Skip to main content
Trigona Ransomware: Rclone-to-MEGA Cloud Exfiltration operation cover
COMING SOONIntermediatePRO

Trigona Ransomware: Rclone-to-MEGA Cloud Exfiltration

A fast, RDP-only, hands-on-keyboard intrusion that went from a valid Administrator logon on an exposed RDP gateway to estate-wide Trigona ransomware in under three hours. The actor dropped a batch-script and Netscan toolkit, enumerated the network and file shares, pivoted over RDP, disabled Windows Defender by hand, exfiltrated file shares to MEGA cloud storage with a renamed rclone client, then staged and ran the Trigona encryptor over SMB. Reconstruct the full kill chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key ATT&CK techniques.

1h
7 tasks
50 points
Pro

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

SIEMFirewallXDR

What you'll investigate

7 objectives unlock when this operation goes live.

1Incident brief
2Trace the initial access
3Name the compromised account
4Classify the discovery tooling's share check
5Isolate the exfiltration destination
6Recover the encryptor indicator
7Classify the defense-evasion step

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.

Get Started Free