INC RANSOMWARE : THREAT INTELLIGENCE
ID: 84446da7-9db4-529f-ac7d-e6ade1015c28
STIX ID: report--84446da7-9db4-529f-ac7d-e6ade1015c28
Feed Name: THE RAVEN FILE
**INC Ransomware intelligence snapshot:** This report documents discovery of INC's negotiation/chat panel (including the Onion address and a revealed real IP), analysis of the bundled JavaScript and tech stack (React/Redux/Socket.io, JWT auth), unusual operational choices (use of port 1002), hosting and CDN/IP overlap patterns (heavy Russian hosting, mixed cloud usage, Cloudflare fronting), sample timelines and sizes (108 samples, clustering around April 2024 and larger stable builds in 2025), and operational scale (≈872 victims with active disclosures), concluding that INC is an active, evolving ransomware actor with reusable infrastructure and multiple spin-offs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
