LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1032: INC Ransom

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]

EnterpriseG1032GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

INC Ransom is an ATT&CK group entry for a ransomware and data extortion threat group associated with INC Ransomware, with reported targeting across industrial, healthcare, and education organizations in the US and Europe. For leaders, the practical issue is not a single malware signature; it is a ransomware playbook that can combine credential abuse, remote access, Active Directory discovery, lateral movement, data staging/exfiltration tooling, and eventual ransomware deployment.

Executive priority

Prioritize this as a business-continuity and incident-readiness scenario, especially where industrial operations, healthcare delivery, or education services depend on Windows identity, remote administration, and shared file infrastructure. Executives should ask whether the organization can prove control over exposed applications, RDP and remote access paths, privileged/domain accounts, data exfiltration routes, and recovery capability before encryption or extortion becomes the decision point.

Technical view

ATT&CK provides no official detection text for this group, so defenders should validate coverage from the related behaviors and software. The relationship set points to Windows-heavy activity such as PsExec, Net, Nltest, AdFind, esentutl, WMI, Windows command shell, RDP, domain and share discovery, valid accounts, file deletion, remote access tools, Rclone, Tor, data staging, ingress tool transfer, and INC Ransomware. SOC and IR teams should test whether they can reconstruct the chain across identity, endpoint, network, web-facing application, and data movement evidence rather than relying on one malware alert.

Likely telemetry

  • Authentication and identity logs for valid-account use, privileged logons, remote access, and RDP activity
  • Endpoint process creation and command-line telemetry for cmd.exe, WMI, PsExec, Net, Nltest, AdFind, esentutl, Rclone, and remote access tools
  • Active Directory and domain controller logs showing account, group, trust, and domain enumeration
  • Windows service creation, administrative share, SMB, and lateral movement evidence
  • Web server, application, VPN, and edge-device logs for public-facing application exploitation or exposed access paths

Detection direction

  • Build detections around behavior clusters: remote access or valid-account use followed by domain discovery, share discovery, lateral execution, staging, and large outbound transfer.
  • Treat PsExec, Net, Nltest, AdFind, WMI, RDP, esentutl, Rclone, and remote access tools as dual-use: tune with administrator baselines, approved hosts, change windows, and ticket context to reduce false positives.
  • Correlate identity events with endpoint command lines; many high-value signals come from legitimate accounts using legitimate tools in unusual sequences.
  • Validate monitoring of public-facing applications and remote access services, since relationships include Exploit Public-Facing Application, Valid Accounts, and RDP.
  • Look for data-theft precursors before encryption: staged archives or directories, Rclone execution or configuration artifacts, unusual cloud-storage synchronization, Tor use, and abnormal egress volumes.

Mitigation priorities

  • First reduce initial access exposure: inventory Internet-facing applications and remote access services, remediate known weaknesses and misconfigurations, and restrict unnecessary exposure.
  • Strengthen identity controls for valid-account abuse: enforce MFA where applicable, remove stale accounts, limit privileged access, monitor domain admin activity, and constrain RDP use.
  • Harden lateral movement paths by limiting administrative shares and remote execution methods to approved administrators and managed systems.
  • Control dual-use tooling by defining approved use of PsExec, Rclone, remote access tools, and administrative discovery utilities, then alerting on exceptions.
  • Improve egress governance for cloud storage, Tor-related traffic, and unusual application-layer outbound connections.
Additional notes and limits

The strongest decision value in this object comes from the relationships rather than the group-level fields. The ATT&CK entry ties INC Ransom to INC Ransomware and to behaviors spanning initial access, discovery, lateral movement, command and control, collection, exfiltration preparation, and stealth. The sector references make operational resilience particularly relevant for industrial, healthcare, and education environments, but local exposure must be determined from the organization’s own assets and telemetry.

ATT&CK does not provide official detection guidance, tactics, or platforms on the group object itself. Platform observations here are inferred only from the related ATT&CK software and technique relationships. This summary does not establish current targeting of any specific organization, confirmed exploitation in a local environment, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

INC Ransom

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1486Data Encrypted for Impact

INC Ransom has used INC Ransomware to encrypt victim's data.[4][6][1][3][2][5]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

INC Ransom has used RDP to move laterally.[2][6][5][7]

EnterpriseT1657Financial Theft

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.[2][1][3][5][4]

EnterpriseT1047Windows Management Instrumentation

INC Ransom has used WMIC to deploy ransomware.[2][6][5]

EnterpriseT1566Phishing

INC Ransom has used phishing to gain initial access.[5][4]

EnterpriseT1059.003Windows Command ShellSub-technique

INC Ransom has used `cmd.exe` to launch malicious payloads.[6]

EnterpriseT1537Transfer Data to Cloud Account

INC Ransom has used Megasync to exfiltrate data to the cloud.[3]

EnterpriseT1087.002Domain AccountSub-technique

INC Ransom has scanned for domain admin accounts in compromised environments.[5]

EnterpriseT1074Data Staged

INC Ransom has staged data on compromised hosts prior to exfiltration.[6][5]

