SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1046 Network Service Discovery |
GroupINC Ransom | INC Ransom has used NETSCAN.EXE for internal reconnaissance. |
| T1083 File and Directory Discovery |
MalwareINC Ransomware | INC Ransomware can receive command line arguments to encrypt specific files and directories. |
| T1190 Exploit Public-Facing Application |
GroupINC Ransom | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1566 Phishing |
GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| T1566 Phishing |
MalwareINC Ransomware | INC Ransomware campaigns have used spearphishing emails for initial access. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.