Threat actor
INC Ransom aka incransom
Operator-curated identity decision: incransom is folded into inc-ransom. inc-ransom was supplied by RansomLook. incransom was supplied by ransomware.live. The feeds supplied these spellings; neither asserted that they are one actor.
PDF export is unavailable. The threat brief remains available below; use your browser's Print command.
Executive facts
Actor INC Ransom
Kind ransomware
Aliases incransom
Actor record created 2026-07-03
Latest observed 2026-09-10
Leak-site claims 339
ATT&CK group G1032
Catalogued techniques 25
Mapping basis name-alias Scope
Tracked sectors Legal, Manufacturing, Business & Professional Services, Healthcare, Nonprofit
Claim records 2026-01-03 to 2026-09-10 Decisive signals with dates No dated decisive signals are attached to this actor's linked vulnerabilities.
Verified techniques Derived only from this actor's stored verified ATT&CK group-to-technique mappings (ATT&CK 19.2); phases are not scored. MITRE group provenance .
Defensive actions M1018 User Account Management 6 techniques M1031 Network Intrusion Prevention 6 techniques M1037 Filter Network Traffic 6 techniques M1026 Privileged Account Management 5 techniques M1038 Execution Prevention 5 techniques M1042 Disable or Remove Feature or Program 4 techniques M1047 Audit 4 techniques M1017 User Training 3 techniques M1022 Restrict File and Directory Permissions 3 techniques M1028 Operating System Configuration 3 techniques Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).
MITRE ATT&CK names and links © The MITRE Corporation.
Most-claimed sectors Legal Manufacturing Business & Professional Services Healthcare Nonprofit
Activity window in this corpus
This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.
Claim records First observed 2026-01-03 Latest observed 2026-09-10 Claims attributed to this actor or leak site 339 Origin and motivation
Origin and motivation not attributed.
Claims attributed to this actor or leak site
339 in this corpus jms building corporation Manufacturing 2026-09-10 source ↗ cullottalaw.com Business & Professional Services 2026-09-09 source ↗ https://mediengruppethiel.de/ Unclassified 2026-09-09 source ↗ Wellness Partners network(combined revenue) Healthcare 2026-09-07 source ↗ myglobal.com Construction & Engineering 2026-09-03 source ↗ Asfaltos y Pavimentos S.A. (Asfalpasa) Manufacturing 2026-09-02 source ↗ Westfield Public School District Education 2026-09-02 source ↗ Trucka Transportation & Logistics 2026-09-02 source ↗ Policlinico Triestino Healthcare 2026-09-02 source ↗ Multiver Ltée Manufacturing 2026-09-02 source ↗ View all on Breaches → Leak-site claim activity
0 additional claims without a disclosure date
2026-01 2026-09
Defensive actions
The MITRE ATT&CK mitigations countering the most of this group's known techniques, derived automatically from MITRE's own group and mitigation data. Each links to the full guidance with NIST 800-53 controls and authoritative configuration sources.
M1018 User Account Management 6 techniques M1031 Network Intrusion Prevention 6 techniques M1037 Filter Network Traffic 6 techniques M1026 Privileged Account Management 5 techniques M1038 Execution Prevention 5 techniques M1042 Disable or Remove Feature or Program 4 techniques M1047 Audit 4 techniques M1017 User Training 3 techniques M1022 Restrict File and Directory Permissions 3 techniques M1028 Operating System Configuration 3 techniques All defensive actions for INC Ransom → Detection rules
SigmaHQ detection rules mapped to this group's MITRE ATT&CK techniques. One technique maps to many rules, so this shows the top few by status and severity, with a link to the full set on SigmaHQ.
