logo

Inc Ransom Attack Analysis

ID: 94f3fb6a-9524-5251-8317-7117a9e86b63

STIX ID: report--94f3fb6a-9524-5251-8317-7117a9e86b63

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2024-08-06

Date Updated: 2026-04-29

...
...

ReliaQuest investigated an April 2024 intrusion by the 'Inc Ransom' double-extortion ransomware group that gained likely initial access to an internet-facing Fortinet EMS server (CVE-2023-48788), deployed RMM tools (AnyDesk, SimpleHelp), harvested credentials (SAM export, secretsdump.py), used pass-the-hash for lateral movement to obtain domain admin access, and exfiltrated file-share data with the backup tool Restic; no file encryption was observed but the activity aligns with typical double-extortion tactics and includes recommendations for patching, network segmentation, EDR, and application control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.