LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1032: INC Ransom

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]

EnterpriseG1032GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1032: INC Ransom describes [INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 202...

Executive priority

G1032: INC Ransom is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1032: INC Ransom by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1032: INC Ransom appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

INC Ransom

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

25 rows
DomainIDNameRelationship / procedure
EnterpriseT1486Data Encrypted for Impact

INC Ransom has used INC Ransomware to encrypt victim's data.[4]CitationHuntress INC Ransom Group August 2023[1][3][2]CitationSOCRadar INC Ransom January 2024

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

INC Ransom has used RDP to move laterally.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024

EnterpriseT1657Financial Theft

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.[2][1][3]CitationSOCRadar INC Ransom January 2024[4]

EnterpriseT1047Windows Management Instrumentation

INC Ransom has used WMIC to deploy ransomware.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024

EnterpriseT1566Phishing

INC Ransom has used phishing to gain initial access.CitationSOCRadar INC Ransom January 2024[4]

EnterpriseT1059.003Windows Command ShellSub-technique

INC Ransom has used `cmd.exe` to launch malicious payloads.CitationHuntress INC Ransom Group August 2023

EnterpriseT1537Transfer Data to Cloud Account

INC Ransom has used Megasync to exfiltrate data to the cloud.[3]

EnterpriseT1087.002Domain AccountSub-technique

INC Ransom has scanned for domain admin accounts in compromised environments.CitationSOCRadar INC Ransom January 2024

EnterpriseT1074Data Staged

INC Ransom has staged data on compromised hosts prior to exfiltration.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024

EnterpriseT1071Application Layer Protocol

INC Ransom has used valid accounts over RDP to connect to targeted systems.CitationHuntress INC Ransom Group August 2023

EnterpriseT1046Network Service Discovery

INC Ransom has used NETSCAN.EXE for internal reconnaissance.CitationSOCRadar INC Ransom January 2024[4]

EnterpriseT1569.002Service ExecutionSub-technique

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.CitationHuntress INC Ransom Group August 2023

EnterpriseT1219Remote Access Tools

INC Ransom has used AnyDesk and PuTTY on compromised systems.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024[4]

EnterpriseT1685Disable or Modify Tools

INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.CitationHuntress INC Ransomware May 2024

EnterpriseT1588.002ToolSub-technique

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024[4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024

EnterpriseT1570Lateral Tool Transfer

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.CitationHuntress INC Ransom Group August 2023[3]

EnterpriseT1069.002Domain GroupsSub-technique

INC Ransom has enumerated domain groups on targeted hosts.CitationHuntress INC Ransom Group August 2023

EnterpriseT1135Network Share Discovery

INC Ransom has used Internet Explorer to view folders on other systems.CitationHuntress INC Ransom Group August 2023

EnterpriseT1190Exploit Public-Facing Application

INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.CitationSOCRadar INC Ransom January 2024[4]

EnterpriseT1070.004File DeletionSub-technique

INC Ransom has uninstalled tools from compromised endpoints after use.CitationHuntress INC Ransomware May 2024

EnterpriseT1078Valid Accounts

INC Ransom has used compromised valid accounts for access to victim environments.[2]CitationHuntress INC Ransom Group August 2023CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024

EnterpriseT1105Ingress Tool Transfer

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. CitationHuntress INC Ransom Group August 2023CitationHuntress INC Ransomware May 2024

EnterpriseT1560.001Archive via UtilitySub-technique

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.CitationHuntress INC Ransom Group August 2023[3]CitationSOCRadar INC Ransom January 2024CitationHuntress INC Ransomware May 2024

EnterpriseT1049System Network Connections Discovery

INC Ransom has used RDP to test network connections.CitationSOCRadar INC Ransom January 2024

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0183: Tor

Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination. [1]

LinuxWindowsmacOS
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
f3d5108fd8d19f29...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundlef3d5108fd8d1…
19.11.0Older bundlee00644371f45…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Bleeping Computer INC Ransomware March 2024

    Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

    Open source URL
  2. [2]
    Cybereason INC Ransomware November 2023

    Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.

    Open source URL
  3. [3]
    Secureworks GOLD IONIC April 2024

    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.

    Open source URL
  4. [4]
    SentinelOne INC Ransomware

    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

    Open source URL
  5. [5]
    GOLD IONIC

    (Citation: Secureworks GOLD IONIC April 2024)

  6. [6]
    mitre-attackG1032
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.