logo

Investigating New INC Ransom Group Activity

ID: 4d05976a-844a-5eac-8b21-27914605ec2e

STIX ID: report--4d05976a-844a-5eac-8b21-27914605ec2e

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress investigated a week-long ransomware intrusion by a group calling itself "INC" that used compromised valid accounts and RDP to access multiple servers, performed reconnaissance and credential dumping (lsassy.py), staged and exfiltrated data (7-Zip archives, MEGASync), and attempted widespread encryption using a named executable (SHA256: accd8bc0d0c2675c15c169688b882ded17e78aed0d914793098337afc57c289c) with PSExec/WMIC to deploy; the report includes IOCs (PDB string, ransom note names, encrypted file extension) and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.