LOLBin to INC Ransomware | Huntress
ID: 88a3d46b-6eff-521c-8144-a2400ceefa61
STIX ID: report--88a3d46b-6eff-521c-8144-a2400ceefa61
Feed Name: Huntress Blog
Threat Score
Huntress analysts observed an INC ransomware operation where attackers—demonstrating prior knowledge of target environments—used native Windows utilities and custom binaries to disable endpoint defenses, collect and exfiltrate data (rclone, MEGAsync), and stage file encryption; the report provides IOCs, ATT&CK mappings, and detection recommendations to help defenders identify and respond before encryption occurs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
