logo

LOLBin to INC Ransomware | Huntress

ID: 88a3d46b-6eff-521c-8144-a2400ceefa61

STIX ID: report--88a3d46b-6eff-521c-8144-a2400ceefa61

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-05-02

Date Updated: 2026-04-28

...
...

Huntress analysts observed an INC ransomware operation where attackers—demonstrating prior knowledge of target environments—used native Windows utilities and custom binaries to disable endpoint defenses, collect and exfiltrate data (rclone, MEGAsync), and stage file encryption; the report provides IOCs, ATT&CK mappings, and detection recommendations to help defenders identify and respond before encryption occurs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.