Inc Ransom Attack Analysis: Extortion Methodologies
ID: 6d03db8f-df6a-5659-94e8-a45a7a84d591
STIX ID: report--6d03db8f-df6a-5659-94e8-a45a7a84d591
Feed Name: ReliaQuest Blog
**Executive summary:** ReliaQuest investigated an August 2024 extortion campaign by the ransomware group “Inc Ransom” against a healthcare customer; attackers likely exploited a firewall, stole service account credentials using Impacket (secretsdump.py, wmiexec.py), performed lateral movement and SQL backup theft, used Rclone and split utilities to exfiltrate data, cleared logs and used encoded PowerShell for defense evasion, and the report provides mitigations for privileged account management, application controls, remote log storage, and network protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
