Carvey, H. (2024, May 1). LOLBin to INC Ransomware. Retrieved June 5, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupINC Ransom | INC Ransom has used RDP to move laterally. |
| T1070.004 File Deletion |
GroupINC Ransom | INC Ransom has uninstalled tools from compromised endpoints after use. |
| T1078 Valid Accounts |
GroupINC Ransom | INC Ransom has used compromised valid accounts for access to victim environments. |
| T1105 Ingress Tool Transfer |
GroupINC Ransom | INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1560.001 Archive via Utility |
GroupINC Ransom | INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration. |
| T1588.002 Tool |
GroupINC Ransom | INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec. |
| T1685 Disable or Modify Tools |
GroupINC Ransom | INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.