAL.ROCKYMOUNTAINGASTRO.COM id14295 View details | United States | Energy | ||
|
330Gb - Revenue: $60.3 Million - Publication date: 2024-10-16 |
|||||
| Ransomware | welland id14134 View details | Canada | Public Sector | ||
|
full data base - Revenue: <$5 Million - Publication date: 2024-10-01 |
|||||
| Ransomware | Cosmetic Dental Group id13882 View details | Jersey | Healthcare / Pharma | ||
|
3.63 Tb - Revenue: <$5 Million - Publication date: 2024-09-18 |
|||||
| Ransomware | Banner and Associates id13805 View details | United States | Public Sector | ||
|
full data base(1,5 TB) - Revenue: $7.6 Million - Publication date: 2024-09-20 |
|||||
| Ransomware | sgvfr.com id12967 View details | United States | Public Sector | ||
|
sgvfr.com - Revenue: 5kk - Publication date: 2024-06-30 |
|||||
| Ransomware | CBSTRAINING id12966 View details | Canada | Education | ||
|
CBSTRAINING - Publication date: 2024-06-30 |
|||||
| Ransomware | filmetrics corporation id12952 View details | Philippines | Services | ||
|
www.filmetrics.com.ph |
|||||