G1032: INC Ransom
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]
Security context for executives and security teams
INC Ransom is an ATT&CK group entry for a ransomware and data extortion threat group associated with INC Ransomware, with reported targeting across industrial, healthcare, and education organizations in the US and Europe. For leaders, the practical issue is not a single malware signature; it is a ransomware playbook that can combine credential abuse, remote access, Active Directory discovery, lateral movement, data staging/exfiltration tooling, and eventual ransomware deployment.
Executive priority
Prioritize this as a business-continuity and incident-readiness scenario, especially where industrial operations, healthcare delivery, or education services depend on Windows identity, remote administration, and shared file infrastructure. Executives should ask whether the organization can prove control over exposed applications, RDP and remote access paths, privileged/domain accounts, data exfiltration routes, and recovery capability before encryption or extortion becomes the decision point.
Technical view
ATT&CK provides no official detection text for this group, so defenders should validate coverage from the related behaviors and software. The relationship set points to Windows-heavy activity such as PsExec, Net, Nltest, AdFind, esentutl, WMI, Windows command shell, RDP, domain and share discovery, valid accounts, file deletion, remote access tools, Rclone, Tor, data staging, ingress tool transfer, and INC Ransomware. SOC and IR teams should test whether they can reconstruct the chain across identity, endpoint, network, web-facing application, and data movement evidence rather than relying on one malware alert.
Likely telemetry
- Authentication and identity logs for valid-account use, privileged logons, remote access, and RDP activity
- Endpoint process creation and command-line telemetry for cmd.exe, WMI, PsExec, Net, Nltest, AdFind, esentutl, Rclone, and remote access tools
- Active Directory and domain controller logs showing account, group, trust, and domain enumeration
- Windows service creation, administrative share, SMB, and lateral movement evidence
- Web server, application, VPN, and edge-device logs for public-facing application exploitation or exposed access paths
Detection direction
- Build detections around behavior clusters: remote access or valid-account use followed by domain discovery, share discovery, lateral execution, staging, and large outbound transfer.
- Treat PsExec, Net, Nltest, AdFind, WMI, RDP, esentutl, Rclone, and remote access tools as dual-use: tune with administrator baselines, approved hosts, change windows, and ticket context to reduce false positives.
- Correlate identity events with endpoint command lines; many high-value signals come from legitimate accounts using legitimate tools in unusual sequences.
- Validate monitoring of public-facing applications and remote access services, since relationships include Exploit Public-Facing Application, Valid Accounts, and RDP.
- Look for data-theft precursors before encryption: staged archives or directories, Rclone execution or configuration artifacts, unusual cloud-storage synchronization, Tor use, and abnormal egress volumes.
Mitigation priorities
- First reduce initial access exposure: inventory Internet-facing applications and remote access services, remediate known weaknesses and misconfigurations, and restrict unnecessary exposure.
- Strengthen identity controls for valid-account abuse: enforce MFA where applicable, remove stale accounts, limit privileged access, monitor domain admin activity, and constrain RDP use.
- Harden lateral movement paths by limiting administrative shares and remote execution methods to approved administrators and managed systems.
- Control dual-use tooling by defining approved use of PsExec, Rclone, remote access tools, and administrative discovery utilities, then alerting on exceptions.
- Improve egress governance for cloud storage, Tor-related traffic, and unusual application-layer outbound connections.
Additional notes and limits
The strongest decision value in this object comes from the relationships rather than the group-level fields. The ATT&CK entry ties INC Ransom to INC Ransomware and to behaviors spanning initial access, discovery, lateral movement, command and control, collection, exfiltration preparation, and stealth. The sector references make operational resilience particularly relevant for industrial, healthcare, and education environments, but local exposure must be determined from the organization’s own assets and telemetry.
