DisclosureLens
← All groups

trinity

Active since 2024-06-06
18 claimed victims

Unverified threat-actor claim — not a regulatory filing

Attribution, victim identity, and counts shown here derive from trinity's public extortion-blog claims, aggregated by ransomware.live. They have not been validated by the victim or any regulator. Treat them as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

According to ransomware.live, the group claims:

Trinity ransomware was first discovered in May 2024, believed to be a rebrand of the Venus/2023Lock variants, using ChaCha20 encryption and double-extortion via a Tor leak site; the US HHS flagged it as a specific threat to the healthcare sector after confirmed attacks on healthcare organizations.

Source: Ransomware.live

Trinity ransomware group · DisclosureLens