Investigating New INC Ransom Group Activity
ID: 4d05976a-844a-5eac-8b21-27914605ec2e
STIX ID: report--4d05976a-844a-5eac-8b21-27914605ec2e
Feed Name: Huntress Blog
Huntress investigated a week-long ransomware intrusion by a group calling itself "INC" that used compromised valid accounts and RDP to access multiple servers, performed reconnaissance and credential dumping (lsassy.py), staged and exfiltrated data (7-Zip archives, MEGASync), and attempted widespread encryption using a named executable (SHA256: accd8bc0d0c2675c15c169688b882ded17e78aed0d914793098337afc57c289c) with PSExec/WMIC to deploy; the report includes IOCs (PDB string, ransom note names, encrypted file extension) and MITRE ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
