CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Threat actor

INC Ransom

ransomware339 leak-site claims, all timeLatest observed leak-site post 2026-09-10MITRE ATT&CK G1032 ↗ORKL search ↗
aka incransom
Operator-curated identity decision: incransom is folded into inc-ransom. inc-ransom was supplied by RansomLook. incransom was supplied by ransomware.live. The feeds supplied these spellings; neither asserted that they are one actor.

Portable threat brief

INC Ransom

Versioned profile fields only · no model narrative

Opens the browser print dialog; choose Save as PDF.

PDF export is unavailable. The threat brief remains available below; use your browser's Print command.

Executive facts

Actor
INC Ransom
Kind
ransomware
Aliases
incransom
Actor record created
2026-07-03
Latest observed
2026-09-10
Leak-site claims
339
ATT&CK group
G1032
Catalogued techniques
25
Mapping basis
name-alias

Scope

Tracked sectors
Legal, Manufacturing, Business & Professional Services, Healthcare, Nonprofit
Claim records
2026-01-03 to 2026-09-10

Decisive signals with dates

No dated decisive signals are attached to this actor's linked vulnerabilities.

Verified techniques

Derived only from this actor's stored verified ATT&CK group-to-technique mappings (ATT&CK 19.2); phases are not scored. MITRE group provenance.

Defensive actions

  • M1018User Account Management6 techniques
  • M1031Network Intrusion Prevention6 techniques
  • M1037Filter Network Traffic6 techniques
  • M1026Privileged Account Management5 techniques
  • M1038Execution Prevention5 techniques
  • M1042Disable or Remove Feature or Program4 techniques
  • M1047Audit4 techniques
  • M1017User Training3 techniques
  • M1022Restrict File and Directory Permissions3 techniques
  • M1028Operating System Configuration3 techniques

Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).

MITRE ATT&CK names and links © The MITRE Corporation.

Most-claimed sectorsLegalManufacturingBusiness & Professional ServicesHealthcareNonprofit
Activity window in this corpus

This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.

Claim records
First observed Latest observed
Verified ATT&CK phases represented

Derived only from this actor's stored verified ATT&CK group-to-technique mappings (ATT&CK 19.2); phases are not scored.

Origin and motivation

Origin and motivation not attributed.

Claims attributed to this actor or leak site
339 in this corpus
View all on Breaches →
Leak-site claim activity

0 additional claims without a disclosure date

2026-012026-09
Defensive actions

The MITRE ATT&CK mitigations countering the most of this group's known techniques, derived automatically from MITRE's own group and mitigation data. Each links to the full guidance with NIST 800-53 controls and authoritative configuration sources.

All defensive actions for INC Ransom →
Detection rules

SigmaHQ detection rules mapped to this group's MITRE ATT&CK techniques. One technique maps to many rules, so this shows the top few by status and severity, with a link to the full set on SigmaHQ.

Detection rules for INC RansomShowing 8 of 262
Author: Florian Roth (Nextron Systems), Arnim Rupp

Detection prerequisites: Log source: antivirus

False positives: Unlikely

title: Antivirus - Exploitation Framework Signature
id: 238527ad-3c2c-4e4f-a1f6-92fd63adb864
status: stable
description: |
    Detects a highly relevant Antivirus alert that reports an exploitation framework.
    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
references:
    - https://www.nextron-systems.com/?s=antivirus
    - https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797
    - https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424
    - https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466
author: Florian Roth (Nextron Systems), Arnim Rupp
date: 2018-09-09
modified: 2026-06-15
tags:
    - attack.execution
    - attack.t1203
    - attack.command-and-control
    - attack.t1219.002
logsource:
    category: antivirus
detection:
    selection:
        Signature|contains:
            - 'ATK/Cobalt'
            - 'Backdoor.Cobalt'
            - 'Beacon'
            - 'Brutel'
            - 'BruteR'
            - 'CbltStr'
            - 'CobaltStr'
            - 'COBALT.SMD'
            - 'COBEACON'
            - 'Cometer'
            - 'Exploit.Script.CVE'
            - 'IISExchgSpawnCMD'
            - 'Metasploit'
            - 'Meterpreter'
            - 'MeteTool'
            - 'Mpreter'
            - 'MsfShell'
            - 'PowerSploit'
            - 'Razy'
            - 'Rozena'
            - 'Sbelt'
            - 'Seatbelt'
            - 'Sliver'
            - 'Swrort'
    condition: selection
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unknown

