INC Ransomware — Malware Profile
INC Ransomware is a ransomware strain that has been used by the INC Ransom group since at least 2023 against multiple industry sectors worldwide. INC Ransomware can employ partial encryption combined with multi-threading to speed encryption.
MITRE ATT&CK techniques (15)
- T1047 Windows Management Instrumentation
- T1057 Process Discovery
- T1083 File and Directory Discovery
- T1106 Native API
- T1120 Peripheral Device Discovery
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1486 Data Encrypted for Impact
- T1489 Service Stop
- T1490 Inhibit System Recovery
- T1491.001 Internal Defacement
- T1566 Phishing
- T1570 Lateral Tool Transfer
- T1652 Device Driver Discovery
- T1680 Local Storage Discovery