Malware.View on attack.mitre.org
INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors worldwide. INC Ransomware can employ partial encryption combined with multi-threading to speed encryption.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment. |
| T1057 Process Discovery |
INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt. |
| T1083 File and Directory Discovery |
INC Ransomware can receive command line arguments to encrypt specific files and directories. |
| T1106 Native API |
INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots. |
| T1120 Peripheral Device Discovery |
INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes. |
| T1135 Network Share Discovery |
INC Ransomware has the ability to check for shared network drives to encrypt. |
| T1140 Deobfuscate/Decode Files or Information |
INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note. |
| T1486 Data Encrypted for Impact |
INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1489 Service Stop |
INC Ransomware can issue a command to kill a process on compromised hosts. |
| T1490 Inhibit System Recovery |
INC Ransomware can delete volume shadow copy backups from victim machines. |
| T1491.001 Internal Defacement |
INC Ransomware has the ability to change the background wallpaper image to display the ransom note. |
| T1566 Phishing |
INC Ransomware campaigns have used spearphishing emails for initial access. |
| T1570 Lateral Tool Transfer |
INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure. |
| T1652 Device Driver Discovery |
INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer. |
| T1680 Local Storage Discovery |
INC Ransomware can discover and mount hidden drives to encrypt them. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.