title: Droppers Exploiting CVE-2017-11882
id: 678eb5f4-8597-4be6-8be7-905e4234b53a
status: stable
description: Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
references:
    - https://www.hybrid-analysis.com/sample/2a4ae284c76f868fc51d3bb65da8caa6efacb707f265b25c30f34250b76b7507?environmentId=100
    - https://www.linkedin.com/pulse/exploit-available-dangerous-ms-office-rce-vuln-called-thebenygreen-
    - https://github.com/embedi/CVE-2017-11882
author: Florian Roth (Nextron Systems)
date: 2017-11-23
modified: 2021-11-27
tags:
    - attack.execution
    - attack.t1203
    - attack.t1204.002
    - attack.initial-access
    - attack.t1566.001
    - cve.2017-11882
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith: '\EQNEDT32.EXE'
    condition: selection
falsepositives:
    - Unknown
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unknown

title: Exploit for CVE-2015-1641
id: 7993792c-5ce2-4475-a3db-a3a5539827ef
status: stable
description: Detects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641
references:
    - https://www.virustotal.com/en/file/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8/analysis/
    - https://www.hybrid-analysis.com/sample/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8?environmentId=100
author: Florian Roth (Nextron Systems)
date: 2018-02-22
modified: 2021-11-27
tags:
    - attack.stealth
    - attack.t1036.005
    - cve.2015-1641
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith: '\WINWORD.EXE'
        Image|endswith: '\MicroScMgmt.exe'
    condition: selection
falsepositives:
    - Unknown
level: critical
View this rule on SigmaHQ ↗
Author: Vasiliy Burov, oscd.community

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: LockerGoga Ransomware Activity
id: 74db3488-fd28-480a-95aa-b7af626de068
status: stable
description: Detects LockerGoga ransomware activity via specific command line.
references:
    - https://medium.com/@malwaredancer/lockergoga-input-arguments-ipc-communication-and-others-bd4e5a7ba80a
    - https://blog.f-secure.com/analysis-of-lockergoga-ransomware/
    - https://www.carbonblack.com/blog/tau-threat-intelligence-notification-lockergoga-ransomware/
author: Vasiliy Burov, oscd.community
date: 2020-10-18
modified: 2023-02-03
tags:
    - attack.impact
    - attack.t1486
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains: '-i SM-tgytutrc -s'
    condition: selection
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unlikely

title: Potential Dridex Activity
id: e6eb5a96-9e6f-4a18-9cdd-642cfda21c8e
status: stable
description: Detects potential Dridex acitvity via specific process patterns
references:
    - https://app.any.run/tasks/993daa5e-112a-4ff6-8b5a-edbcec7c7ba3
    - https://redcanary.com/threat-detection-report/threats/dridex/
author: Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)
date: 2019-01-10
modified: 2023-02-03
tags:
    - attack.privilege-escalation
    - attack.stealth
    - attack.t1055
    - attack.discovery
    - attack.t1135
    - attack.t1033
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_svchost:
        Image|endswith: '\svchost.exe'
        CommandLine|contains|all:
            - 'C:\Users\'
            - '\Desktop\'
    filter_svchost:
        ParentImage|startswith: 'C:\Windows\System32\'
    selection_regsvr:
        ParentImage|endswith: '\excel.exe'
        Image|endswith: '\regsvr32.exe'
        CommandLine|contains:
            - ' -s '
            - '\AppData\Local\Temp\'
    filter_regsvr:
        CommandLine|contains: '.dll'
    selection_anomaly_parent:
        ParentImage|endswith: '\svchost.exe'
    selection_anomaly_child_1:
        Image|endswith: '\whoami.exe'
        CommandLine|contains: ' /all'
    selection_anomaly_child_2:
        Image|endswith:
            - '\net.exe'
            - '\net1.exe'
        CommandLine|contains: ' view'
    condition: (selection_svchost and not filter_svchost) or (selection_regsvr and not filter_regsvr) or (selection_anomaly_parent and 1 of selection_anomaly_child_*)
falsepositives:
    - Unlikely
level: critical
View this rule on SigmaHQ ↗
Author: Thomas Patzke

Detection prerequisites: Log source: proxy

False positives: Unknown

title: Ursnif Malware C2 URL Pattern
id: 932ac737-33ca-4afd-9869-0d48b391fcc9
status: stable
description: Detects Ursnif C2 traffic.
references:
    - https://www.fortinet.com/blog/threat-research/ursnif-variant-spreading-word-document.html
author: Thomas Patzke
date: 2019-12-19
modified: 2021-08-09
tags:
    - attack.initial-access
    - attack.t1566.001
    - attack.execution
    - attack.t1204.002
    - attack.command-and-control
    - attack.t1071.001
    - detection.emerging-threats
logsource:
    category: proxy
detection:
    b64encoding:
        c-uri|contains:
            - '_2f'
            - '_2b'
    urlpatterns:
        c-uri|contains|all:
            - '.avi'
            - '/images/'
    condition: b64encoding and urlpatterns
falsepositives:
    - Unknown
level: critical
View this rule on SigmaHQ ↗
Author: Sittikorn S

