INC Ransom
MITRE ATT&CK: G1032 View on attack.mitre.org
Aliases: GOLD IONIC, INC Ransom
- First seen
- 2023-07-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:30:27
Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical manufacturing
Targeted regions: country_code:us country_code:fr country_code:de
Context
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.
Detection coverage
- 3 YARA rules
- 611 Sigma rules
Malware & tools used
- Data Encrypted for Impact (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Financial Theft (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Phishing (attack-pattern)
- Windows Command Shell (attack-pattern)
- Transfer Data to Cloud Account (attack-pattern)
- Domain Account (attack-pattern)
- Data Staged (attack-pattern)
- Application Layer Protocol (attack-pattern)
- Network Service Discovery (attack-pattern)
- Service Execution (attack-pattern)
- Remote Access Tools (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Tool (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Domain Groups (attack-pattern)
- Network Share Discovery (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- File Deletion (attack-pattern)
- Valid Accounts (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Archive via Utility (attack-pattern)
- System Network Connections Discovery (attack-pattern)
Reports & references
- MITRE ATT&CK — G1032 (report)
- bleepingcomputer.com — Inc Ransom Threatens To Leak 3Tb Of Nhs Scotland Stolen Data (report)
- cybereason.com — Threat Alert Inc Ransomware (report)
- secureworks.com — Gold Ionic Deploys Inc Ransomware (report)
- sentinelone.com — Inc Ransom (report)