INC Ransomware affiliate targets ESXi & NAS Devices in AD environment
ID: b55b1148-94a3-53b0-acfd-60ab8e1b7e99
STIX ID: report--b55b1148-94a3-53b0-acfd-60ab8e1b7e99
Feed Name: Ctrl-Alt-Int3l
Researchers exposed an INC Ransom affiliate's operator working directory that documents a sophisticated intrusion against a Chinese technology company combining compromised Microsoft 365 and VPN credentials, WinRM-driven Active Directory compromise, vCenter/ESXi and storage management-plane attacks, exfiltration of NTDS/registry hives, and deployment of a multi-platform INC encryptor to map and encrypt NAS shares; the collection includes scripts, tooling, IOCs (IP 213.176.114.6, domain names, file hashes), and evidence the affiliate leveraged LLM-generated code to operationalize the attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
