Ransomware Intelligence

Ransomware needs a way in. Stolen credentials are the cheapest one.

Check Your Exposure

tridentlocker Ransomware Group

Ransomware group profile

17Victims
RussiaSource country
63Impact score

Description

TridentLocker is a ransomware-as-a-service (RaaS) operation that emerged in late 2025, utilizing double-extortion tactics to pressurize victims for financial gain. The group encrypts systems while threatening to release stolen data, demonstrating sophisticated operational security and a rapid pace of attacks across various sectors.

Key insights

  • Employs double-extortion tactics by encrypting systems and threatening to leak stolen data.
  • Gains initial access through credential abuse and privilege escalation techniques.
  • Targets a diverse range of sectors, indicating a broad operational focus.
  • Utilizes proprietary ransomware while engaging in data exfiltration prior to encryption.
  • Demonstrates high operational security, allowing prolonged undetected presence within networks.

Threat Level & Status Breakdown

For tridentlocker · Based on incidents in selected period

1.8threat level
Aggressiveness5.3/ 10
Lethality0/ 10
Criticality0/ 10

Status Breakdown

Claimed100.0%17
First seenOct 2025
Last seenSep 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedSep 7, 2026

Recent activity

Monthly attack count for tridentlocker in the selected period

17Total attacks
8peak in Nov
2.1avg / month
↓ 1 vs first month
OctNovDecJanFebMarAprSep02468

Intelligence

IOCs, YARA/Sigma rules, and related families for tridentlocker

  1. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
  2. 7eec7d07587112777016e5742c0d002d7e64a3e1fe7bde82fed8f65e3663456a
  3. e1c371c7c39c16d208bcbaa5b5d0714df696e6ef68b95a880673a904527c8b96
  4. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  5. e06520c65bf27d9110d68ecc0de0e0824c3a99be080ead1a5b5be8fd2a26d12d
  6. eae09889399fe4fb8e78b114dba0527de913d12fb1802944a88ed136e3e90577
View full IOC feed33 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for tridentlocker

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1046

T1046

T1562

T1562

T1021

T1021

T1033

T1033

T1021.001

T1021.001

T1020

T1020

T1059

T1059

T1005

T1005

Victims(17)

United StatesManufacturingsoutherncarlson.com
Claimed
4 days ago
United KingdomTechnology
Claimed
4 months ago
United StatesProfessional Servicesjpclaw.com
Claimed
6 months ago
JapanProfessional Servicestm-partner.ch
Claimed
7 months ago
United KingdomEnergy & Utilitiesecogreengroup.co.uk
Claimed
8 months ago
United StatesGovernment & Defensesedgwickgovernment.com
Claimed
8 months ago
United StatesProfessional Servicesallenprinting.com
Claimed
9 months ago
United StatesTechnologyadvantage360.com
Claimed
9 months ago
CanadaTechnologyguesttek.com
Claimed
9 months ago
IraqManufacturing
Claimed
9 months ago
United StatesTechnologynoment.com
Claimed
9 months ago
United StatesManufacturinglmgholdings.com
Claimed
9 months ago
BelgiumTechnologybpost.be
Claimed
9 months ago
United StatesTechnologytypecaseinc.com
Claimed
9 months ago
South KoreaFinancial Servicesasiawba.com
Claimed
9 months ago
CanadaManufacturingcalmec.com
Claimed
9 months ago
United KingdomEnergy & Utilitiesenquest.com
Claimed
9 months ago