Hacker groupG1032

INC Ransom

Also tracked as GOLD IONIC

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.

Known attack methods
25
Motive
Financial gain
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

INC Ransomware

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

AdFindNetNltestPsExecRcloneToresentutl