Active ransomware operator
← All groupsTRIDENT
aka DAGGER PANDA, IceFog, RedFoxtrot, Red Wendigo, PLA Unit 69010, UAT-7290, Red Foxtrot · 0 victims indexed
At a glance
- Status
- active
- Aliases
- DAGGER PANDA, IceFog, RedFoxtrot, Red Wendigo, PLA Unit 69010, UAT-7290, Red Foxtrot
- First seen
- —
- Last activity
- —
- Onion sites
- 1 known endpoint
- Suspected origin
- 🇨🇳CN
Attribution
Community-assessed by the MISP threat-intel community — not Darkfield's own attribution.
- Suspected sponsor
- 🇨🇳China
- Activity type
- Espionage
- Attribution confidence
- Moderate · 50/100
About
References
7 linksExternal sources curated by the MISP threat-intel community.
- securelist.com/the-icefog-apt-a-tale-of-cloak-and-three-daggers/57331/
- securelist.com/the-icefog-apt-hits-us-targets-with-java-backdoor/58209/
- cfr.org/interactive/cyber-operations/icefog
- d2538mqrb7brka.cloudfront.net/wp-content/uploads/sites/43/2018/03/20133739/icefog.pdf
- pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospect/yir-cyber-threats-report-download.pdf
- go.recordedfuture.com/hubfs/reports/cta-2021-0616.pdf
- blog.talosintelligence.com/uat-7290/
Recent victims
Loading…
Onion infrastructure
1 known- http://tridentfrdy6jydwywfx4vx422vnto7pktao2gyx2qdcwjanogq454ad.onion/articles
Source
Updated recentlyData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
Get alerted the next time TRIDENT posts a victim.
Add TRIDENT to your watchlist — Pro pings you within 5 minutes of any new TRIDENT leak-site post, Telegram callout, or affiliate-rebrand inference.