Detection rules for INC Ransom Showing 8 of 262
Author: Florian Roth (Nextron Systems), Arnim Rupp
Detection prerequisites: Log source: antivirus
False positives: Unlikely
title: Antivirus - Exploitation Framework Signature
id: 238527ad-3c2c-4e4f-a1f6-92fd63adb864
status: stable
description: |
Detects a highly relevant Antivirus alert that reports an exploitation framework.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
references:
- https://www.nextron-systems.com/?s=antivirus
- https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797
- https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424
- https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2018-09-09
modified: 2026-06-15
tags:
- attack.execution
- attack.t1203
- attack.command-and-control
- attack.t1219.002
logsource:
category: antivirus
detection:
selection:
Signature|contains:
- 'ATK/Cobalt'
- 'Backdoor.Cobalt'
- 'Beacon'
- 'Brutel'
- 'BruteR'
- 'CbltStr'
- 'CobaltStr'
- 'COBALT.SMD'
- 'COBEACON'
- 'Cometer'
- 'Exploit.Script.CVE'
- 'IISExchgSpawnCMD'
- 'Metasploit'
- 'Meterpreter'
- 'MeteTool'
- 'Mpreter'
- 'MsfShell'
- 'PowerSploit'
- 'Razy'
- 'Rozena'
- 'Sbelt'
- 'Seatbelt'
- 'Sliver'
- 'Swrort'
condition: selection
falsepositives:
- Unlikely
level: critical
View this rule on SigmaHQ ↗ Author: Florian Roth (Nextron Systems)
Detection prerequisites: Platform: windows · Log source: process_creation
False positives: Unknown
title: Droppers Exploiting CVE-2017-11882
id: 678eb5f4-8597-4be6-8be7-905e4234b53a
status: stable
description: Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
references:
- https://www.hybrid-analysis.com/sample/2a4ae284c76f868fc51d3bb65da8caa6efacb707f265b25c30f34250b76b7507?environmentId=100
- https://www.linkedin.com/pulse/exploit-available-dangerous-ms-office-rce-vuln-called-thebenygreen-
- https://github.com/embedi/CVE-2017-11882
author: Florian Roth (Nextron Systems)
date: 2017-11-23
modified: 2021-11-27
tags:
- attack.execution
- attack.t1203
- attack.t1204.002
- attack.initial-access
- attack.t1566.001
- cve.2017-11882
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\EQNEDT32.EXE'
condition: selection
falsepositives:
- Unknown
level: critical
View this rule on SigmaHQ ↗ Author: Florian Roth (Nextron Systems)
Detection prerequisites: Platform: windows · Log source: process_creation
False positives: Unknown
title: Exploit for CVE-2015-1641
id: 7993792c-5ce2-4475-a3db-a3a5539827ef
status: stable
description: Detects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641
references:
- https://www.virustotal.com/en/file/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8/analysis/
- https://www.hybrid-analysis.com/sample/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8?environmentId=100
author: Florian Roth (Nextron Systems)
date: 2018-02-22
modified: 2021-11-27
tags:
- attack.stealth
- attack.t1036.005
- cve.2015-1641
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\WINWORD.EXE'
Image|endswith: '\MicroScMgmt.exe'
condition: selection
falsepositives:
- Unknown
level: critical
View this rule on SigmaHQ ↗ Author: Vasiliy Burov, oscd.community
Detection prerequisites: Platform: windows · Log source: process_creation
False positives: Unlikely
title: LockerGoga Ransomware Activity
id: 74db3488-fd28-480a-95aa-b7af626de068
status: stable
description: Detects LockerGoga ransomware activity via specific command line.
references:
- https://medium.com/@malwaredancer/lockergoga-input-arguments-ipc-communication-and-others-bd4e5a7ba80a
- https://blog.f-secure.com/analysis-of-lockergoga-ransomware/
- https://www.carbonblack.com/blog/tau-threat-intelligence-notification-lockergoga-ransomware/
author: Vasiliy Burov, oscd.community
date: 2020-10-18
modified: 2023-02-03
tags:
- attack.impact
- attack.t1486
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains: '-i SM-tgytutrc -s'
condition: selection
falsepositives:
- Unlikely
level: critical
View this rule on SigmaHQ ↗ Author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)
Detection prerequisites: Platform: windows · Log source: process_creation
False positives: Unlikely
title: Potential Dridex Activity
id: e6eb5a96-9e6f-4a18-9cdd-642cfda21c8e
status: stable
description: Detects potential Dridex acitvity via specific process patterns
references:
- https://app.any.run/tasks/993daa5e-112a-4ff6-8b5a-edbcec7c7ba3
- https://redcanary.com/threat-detection-report/threats/dridex/
author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)
date: 2019-01-10
modified: 2023-02-03
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1055
- attack.discovery
- attack.t1135
- attack.t1033
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_svchost:
Image|endswith: '\svchost.exe'
CommandLine|contains|all:
- 'C:\Users\'
- '\Desktop\'
filter_svchost:
ParentImage|startswith: 'C:\Windows\System32\'
selection_regsvr:
ParentImage|endswith: '\excel.exe'
Image|endswith: '\regsvr32.exe'
CommandLine|contains:
- ' -s '
- '\AppData\Local\Temp\'
filter_regsvr:
CommandLine|contains: '.dll'
selection_anomaly_parent:
ParentImage|endswith: '\svchost.exe'
selection_anomaly_child_1:
Image|endswith: '\whoami.exe'
CommandLine|contains: ' /all'
selection_anomaly_child_2:
Image|endswith:
- '\net.exe'
- '\net1.exe'
CommandLine|contains: ' view'
condition: (selection_svchost and not filter_svchost) or (selection_regsvr and not filter_regsvr) or (selection_anomaly_parent and 1 of selection_anomaly_child_*)
falsepositives:
- Unlikely
level: critical
View this rule on SigmaHQ ↗ Author: Thomas Patzke
Detection prerequisites: Log source: proxy
False positives: Unknown
title: Ursnif Malware C2 URL Pattern
id: 932ac737-33ca-4afd-9869-0d48b391fcc9
status: stable
description: Detects Ursnif C2 traffic.
