🌐INC Ransom
🌐 INC Ransom is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 22 detection use cases to this actor across 35 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-05-18 to 2026-05-18.
crit 1
22Use cases
1Articles
35Techniques
0IOCs
Known aliases
INC ransomwareINC RansomINC GroupGOLD IONIC
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1059.003 · Windows Command ShellT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1074 · Data StagedT1078 · Valid AccountsT1087.002 · Domain AccountT1105 · Ingress Tool TransferT1133 · External Remote ServicesT1135 · Network Share DiscoveryT1219 · Remote Access ToolsT1486 · Data Encrypted for ImpactT1537 · Transfer Data to Cloud AccountT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1560.001 · Archive via UtilityT1566 · PhishingT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1588.002 · ToolT1657 · Financial TheftT1685 · Disable or Modify Tools
Detection use cases (22)
INC Ransom data staging + MEGAsync/rclone cloud exfiltration chain INC Ransom hands-on-keyboard credential access: comsvcs.dll LSASS mini-dump + AdFind/netscan recon chain Cisco Secure FMC anomalous outbound HTTP PUT (Interlock CVE-2026-20131 callback) Crypto-wallet file/keystore access by non-wallet process Infostealer — non-browser process accessing browser cookie/login DBs Asset exposure — vulnerability matches article CVE(s) Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual children 1Password impossible-travel sign-in 1Password vault export attempted Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Service-process parent spawns subprocess containing CLI-argument-injection tokens Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Atlassian administrator impersonating userThreat-intel articles (1)
Tracked indicators
CVEs (1)
CVE-2026-20131