EnterpriseT1071Application Layer Protocol

INC Ransom has used valid accounts over RDP to connect to targeted systems.[6]

EnterpriseT1046Network Service Discovery

INC Ransom has used NETSCAN.EXE for internal reconnaissance.[5][4]

EnterpriseT1569.002Service ExecutionSub-technique

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.[6]

EnterpriseT1219Remote Access Tools

INC Ransom has used AnyDesk and PuTTY on compromised systems.[6][5][7][4]

EnterpriseT1685Disable or Modify Tools

INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.[7]

EnterpriseT1588.002ToolSub-technique

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.[2][6][5][7][4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.[6][5]

EnterpriseT1570Lateral Tool Transfer

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.[6][3]

EnterpriseT1069.002Domain GroupsSub-technique

INC Ransom has enumerated domain groups on targeted hosts.[6]

EnterpriseT1135Network Share Discovery

INC Ransom has used Internet Explorer to view folders on other systems.[6]

EnterpriseT1190Exploit Public-Facing Application

INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.[5][4]

EnterpriseT1070.004File DeletionSub-technique

INC Ransom has uninstalled tools from compromised endpoints after use.[7]

EnterpriseT1078Valid Accounts

INC Ransom has used compromised valid accounts for access to victim environments.[2][6][5][7]

EnterpriseT1105Ingress Tool Transfer

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. [6][7]

EnterpriseT1560.001Archive via UtilitySub-technique

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.[6][3][5][7]

EnterpriseT1049System Network Connections Discovery

INC Ransom has used RDP to test network connections.[5]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0183: Tor

Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination. [1]

LinuxWindowsmacOS
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
e00644371f45fd20...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlee00644371f45…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  2. [2]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  3. [3]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  4. [4]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  5. [5]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  6. [6]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  7. [7]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  8. [8]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  9. [9]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  10. [10]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  11. [11]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  12. [12]
    GOLD IONIC

    (Citation: Secureworks GOLD IONIC April 2024)

  13. [13]
    GOLD IONIC

    (Citation: Secureworks GOLD IONIC April 2024)

  14. [14]
    GOLD IONIC

    (Citation: Secureworks GOLD IONIC April 2024)

  15. [15]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  16. [16]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  17. [17]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  18. [18]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  19. [19]
    mitre-attackG1032
    Open source URL
  20. [20]
    mitre-attackG1032
    Open source URL
  21. [21]
    mitre-attackG1032
    Open source URL
  22. [22]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  23. [23]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  24. [24]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  25. [25]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  26. [26]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  27. [27]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  28. [28]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  29. [29]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  30. [30]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  31. [31]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  32. [32]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  33. [33]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  34. [34]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  35. [35]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  36. [36]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  37. [37]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  38. [38]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  39. [39]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  40. [40]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  41. [41]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  42. [42]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  43. [43]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  44. [44]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  45. [45]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  46. [46]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  47. [47]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  48. [48]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  49. [49]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  50. [50]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  51. [51]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  52. [52]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  53. [53]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  54. [54]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  55. [55]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  56. [56]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  57. [57]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  58. [58]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  59. [59]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  60. [60]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  61. [61]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  62. [62]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  63. [63]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  64. [64]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  65. [65]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  66. [66]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  67. [67]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  68. [68]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  69. [69]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  70. [70]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  71. [71]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  72. [72]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  73. [73]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  74. [74]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  75. [75]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  76. [76]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  77. [77]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  78. [78]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  79. [79]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  80. [80]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  81. [81]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  82. [82]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  83. [83]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  84. [84]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  85. [85]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  86. [86]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  87. [87]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  88. [88]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  89. [89]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  90. [90]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  91. [91]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  92. [92]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  93. [93]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  94. [94]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  95. [95]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  96. [96]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  97. [97]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  98. [98]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  99. [99]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  100. [100]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  101. [101]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  102. [102]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  103. [103]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  104. [104]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  105. [105]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  106. [106]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  107. [107]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  108. [108]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  109. [109]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  110. [110]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  111. [111]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  112. [112]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  113. [113]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  114. [114]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  115. [115]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  116. [116]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  117. [117]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  118. [118]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  119. [119]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  120. [120]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  121. [121]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  122. [122]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  123. [123]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  124. [124]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  125. [125]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  126. [126]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  127. [127]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  128. [128]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  129. [129]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  130. [130]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  131. [131]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  132. [132]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  133. [133]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  134. [134]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  135. [135]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  136. [136]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  137. [137]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  138. [138]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  139. [139]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  140. [140]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  141. [141]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  142. [142]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  143. [143]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  144. [144]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  145. [145]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  146. [146]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  147. [147]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  148. [148]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  149. [149]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  150. [150]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  151. [151]
    Huntress INC Ransom Group August 2023

    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

    Open source URL
  152. [152]
    Huntress INC Ransomware May 2024

    Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  153. [153]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
  154. [154]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  155. [155]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  156. [156]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  157. [157]
    SOCRadar INC Ransom January 2024

    SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.