Ransomware Group intelligence
Incransom
ActiveTrack Incransom with 1013 published victims and 7 known leak locations in a single intelligence view.
Overview
Incransom is tracked by Breach House as a ransomware group with 1013 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 7 | Onion service | Up checked 1h ago | incbacg6bfwtrlzwdbqc55gsfl763s3twdtwhp27dzuik6s6rwdcityd.onion |
| Leak location 6 | Onion service | Up checked 1h ago | incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion |
| Leak location 2 | Onion service | Down checked 1h ago | incbackrlasjesgpfu5brktfjknbqoahe2hhmqfhasc5fb56mtukn4yd.onion |
| Leak location 5 | Web location | Down checked 1h ago | incapt.su |
| Leak location 4 | Web location | Down checked 1h ago | incapt.blog |
| Leak location 1 | Onion service | Down checked 1h ago | incblog7vmuq7rktic73r4ha4j757m3ptym37tyvifzp2roedyyzzxid.onion |
| Leak location 3 | Web location | Down checked 1h ago | incbackend.top |
Top Activity Sectors (18)
- Communication / Marketing 173
- Healthcare / Pharma 112
- Finance / Legal / Insurance 110
- Services 73
- Manufacturing / Engineering 69
- Education 56
- Not identified 54
- Construction / Real Estate 53
- Public Sector 44
- IT 39
- Retail / E-commerce 27
- NGOs / Associations 24
- Transportation / Travel / Logistics 22
- Energy 21
- Hospitality / Food & Beverage / Tourism 16
- Agriculture / Food 13
- Telecommunications 11
- null 1
Typical Attacks (35)
▼How Incransom typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via INC Ransom, INC Ransomware.
-
T1588.002 Tool Resource Development
What they do: INC Ransom has acquired and used several tools including MegaSync, AnyDesk, esentutl and PsExec.
What that means: Adversaries may buy, steal, or download software tools that can be used during targeting.
-
What they do: INC Ransom has used compromised valid accounts for access to victim environments.
What that means: Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
T1190 Exploit Public-Facing Application Initial Access
What they do: INC Ransom has exploited known vulnerabilities including CVE-2023-3519 in Citrix NetScaler for initial access.
What that means: Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
-
T1566 Phishing Initial Access
What they do: INC Ransom has used phishing to gain initial access.
What that means: Adversaries may send phishing messages to gain access to victim systems.
-
T1047 Windows Management Instrumentation Execution
What they do: INC Ransom has used WMIC to deploy ransomware.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.003 Windows Command Shell Execution
What they do: INC Ransom has used `cmd.exe` to launch malicious payloads.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: INC Ransomware can use the API `DeviceIoControl` to resize the allocated space for and cause the deletion of volume shadow copy snapshots.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: INC Ransom has run a file encryption executable via `Service Control Manager/7045;winupd,%SystemRoot%\winupd.exe,user mode service,demand start,LocalSystem`.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: INC Ransom has uninstalled tools from compromised endpoints after use.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: INC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: INC Ransom can use SystemSettingsAdminFlows.exe, a native Windows utility, to disable Windows Defender.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1046 Network Service Discovery Discovery
What they do: INC Ransom has used NETSCAN.EXE for internal reconnaissance.
What that means: Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
-
T1049 System Network Connections Discovery Discovery
What they do: INC Ransom has used RDP to test network connections.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1069.002 Domain Groups Discovery
What they do: INC Ransom has enumerated domain groups on targeted hosts.
What that means: Adversaries may attempt to find domain-level groups and permission settings.
-
T1083 File and Directory Discovery Discovery
What they do: INC Ransomware can receive command line arguments to encrypt specific files and directories.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1087.002 Domain Account Discovery
What they do: INC Ransom has scanned for domain admin accounts in compromised environments.
What that means: Adversaries may attempt to get a listing of domain accounts.
-
T1120 Peripheral Device Discovery Discovery
What they do: INC Ransomware can identify external USB and hard drives for encryption and printers to print ransom notes.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: INC Ransom has used Internet Explorer to view folders on other systems.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1652 Device Driver Discovery Discovery
What they do: INC Ransomware can verify the presence of specific drivers on compromised hosts including Microsoft Print to PDF and Microsoft XPS Document Writer.
What that means: Adversaries may attempt to enumerate local device drivers on a victim host.
-
T1680 Local Storage Discovery Discovery
What they do: INC Ransomware can discover and mount hidden drives to encrypt them.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.001 Remote Desktop Protocol Lateral Movement
What they do: INC Ransom has used RDP to move laterally.
