Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupINC Ransom | INC Ransom has used RDP to move laterally. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1047 Windows Management Instrumentation |
MalwareINC Ransomware | INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1059.003 Windows Command Shell |
GroupINC Ransom | INC Ransom has used `cmd.exe` to launch malicious payloads. |
| T1069.002 Domain Groups |
GroupINC Ransom | INC Ransom has enumerated domain groups on targeted hosts. |
| T1071 Application Layer Protocol |
GroupINC Ransom | INC Ransom has used valid accounts over RDP to connect to targeted systems. |
| T1074 Data Staged |
GroupINC Ransom | INC Ransom has staged data on compromised hosts prior to exfiltration. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1105 Ingress Tool Transfer |
GroupINC Ransom | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. |
| T1135 Network Share Discovery |
GroupINC Ransom | INC Ransom has used Internet Explorer to view folders on other systems. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
| T1569.002 Service Execution |
GroupINC Ransom | INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`. |
| T1570 Lateral Tool Transfer |
GroupINC Ransom | INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure. |
| T1570 Lateral Tool Transfer |
MalwareINC Ransomware | INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.