ATT&CKReferencesHuntress INC Ransom Group August 2023

Huntress INC Ransom Group August 2023

Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupINC Ransom

INC Ransom has used RDP to move laterally.

T1036.005
Match Legitimate Resource Name or Location
GroupINC Ransom

INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.

T1047
Windows Management Instrumentation
MalwareINC Ransomware

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1047
Windows Management Instrumentation
GroupINC Ransom

INC Ransom has used WMIC to deploy ransomware.

T1059.003
Windows Command Shell
GroupINC Ransom

INC Ransom has used `cmd.exe` to launch malicious payloads.

T1069.002
Domain Groups
GroupINC Ransom

INC Ransom has enumerated domain groups on targeted hosts.

T1071
Application Layer Protocol
GroupINC Ransom

INC Ransom has used valid accounts over RDP to connect to targeted systems.

T1074
Data Staged
GroupINC Ransom

INC Ransom has staged data on compromised hosts prior to exfiltration.

T1078
Valid Accounts
GroupINC Ransom

INC Ransom has used compromised valid accounts for access to victim environments.

T1105
Ingress Tool Transfer
GroupINC Ransom

INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.

T1135
Network Share Discovery
GroupINC Ransom

INC Ransom has used Internet Explorer to view folders on other systems.

T1219
Remote Access Tools
GroupINC Ransom

INC Ransom has used AnyDesk and PuTTY on compromised systems.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
MalwareINC Ransomware

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1560.001
Archive via Utility
GroupINC Ransom

INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.

T1569.002
Service Execution
GroupINC Ransom

INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.

T1570
Lateral Tool Transfer
GroupINC Ransom

INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.

T1570
Lateral Tool Transfer
MalwareINC Ransomware

INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure.

T1588.002
Tool
GroupINC Ransom

INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.