G1032: INC Ransom
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]
Security context for executives and security teams
G1032: INC Ransom describes [INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 202...
Executive priority
G1032: INC Ransom is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1032: INC Ransom by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1032: INC Ransom appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
INC Ransom
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1486 | Data Encrypted for Impact | INC Ransom has used INC Ransomware to encrypt victim's data.[4]CitationHuntress INC Ransom Group August 2023[1][3][2]CitationSOCRadar INC Ransom January 2024 |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | INC Ransom has used RDP to move laterally.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1657 | Financial Theft | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.[2][1][3]CitationSOCRadar INC Ransom January 2024[4] |
| Enterprise | T1047 | Windows Management Instrumentation | INC Ransom has used WMIC to deploy ransomware.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024 |
| Enterprise | T1566 | Phishing | INC Ransom has used phishing to gain initial access.CitationSOCRadar INC Ransom January 2024[4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | INC Ransom has used `cmd.exe` to launch malicious payloads.CitationHuntress INC Ransom Group August 2023 |
| Enterprise | T1537 | Transfer Data to Cloud Account | INC Ransom has used Megasync to exfiltrate data to the cloud.[3] |
| Enterprise | T1087.002 | Domain AccountSub-technique | INC Ransom has scanned for domain admin accounts in compromised environments.CitationSOCRadar INC Ransom January 2024 |
| Enterprise | T1074 | Data Staged | INC Ransom has staged data on compromised hosts prior to exfiltration.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024 |
| Enterprise | T1071 | Application Layer Protocol | INC Ransom has used valid accounts over RDP to connect to targeted systems.CitationHuntress INC Ransom Group August 2023 |
| Enterprise | T1046 | Network Service Discovery | INC Ransom has used NETSCAN.EXE for internal reconnaissance.CitationSOCRadar INC Ransom January 2024[4] |
| Enterprise | T1569.002 | Service ExecutionSub-technique | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.CitationHuntress INC Ransom Group August 2023 |
| Enterprise | T1219 | Remote Access Tools | INC Ransom has used AnyDesk and PuTTY on compromised systems.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024[4] |
| Enterprise | T1685 | Disable or Modify Tools | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1588.002 | ToolSub-technique | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024[4] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024 |
| Enterprise | T1570 | Lateral Tool Transfer | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.CitationHuntress INC Ransom Group August 2023[3] |
| Enterprise | T1069.002 | Domain GroupsSub-technique | INC Ransom has enumerated domain groups on targeted hosts.CitationHuntress INC Ransom Group August 2023 |
| Enterprise | T1135 | Network Share Discovery | INC Ransom has used Internet Explorer to view folders on other systems.CitationHuntress INC Ransom Group August 2023 |
| Enterprise | T1190 | Exploit Public-Facing Application | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.CitationSOCRadar INC Ransom January 2024[4] |
| Enterprise | T1070.004 | File DeletionSub-technique | INC Ransom has uninstalled tools from compromised endpoints after use.CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1078 | Valid Accounts | INC Ransom has used compromised valid accounts for access to victim environments.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1105 | Ingress Tool Transfer | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. CitationHuntress INC Ransom Group August 2023CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.CitationHuntress INC Ransom Group August 2023[3]CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024 |
| Enterprise | T1049 | System Network Connections Discovery | INC Ransom has used RDP to test network connections.CitationSOCRadar INC Ransom January 2024 |
Groups, software, and campaigns
S0183: Tor
Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination. [1]
S0029: PsExec
S0359: Nltest
S1040: Rclone
S0552: AdFind
S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
S0404: esentutl
S1139: INC Ransomware
INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors worldwide. INC Ransomware can employ partial encryption combined with multi-threading to speed encryption.[1][2][3]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | f3d5108fd8d1… | ||
| 19.1 | 1.0 | Older bundle | e00644371f45… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Bleeping Computer INC Ransomware March 2024
Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.
Open source URL - [2]Cybereason INC Ransomware November 2023
Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
Open source URL - [3]Secureworks GOLD IONIC April 2024
Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
Open source URL - [4]SentinelOne INC Ransomware
SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
Open source URL - [5]GOLD IONIC
(Citation: Secureworks GOLD IONIC April 2024)
- [6]mitre-attackG1032Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