references:
- https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html
author: Thomas Patzke
date: 2019-12-19
modified: 2021-08-09
tags:
- attack.initial-access
- attack.t1566.001
- attack.execution
- attack.t1204.002
- attack.command-and-control
- attack.t1071.001
- detection.emerging-threats
logsource:
category: proxy
detection:
b64encoding:
c-uri|contains:
- '_2f'
- '_2b'
urlpatterns:
c-uri|contains|all:
- '.avi'
- '/images/'
condition: b64encoding and urlpatterns
falsepositives:
- Unknown
level: critical
View this rule on SigmaHQ ↗ Author: Sittikorn S
Detection prerequisites: Platform: aws · Service: cloudtrail
False positives: System or Network administrator behaviors; DEV, UAT, SAT environment. You should apply this rule with PROD environment only.
title: AWS SecurityHub Findings Evasion
id: a607e1fe-74bf-4440-a3ec-b059b9103157
status: stable
description: Detects the modification of the findings on SecurityHub.
references:
- https://docs.aws.amazon.com/cli/latest/reference/securityhub/
author: Sittikorn S
date: 2021-06-28
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: securityhub.amazonaws.com
eventName:
- 'BatchUpdateFindings'
- 'DeleteInsight'
- 'UpdateFindings'
- 'UpdateInsight'
condition: selection
falsepositives:
- System or Network administrator behaviors
- DEV, UAT, SAT environment. You should apply this rule with PROD environment only.
level: high
View this rule on SigmaHQ ↗ Author: Thomas Patzke
Detection prerequisites: Platform: windows · Log source: process_creation
False positives: Unknown
title: HackTool - CrackMapExec Execution Patterns
id: 058f4380-962d-40a5-afce-50207d36d7e2
status: stable
description: Detects various execution patterns of the CrackMapExec pentesting framework
references:
- https://github.com/byt3bl33d3r/CrackMapExec
author: Thomas Patzke
date: 2020-05-22
modified: 2023-11-06
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.t1047
- attack.t1053
- attack.t1059.003
- attack.t1059.001
- attack.s0106
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
# cme/protocols/smb/wmiexec.py (generalized execute_remote and execute_fileless)
- 'cmd.exe /Q /c * 1> \\\\*\\*\\* 2>&1'
# cme/protocols/smb/atexec.py:109 (fileless output via share)
- 'cmd.exe /C * > \\\\*\\*\\* 2>&1'
# cme/protocols/smb/atexec.py:111 (fileless output via share)
- 'cmd.exe /C * > *\\Temp\\* 2>&1'
# https://github.com/byt3bl33d3r/CrackMapExec/blob/d8c50c8cbaf36c29329078662473f75e440978d2/cme/helpers/powershell.py#L136 (PowerShell execution with obfuscation)
- 'powershell.exe -exec bypass -noni -nop -w 1 -C "'
# https://github.com/byt3bl33d3r/CrackMapExec/blob/d8c50c8cbaf36c29329078662473f75e440978d2/cme/helpers/powershell.py#L160 (PowerShell execution without obfuscation)
- 'powershell.exe -noni -nop -w 1 -enc '
condition: selection
falsepositives:
- Unknown
level: high
View this rule on SigmaHQ ↗ View all detecting rules on SigmaHQ → Detection rules licensed under Detection Rule License (DRL) 1.1 , from SigmaHQ. Each rule retains its author.
Validation tests
Atomic Red Team validating tests mapped to this group's MITRE ATT&CK techniques, shown beside the detection rules so you can validate the detections. This shows the top few, with a link to the full set on GitHub. Descriptive metadata only, never the attack commands.
Validating tests for INC Ransom Showing 8 of 205
Platforms: linux
This test uses LDAPDomainDump to perform account enumeration on a domain.
[Reference](https://securityonline.info/ldapdomaindump-active-directory-information-dumper-via-ldap/)
View this test on GitHub ↗ Platforms: linux
Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory
View this test on GitHub ↗ Platforms: linux
Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory
View this test on GitHub ↗ Platforms: windows
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Admin accounts
reference- http://www.joeware.net/freetools/tools/adfind/, https://stealthbits.com/blog/fun-with-active-directorys-admincount-attribute/
View this test on GitHub ↗ Platforms: windows
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Exchange Objects
reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html
View this test on GitHub ↗ Platforms: windows
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory User Objects
reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html
View this test on GitHub ↗ Platforms: windows
Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Groups
reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html
View this test on GitHub ↗ Platforms: windows
Adfind tool can be used for reconnaissance in an Active directory environment. The example chosen illustrates adfind used to query the local password policy.
reference- http://www.joeware.net/freetools/tools/adfind/, https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx
View this test on GitHub ↗ View all validating tests on GitHub → Atomic tests from Atomic Red Team , (c) Red Canary, MIT License . Not affiliated with or endorsed by Red Canary.
Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).