logo

Inc Ransom Attack Analysis: Extortion Methodologies

ID: 6d03db8f-df6a-5659-94e8-a45a7a84d591

STIX ID: report--6d03db8f-df6a-5659-94e8-a45a7a84d591

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2024-09-10

Date Updated: 2026-04-29

...
...

**Executive summary:** ReliaQuest investigated an August 2024 extortion campaign by the ransomware group “Inc Ransom” against a healthcare customer; attackers likely exploited a firewall, stole service account credentials using Impacket (secretsdump.py, wmiexec.py), performed lateral movement and SQL backup theft, used Rclone and split utilities to exfiltrate data, cleared logs and used encoded PowerShell for defense evasion, and the report provides mitigations for privileged account management, application controls, remote log storage, and network protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.