ATT&CKReferencesSecureworks GOLD IONIC April 2024

Secureworks GOLD IONIC April 2024

Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareINC Ransomware

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1491.001
Internal Defacement
MalwareINC Ransomware

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

T1537
Transfer Data to Cloud Account
GroupINC Ransom

INC Ransom has used Megasync to exfiltrate data to the cloud.

T1560.001
Archive via Utility
GroupINC Ransom

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.

T1570
Lateral Tool Transfer
GroupINC Ransom

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.

T1657
Financial Theft
GroupINC Ransom

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.