ATT&CK does not provide official detection guidance, tactics, or platforms on the group object itself. Platform observations here are inferred only from the related ATT&CK software and technique relationships. This summary does not establish current targeting of any specific organization, confirmed exploitation in a local environment, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
INC Ransom
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1486 | Data Encrypted for Impact | INC Ransom has used INC Ransomware to encrypt victim's data.[4][6][1][3][2][5] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | INC Ransom has used RDP to move laterally.[2][6][5][7] |
| Enterprise | T1657 | Financial Theft | |
| Enterprise | T1047 | Windows Management Instrumentation | INC Ransom has used WMIC to deploy ransomware.[2][6][5] |
| Enterprise | T1566 | Phishing | INC Ransom has used phishing to gain initial access.[5][4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | INC Ransom has used `cmd.exe` to launch malicious payloads.[6] |
| Enterprise | T1537 | Transfer Data to Cloud Account | INC Ransom has used Megasync to exfiltrate data to the cloud.[3] |
| Enterprise | T1087.002 | Domain AccountSub-technique | INC Ransom has scanned for domain admin accounts in compromised environments.[5] |
| Enterprise | T1074 | Data Staged | INC Ransom has staged data on compromised hosts prior to exfiltration.[6][5] |
| Enterprise | T1071 | Application Layer Protocol | INC Ransom has used valid accounts over RDP to connect to targeted systems.[6] |
| Enterprise | T1046 | Network Service Discovery | INC Ransom has used NETSCAN.EXE for internal reconnaissance.[5][4] |
| Enterprise | T1569.002 | Service ExecutionSub-technique | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.[6] |
| Enterprise | T1219 | Remote Access Tools | INC Ransom has used AnyDesk and PuTTY on compromised systems.[6][5][7][4] |
| Enterprise | T1685 | Disable or Modify Tools | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.[7] |
| Enterprise | T1588.002 | ToolSub-technique | |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.[6][5] |
| Enterprise | T1570 | Lateral Tool Transfer | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.[6][3] |
| Enterprise | T1069.002 | Domain GroupsSub-technique | INC Ransom has enumerated domain groups on targeted hosts.[6] |
| Enterprise | T1135 | Network Share Discovery | INC Ransom has used Internet Explorer to view folders on other systems.[6] |
| Enterprise | T1190 | Exploit Public-Facing Application | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.[5][4] |
| Enterprise | T1070.004 | File DeletionSub-technique | INC Ransom has uninstalled tools from compromised endpoints after use.[7] |
| Enterprise | T1078 | Valid Accounts | INC Ransom has used compromised valid accounts for access to victim environments.[2][6][5][7] |
| Enterprise | T1105 | Ingress Tool Transfer | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. [6][7] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.[6][3][5][7] |
| Enterprise | T1049 | System Network Connections Discovery | INC Ransom has used RDP to test network connections.[5] |
Groups, software, and campaigns
S0183: Tor
Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination. [1]
S0029: PsExec
S0359: Nltest
S1040: Rclone
S0552: AdFind
S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
S0404: esentutl
S1139: INC Ransomware
INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors worldwide. INC Ransomware can employ partial encryption combined with multi-threading to speed encryption.[1][2][3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(1)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.1 | 1.0 | Current bundle | e00644371f45… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [2]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [3]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [4]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [5]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [6]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [7]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [8]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [9]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [10]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [11]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [12]GOLD IONIC
(Citation: Secureworks GOLD IONIC April 2024)
- [13]GOLD IONIC
(Citation: Secureworks GOLD IONIC April 2024)
- [14]GOLD IONIC
(Citation: Secureworks GOLD IONIC April 2024)
- [15]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [16]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [17]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [18]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [19]mitre-attackG1032Open source URL
- [20]mitre-attackG1032Open source URL
- [21]mitre-attackG1032Open source URL
- [22]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [23]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [24]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [25]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [26]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [27]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [28]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [29]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [30]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [31]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [32]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [33]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [34]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [35]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [36]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [37]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [38]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [39]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [40]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [41]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [42]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [43]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [44]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [45]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [46]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [47]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [48]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [49]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [50]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [51]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [52]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [53]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [54]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [55]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [56]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [57]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [58]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [59]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [60]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [61]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [62]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [63]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [64]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [65]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [66]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [67]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [68]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [69]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [70]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [71]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [72]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [73]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [74]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [75]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [76]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [77]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [78]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [79]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [80]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [81]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [82]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [83]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [84]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [85]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [86]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [87]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [88]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [89]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [90]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [91]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [92]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [93]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [94]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [95]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [96]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [97]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [98]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [99]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [100]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [101]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [102]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [103]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [104]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [105]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [106]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [107]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [108]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [109]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [110]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [111]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [112]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [113]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [114]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [115]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [116]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [117]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [118]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [119]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [120]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [121]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [122]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [123]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [124]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [125]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [126]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [127]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [128]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [129]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [130]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [131]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [132]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [133]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [134]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [135]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [136]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [137]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [138]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [139]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [140]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [141]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [142]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [143]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [144]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [145]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [146]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [147]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [148]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [149]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [150]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [151]Huntress INC Ransom Group August 2023
Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Open source URL - [152]Huntress INC Ransomware May 2024
Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Open source URL - [153]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL - [154]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [155]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [156]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [157]SOCRadar INC Ransom January 2024
SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
