ATT&CKReferencesCybereason INC Ransomware November 2023

Cybereason INC Ransomware November 2023

Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupINC Ransom

INC Ransom has used RDP to move laterally.

T1047
Windows Management Instrumentation
GroupINC Ransom

INC Ransom has used WMIC to deploy ransomware.

T1057
Process Discovery
MalwareINC Ransomware

INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.

T1078
Valid Accounts
GroupINC Ransom

INC Ransom has used compromised valid accounts for access to victim environments.

T1083
File and Directory Discovery
MalwareINC Ransomware

INC Ransomware can receive command line arguments to encrypt specific files and directories.

T1106
Native API
MalwareINC Ransomware

INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.

T1120
Peripheral Device Discovery
MalwareINC Ransomware

INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.

T1135
Network Share Discovery
MalwareINC Ransomware

INC Ransomware has the ability to check for shared network drives to encrypt.

T1140
Deobfuscate/Decode Files or Information
MalwareINC Ransomware

INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
MalwareINC Ransomware

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1489
Service Stop
MalwareINC Ransomware

INC Ransomware can issue a command to kill a process on compromised hosts.

T1490
Inhibit System Recovery
MalwareINC Ransomware

INC Ransomware can delete volume shadow copy backups from victim machines.

T1491.001
Internal Defacement
MalwareINC Ransomware

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

T1588.002
Tool
GroupINC Ransom

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.

T1652
Device Driver Discovery
MalwareINC Ransomware

INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.

T1657
Financial Theft
GroupINC Ransom

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.

T1680
Local Storage Discovery
MalwareINC Ransomware

INC Ransomware can discover and mount hidden drives to encrypt them.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.