Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupINC Ransom | INC Ransom has used RDP to move laterally. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1057 Process Discovery |
MalwareINC Ransomware | INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1083 File and Directory Discovery |
MalwareINC Ransomware | INC Ransomware can receive command line arguments to encrypt specific files and directories. |
| T1106 Native API |
MalwareINC Ransomware | INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots. |
| T1120 Peripheral Device Discovery |
MalwareINC Ransomware | INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes. |
| T1135 Network Share Discovery |
MalwareINC Ransomware | INC Ransomware has the ability to check for shared network drives to encrypt. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareINC Ransomware | INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1489 Service Stop |
MalwareINC Ransomware | INC Ransomware can issue a command to kill a process on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareINC Ransomware | INC Ransomware can delete volume shadow copy backups from victim machines. |
| T1491.001 Internal Defacement |
MalwareINC Ransomware | INC Ransomware has the ability to change the background wallpaper image to display the ransom note. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1652 Device Driver Discovery |
MalwareINC Ransomware | INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
| T1680 Local Storage Discovery |
MalwareINC Ransomware | INC Ransomware can discover and mount hidden drives to encrypt them. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.