INC Ransom
[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Properties
- stix_id
- intrusion-set--cb41e991-65f4-4668-a65f-f4200545b5a1
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (26)
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, enc
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detectio
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in fol
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries dete
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own fina
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., [Ingress T
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is don
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vul
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Col
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishi
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools crea
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a computer using the Remote Desktop Protocol (RDP). The ad
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>servic
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another clo
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the prima
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the
Software & Tools (8)
[AdFind](https://attack.mitre.org/software/S0552) is a free command-line query tool that can be used for gathering information from Active Directory.(
[INC Ransomware](https://attack.mitre.org/software/S1139) is a ransomware strain that has been used by the [INC Ransom](https://attack.mitre.org/group
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for c
[Nltest](https://attack.mitre.org/software/S0359) is a Windows command-line utility used to list domain controllers and enumerate domain trusts.(Citat
[PsExec](https://attack.mitre.org/software/S0029) is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT
[Rclone](https://attack.mitre.org/software/S1040) is a command line program for syncing files with cloud storage services such as Dropbox, Google Driv
[Tor](https://attack.mitre.org/software/S0183) is a software suite and network that provides increased anonymity on the Internet. It creates a multi-h
[esentutl](https://attack.mitre.org/software/S0404) is a command-line tool that provides database utilities for the Windows Extensible Storage Engine.
Explore this actor's full graph with Ninja Signal