ATT&CKGroupsINC Ransom

INC Ransom

G1032

Threat group.View on attack.mitre.org

About this group

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

INC Ransom has used RDP to move laterally.

T1036.005
Match Legitimate Resource Name or Location

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.

T1046
Network Service Discovery

INC Ransom has used NETSCAN.EXE for internal reconnaissance.

T1047
Windows Management Instrumentation

INC Ransom has used WMIC to deploy ransomware.

T1049
System Network Connections Discovery

INC Ransom has used RDP to test network connections.

T1059.003
Windows Command Shell

INC Ransom has used `cmd.exe` to launch malicious payloads.

T1069.002
Domain Groups

INC Ransom has enumerated domain groups on targeted hosts.

T1070.004
File Deletion

INC Ransom has uninstalled tools from compromised endpoints after use.

T1071
Application Layer Protocol

INC Ransom has used valid accounts over RDP to connect to targeted systems.

T1074
Data Staged

INC Ransom has staged data on compromised hosts prior to exfiltration.

T1078
Valid Accounts

INC Ransom has used compromised valid accounts for access to victim environments.

T1087.002
Domain Account

INC Ransom has scanned for domain admin accounts in compromised environments.

T1105
Ingress Tool Transfer

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.

T1135
Network Share Discovery

INC Ransom has used Internet Explorer to view folders on other systems.

T1190
Exploit Public-Facing Application

INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.

View all 25 procedure examples

Software8

Campaigns0

None recorded.

References4

  1. Bleeping Computer INC Ransomware March 2024 Open source
    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
  2. Cybereason INC Ransomware November 2023 Open source
    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
  3. Secureworks GOLD IONIC April 2024 Open source
    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
  4. SentinelOne INC Ransomware Open source
    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.