INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration
ID: d9ebc38e-5d44-5ae1-bed1-6db0299530e7
STIX ID: report--d9ebc38e-5d44-5ae1-bed1-6db0299530e7
Feed Name: Cyber Press
INC is a highly active Ransomware-as-a-Service group that has claimed over 800 victims since mid-2023, focusing on legal, manufacturing, technology, and healthcare organizations primarily in the United States. The group uses spear-phishing, bought credentials, and exploits of public-facing CVEs (e.g., Citrix and Fortinet issues) to gain access, employs a Base64-encoded PowerShell tool to extract Veeam/DPAPI-protected credentials, and deploys Rust-based, cross-platform ransomware that supports partial multithreaded encryption on Windows and destructive workflows on Linux/ESXi; it also maintains private negotiation portals and public leak sites as part of a double-extortion strategy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