What that means: Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: INC Ransom has used a rapid succession of copy commands to install a file encryption executable across multiple endpoints within compromised infrastructure.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1074 Data Staged Collection
What they do: INC Ransom has staged data on compromised hosts prior to exfiltration.
What that means: Adversaries may stage collected data in a central location or directory prior to Exfiltration.
-
T1560.001 Archive via Utility Collection
What they do: INC Ransom has used 7-Zip and WinRAR to archive collected data prior to exfiltration.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1071 Application Layer Protocol Command and Control
What they do: INC Ransom has used valid accounts over RDP to connect to targeted systems.
What that means: Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
-
T1105 Ingress Tool Transfer Command and Control
What they do: INC Ransom has downloaded tools to compromised servers including Advanced IP Scanner.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1219 Remote Access Tools Command and Control
What they do: INC Ransom has used AnyDesk and PuTTY on compromised systems.
What that means: An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
-
T1537 Transfer Data to Cloud Account Exfiltration
What they do: INC Ransom has used Megasync to exfiltrate data to the cloud.
What that means: Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
-
T1486 Data Encrypted for Impact Impact
What they do: INC Ransom has used INC Ransomware to encrypt victim's data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: INC Ransomware can issue a command to kill a process on compromised hosts.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: INC Ransomware can delete volume shadow copy backups from victim machines.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: INC Ransomware has the ability to change the background wallpaper image to display the ransom note.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
-
T1657 Financial Theft Impact
What they do: INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.
What that means: Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims.
Tools Observed (9)
▼Software Incransom has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Victims (1013)
Search, filter and paginate the victim timeline for Incransom. Showing 1001–1013 of 1013.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ENTRUST Solutions Group id8702 View details | Services | |||
|
ENTRUST Solutions Group is a community of people, 3,100+ strong, who are committed to our clients and each other. We are diverse, talented, dedicated, and wholly focused on not only meeting the needs... |
|||||
| Ransomware | Federal Labor Relations Authority id8701 View details | United States | Public Sector | ||
|
The Federal Labor Relations Authority (FLRA) is an independent agency of the United States government that governs labor relations between the federal government and its employees. |
|||||
| Ransomware | Leoch Battery id8700 View details | Energy | |||
|
LEOCH Battery is a China-based energy company founded in 1999 and headquartered in Anhui Province, with operations focused on advanced battery power and energy management solutions. Its portfolio includes lead-acid batteries, lithium energy storage systems, backup power supplies, automotive start-stop batteries, and motive power products for industrial, commercial, residential, grid-side, and renewable energy uses. The company describes itself as a global leader in energy storage and battery manufacturing, serving a broad range of power applications. It was listed as a ransomware victim associated with incransom. |
|||||
| Ransomware | Leoch Battery Corp id22320 View details | Energy | |||
|
Products Lithium Battery Lithium solutions are mainly used in network power, green energy storage and transportation with high energy density, exceptional performance, and long life. Leoch has a... |
|||||
| Ransomware | Elemetal id8677 View details | Manufacturing / Engineering | |||
|
Elemetal is one of the largest precious metals refiner. They are laundering money for drug cartel and can't find a small amount to prevent data leak. Cost of their privacy is $160.000. 600GB of... |
|||||
| Ransomware | ************ id8675 View details | Communication / Marketing | |||
|
************ one of the largest precious metals refiner. they are laundering money for drug cartel and can't find a small amount to prevent data leak. we will name company on Friday if there will be... |
|||||
| Ransomware | Abbeyfield id8598 View details | Construction / Real Estate | |||
|
It's our mission to provide the best service of care and housing for all our residents, and to be a champion for older people. |
|||||
| Ransomware | I Keating Furniture World id8521 View details | Retail / E-commerce | |||
|
I. Keating Furniture World is a family owned Furniture & Mattresses store located in Minot, ND. |
|||||
| Ransomware | It4 Solutions Robras id8517 View details | United States | Services | ||
|
It4 Solutions Robras Corp is a company that operates in the Information Technology and Services industry. |
|||||
| Ransomware | Arkopharma id8453 View details | Healthcare / Pharma | |||
|
Arkopharma in brief Arkopharma is a pharmaceutical laboratory specialised in the area of phytotherapy, natural medicine and dietary supplements. |
|||||
| Ransomware | Pifer's Auction & Realty id8398 View details | Construction / Real Estate | |||
|
Pifer's Auction & Realty is a full service auction and real estate firm specializing in land auctions, machinery auctions, and land management. |
|||||
| Ransomware | Hemmink id8150 View details | Other | |||
|
say hello martin! you have very bad it specialists |
|||||
| Ransomware | Thermenhotel Stoiser id8105 View details | Hospitality / Food & Beverage / Tourism | |||
|
ENJOY! |
|||||