ATT&CKReferencesSentinelOne INC Ransomware

SentinelOne INC Ransomware

SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1046
Network Service Discovery
GroupINC Ransom

INC Ransom has used NETSCAN.EXE for internal reconnaissance.

T1083
File and Directory Discovery
MalwareINC Ransomware

INC Ransomware can receive command line arguments to encrypt specific files and directories.

T1190
Exploit Public-Facing Application
GroupINC Ransom

INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.

T1219
Remote Access Tools
GroupINC Ransom

INC Ransom has used AnyDesk and PuTTY on compromised systems.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
MalwareINC Ransomware

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1566
Phishing
GroupINC Ransom

INC Ransom has used phishing to gain initial access.

T1566
Phishing
MalwareINC Ransomware

INC Ransomware campaigns have used spearphishing emails for initial access.

T1588.002
Tool
GroupINC Ransom

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.

T1657
Financial Theft
GroupINC Ransom

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.