Detection prerequisites: Platform: aws · Service: cloudtrail

False positives: System or Network administrator behaviors; DEV, UAT, SAT environment. You should apply this rule with PROD environment only.

title: AWS SecurityHub Findings Evasion
id: a607e1fe-74bf-4440-a3ec-b059b9103157
status: stable
description: Detects the modification of the findings on SecurityHub.
references:
    - https://docs.aws.amazon.com/cli/latest/reference/securityhub/
author: Sittikorn S
date: 2021-06-28
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    product: aws
    service: cloudtrail
detection:
    selection:
        eventSource: securityhub.amazonaws.com
        eventName:
            - 'BatchUpdateFindings'
            - 'DeleteInsight'
            - 'UpdateFindings'
            - 'UpdateInsight'
    condition: selection
falsepositives:
    - System or Network administrator behaviors
    - DEV, UAT, SAT environment. You should apply this rule with PROD environment only.
level: high
View this rule on SigmaHQ ↗
Author: Thomas Patzke

Detection prerequisites: Platform: windows · Log source: process_creation

False positives: Unknown

title: HackTool - CrackMapExec Execution Patterns
id: 058f4380-962d-40a5-afce-50207d36d7e2
status: stable
description: Detects various execution patterns of the CrackMapExec pentesting framework
references:
    - https://github.com/byt3bl33d3r/CrackMapExec
author: Thomas Patzke
date: 2020-05-22
modified: 2023-11-06
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.execution
    - attack.t1047
    - attack.t1053
    - attack.t1059.003
    - attack.t1059.001
    - attack.s0106
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            # cme/protocols/smb/wmiexec.py (generalized execute_remote and execute_fileless)
            - 'cmd.exe /Q /c * 1> \\\\*\\*\\* 2>&1'
            # cme/protocols/smb/atexec.py:109 (fileless output via share)
            - 'cmd.exe /C * > \\\\*\\*\\* 2>&1'
            # cme/protocols/smb/atexec.py:111 (fileless output via share)
            - 'cmd.exe /C * > *\\Temp\\* 2>&1'
            # https://github.com/byt3bl33d3r/CrackMapExec/blob/d8c50c8cbaf36c29329078662473f75e440978d2/cme/helpers/powershell.py#L136 (PowerShell execution with obfuscation)
            - 'powershell.exe -exec bypass -noni -nop -w 1 -C "'
            # https://github.com/byt3bl33d3r/CrackMapExec/blob/d8c50c8cbaf36c29329078662473f75e440978d2/cme/helpers/powershell.py#L160 (PowerShell execution without obfuscation)
            - 'powershell.exe -noni -nop -w 1 -enc '
    condition: selection
falsepositives:
    - Unknown
level: high
View this rule on SigmaHQ ↗
View all detecting rules on SigmaHQ →

Detection rules licensed under Detection Rule License (DRL) 1.1, from SigmaHQ. Each rule retains its author.

Validation tests

Atomic Red Team validating tests mapped to this group's MITRE ATT&CK techniques, shown beside the detection rules so you can validate the detections. This shows the top few, with a link to the full set on GitHub. Descriptive metadata only, never the attack commands.

Validating tests for INC RansomShowing 8 of 205
Platforms: linux

This test uses LDAPDomainDump to perform account enumeration on a domain. [Reference](https://securityonline.info/ldapdomaindump-active-directory-information-dumper-via-ldap/)

View this test on GitHub ↗
Platforms: linux

Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory

View this test on GitHub ↗
Platforms: linux

Output information from LDAPSearch. LDAP Password is the admin-user password on Active Directory

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Admin accounts reference- http://www.joeware.net/freetools/tools/adfind/, https://stealthbits.com/blog/fun-with-active-directorys-admincount-attribute/

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Exchange Objects reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory User Objects reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. This example has been documented by ransomware actors enumerating Active Directory Groups reference- http://www.joeware.net/freetools/tools/adfind/, https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

View this test on GitHub ↗
Platforms: windows

Adfind tool can be used for reconnaissance in an Active directory environment. The example chosen illustrates adfind used to query the local password policy. reference- http://www.joeware.net/freetools/tools/adfind/, https://social.technet.microsoft.com/wiki/contents/articles/7535.adfind-command-examples.aspx

View this test on GitHub ↗
View all validating tests on GitHub →

Atomic tests from Atomic Red Team, (c) Red Canary, MIT License. Not affiliated with or endorsed by Red Canary.

Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).

Glossary