🌐INC Ransom
🌐 INC Ransom is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 24 detection use cases to this actor across 40 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-08-10 to 2026-08-11.
crit 1high 1
24Use cases
2Articles
40Techniques
12IOCs
Known aliases
INC ransomwareINC RansomINC GroupGOLD IONIC
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1074 · Data StagedT1078 · Valid AccountsT1087.002 · Domain AccountT1105 · Ingress Tool TransferT1135 · Network Share DiscoveryT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1486 · Data Encrypted for ImpactT1537 · Transfer Data to Cloud AccountT1539 · Steal Web Session CookieT1555.003 · Credentials from Web BrowsersT1560.001 · Archive via UtilityT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1588.002 · ToolT1657 · Financial TheftT1685 · Disable or Modify Tools
Detection use cases (24)
Infostealer — non-browser process accessing browser cookie/login DBs Phishing-link click correlated to endpoint execution Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) PowerShell encoded / obfuscated command Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Network connections to article IPs / domains Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process 1Password impossible-travel sign-in 1Password vault export attempted Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Service-process parent spawns subprocess containing CLI-argument-injection tokensThreat-intel articles (2)
Tracked indicators
Domains (11)
1rpc.io deadblogdbdu5wprek7wa2o4 deadlock.liveblog365.com deadlockblog.great-site. deadlockblog.medianewson dlock.liveblog365.com polygon-bor-rpc.publicno polygon-pokt.nodies.app polygon-rpc.com polygon.drpc.org polygon.meowrpc.comIP addresses (1)
138.226.236.51