logo

INC Ransomware affiliate targets ESXi & NAS Devices in AD environment

ID: b55b1148-94a3-53b0-acfd-60ab8e1b7e99

STIX ID: report--b55b1148-94a3-53b0-acfd-60ab8e1b7e99

Feed Name: Ctrl-Alt-Int3l

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: Ctrl-Alt-Intel

...
...

Researchers exposed an INC Ransom affiliate's operator working directory that documents a sophisticated intrusion against a Chinese technology company combining compromised Microsoft 365 and VPN credentials, WinRM-driven Active Directory compromise, vCenter/ESXi and storage management-plane attacks, exfiltration of NTDS/registry hives, and deployment of a multi-platform INC encryptor to map and encrypt NAS shares; the collection includes scripts, tooling, IOCs (IP 213.176.114.6, domain names, file hashes), and evidence the affiliate leveraged LLM-generated code to operationalize the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.