SOCRadar. (2024, January 24). Dark Web Profile: INC Ransom. Retrieved June 5, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupINC Ransom | INC Ransom has used RDP to move laterally. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1046 Network Service Discovery |
GroupINC Ransom | INC Ransom has used NETSCAN.EXE for internal reconnaissance. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1049 System Network Connections Discovery |
GroupINC Ransom | INC Ransom has used RDP to test network connections. |
| T1074 Data Staged |
GroupINC Ransom | INC Ransom has staged data on compromised hosts prior to exfiltration. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1087.002 Domain Account |
GroupINC Ransom | INC Ransom has scanned for domain admin accounts in compromised environments. |
| T1190 Exploit Public-Facing Application |
GroupINC Ransom | INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
| T1566 Phishing |
GroupINC Ransom | INC Ransom has used phishing to gain initial access. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1657 Financial Theft |
GroupINC Ransom | INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.