ATT&CKSoftwareINC Ransomware

INC Ransomware

S1139

Malware.View on attack.mitre.org

About this malware

INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors worldwide. INC Ransomware can employ partial encryption combined with multi-threading to speed encryption.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1047
Windows Management Instrumentation

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1057
Process Discovery

INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.

T1083
File and Directory Discovery

INC Ransomware can receive command line arguments to encrypt specific files and directories.

T1106
Native API

INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.

T1120
Peripheral Device Discovery

INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.

T1135
Network Share Discovery

INC Ransomware has the ability to check for shared network drives to encrypt.

T1140
Deobfuscate/Decode Files or Information

INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.

T1486
Data Encrypted for Impact

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1489
Service Stop

INC Ransomware can issue a command to kill a process on compromised hosts.

T1490
Inhibit System Recovery

INC Ransomware can delete volume shadow copy backups from victim machines.

T1491.001
Internal Defacement

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

T1566
Phishing

INC Ransomware campaigns have used spearphishing emails for initial access.

T1570
Lateral Tool Transfer

INC Ransomware can push its encryption executable to multiple endpoints within compromised infrastructure.

T1652
Device Driver Discovery

INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.

T1680
Local Storage Discovery

INC Ransomware can discover and mount hidden drives to encrypt them.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Huntress INC Ransom Group August 2023 Open source
    Team Huntress. (2023, August 11). Investigating New INC Ransom Group Activity. Retrieved June 5, 2024.
  2. Secureworks GOLD IONIC April 2024 Open source
    Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
  3. SentinelOne INC Ransomware Open source
    SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.