// THREAT ACTOR
TRISEC_
DormantTRISEC is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of TRISEC — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2024 3
Leak site mirrors
6 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
orfc3joknhrzscdbuxajypgrvlcawtuagbj7f44ugbosuvavg3dc3zid.onion404 Not Found snapshot · 2024-04-11 16:02 -
orfc3joknhrzscdbuxajypgrvlcawtuagbj7f44ugbosuvavg3dc3zid.onionIndex of / snapshot · 2024-04-11 16:02 -
pkk4gbz7lsbgeja6s6iwsan2ce364sqioici65swwt65uhicke65uyid.onionIndex of / snapshot · 2024-04-11 16:02 -
5qmw6mv5ucbeskd3rv6vgn5dqgsuectmtqvz4paukmvhtlazzkuxuwqd.onionIndex of / snapshot · 2024-04-11 16:02 -
5qmw6mv5ucbeskd3rv6vgn5dqgsuectmtqvz4paukmvhtlazzkuxuwqd.onion404 Not Found snapshot · 2024-04-11 16:02 -
pkk4gbz7lsbgeja6s6iwsan2ce364sqioici65swwt65uhicke65uyid.onion404 Not Found snapshot · 2024-04-11 16:02
Recent victims
The 50 most recent victims claimed by TRISEC. Total in the index: 3.
| Date listed | Victim | Description |
|---|---|---|
| 2024-02-19 | aivi.it | |
| 2024-02-19 | ki.se | |
| 2024-02-19 | www.cogans.ie |