INC Ransomware Explained: How It Attacks Healthcare and Education
ID: 5253e693-ebc2-5a09-85e9-1dd3e8ca770b
STIX ID: report--5253e693-ebc2-5a09-85e9-1dd3e8ca770b
Feed Name: Picus Security Articles
INC Ransom is a multi-extortion ransomware group active since July 2023 that targets healthcare, industrial, and education organizations in the US and Europe. The report describes their use of living-off-the-land tools (NETSCAN.EXE, AnyDesk, SystemSettingsAdminFlows.exe), exploitation of Citrix CVEs for initial access, Defender tampering and EDR-killing utilities, credential harvesting (lsassy.py), data staging/exfiltration (7-Zip, MEGASync, rclone), and ransomware families that employ Salsa20/AES/Curve25519 on Windows and X25519/AES-128-CTR on Linux/ESXi, including operator-configurable options that can render systems non-bootable and support double-extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
