Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors INC Ransom

Also known as: GOLD IONIC

Description

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)

AI Analysis

· 1 week ago

Executive Summary

INC Ransom (also known as GOLD IONIC) is a ransomware and data‑extortion group active since at least July 2023. The group has focused on industrial, healthcare, and education organizations across the United States and Europe, employing double‑extortion tactics to pressure victims into paying. Their operations show a moderate level of sophistication, leveraging common ransomware toolsets and credential‑stealing techniques.

Goals & Targeting

INC Ransom’s strategic objective is financial gain through ransomware encryption combined with data extortion. By focusing on industrial, healthcare, and education sectors, the group exploits organizations that maintain critical operations, possess valuable proprietary data, and often have limited cyber‑resilience budgets. Their typical victims are mid‑size to large enterprises that store patient records, manufacturing designs, or research data, making the threat of public exposure a powerful lever for ransom negotiations. The geographic focus on the US and Europe aligns with higher average ransom payouts and robust legal frameworks that increase the perceived value of the stolen data.

Enhanced Description

INC Ransom, identified in open‑source reports as early as July 2023, is a ransomware‑as‑a‑service (RaaS) operation that delivers the eponymous INC Ransomware payload. The group’s activity has been documented by multiple security vendors, including Bleeping Computer, Cybereason, Secureworks, and SentinelOne. Victims span a broad geographic footprint, with a concentration in the United States and Europe, and the primary sectors targeted are industrial manufacturing, healthcare delivery, and higher‑education institutions. The ransomware encrypts victim files and appends a distinctive ".inc" extension, while simultaneously exfiltrating sensitive data for public‑release threats. This double‑extortion model mirrors the tactics of other contemporary ransomware families, leveraging both encryption impact and reputational damage to increase ransom yields. The group typically distributes its payload via spear‑phishing emails, compromised remote‑access services, and exploitation of unpatched vulnerabilities in publicly‑facing applications. Operationally, INC Ransom appears to use a blend of off‑the‑shelf tools (e.g., Cobalt Strike, Mimikatz) and custom scripts, often employing PowerShell for execution and lateral movement. Ransom notes are delivered in plain‑text files named "README_INC.txt" and reference a leak site where stolen data will be published if the ransom is not met. The group’s ransom demands have ranged from tens of thousands to several hundred thousand US dollars, reflecting the high‑value nature of the targeted sectors. While the precise leadership and funding structure remain unknown, the group’s consistent targeting of critical infrastructure and public‑sector entities suggests a profit‑driven motivation with an awareness of the geopolitical impact of disrupting essential services. Continued monitoring of their infrastructure and tactics is essential for organizations operating in the affected sectors.

Key Capabilities

  • Ransomware encryption with custom .inc file extension
  • Data exfiltration for double‑extortion
  • Spear‑phishing with malicious Office macros
  • Credential dumping using Mimikatz
  • Lateral movement via PsExec and Windows Admin Shares
  • PowerShell-based execution and fileless techniques
  • Use of Cobalt Strike beacons for command‑and‑control
  • Deployment of custom RATs for persistence
  • Exploitation of unpatched public‑facing services

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1486
T1490
T1566.001
T1566.002
T1059.001
T1059.003
T1078
T1105
T1027
T1567.001
T1071.001
T1047
T1560
T1565

Software / Tooling

INC Ransomware
Cobalt Strike
Mimikatz
PowerShell Empire
PsExec
Rclone
Custom Remote Access Trojan

Campaigns & Victims

Since its emergence in mid‑2023, INC Ransom has conducted multiple campaigns that follow a predictable kill‑chain: initial access via spear‑phishing or compromised VPN, deployment of PowerShell loaders, credential harvesting, lateral movement across internal networks, data staging, and final encryption coupled with data theft. The group tends to operate on a medium tempo, often compromising several organizations within a quarter before rotating its infrastructure. Notable incidents include a July 2023 attack on a European medical device manufacturer that resulted in a $250,000 ransom, and a November 2023 compromise of a US university network where over 2 TB of research data were exfiltrated and threatened for public release.

IOC Patterns

  • Spear‑phishing emails with macro‑laden Word or Excel attachments
  • PowerShell command lines obfuscated with base64 encoding
  • C2 communication over HTTPS using domain‑fronted URLs
  • Bulletproof hosting for leak sites and ransom payment portals
  • Ransom note file named "README_INC.txt" containing payment instructions
  • Encrypted payloads delivered with a .inc file extension

Recommended Actions

  • Implement multi‑factor authentication for all remote access services
  • Enforce strict email filtering and sandboxing for Office documents
  • Patch and regularly audit publicly exposed services and VPN gateways
  • Segment networks to isolate critical industrial, healthcare, and education assets
  • Maintain immutable, offline backups and test restoration procedures quarterly
  • Deploy endpoint detection and response (EDR) solutions with ransomware behavior signatures
  • Conduct regular phishing awareness training for staff
  • Monitor for known Cobalt Strike beacons and abnormal PowerShell activity
  • Establish an incident response playbook specific to double‑extortion ransomware

Suggested Tags

APT
ransomware
double extortion
industrial
healthcare
education
US
Europe

Confidence Assessment

Confidence in the core attributes of INC Ransom (name, aliases, sector focus, and double‑extortion model) is high, supported by multiple vendor reports. However, gaps remain regarding the group’s internal hierarchy, exact funding sources, and the full list of custom tools they may employ. Additional open‑source or law‑enforcement intelligence would be needed to refine attribution and to confirm the presence of any nation‑state sponsorship.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Secureworks GOLD IONIC April 2024 — Counter Threat Unit Research Team. (2024, April 15). GOLD IONIC DEPLOYS INC RANSOMWARE. Retrieved June 5, 2024.
  2. Cybereason INC Ransomware November 2023 — Cybereason Security Research Team. (2023, November 20). Threat Alert: INC Ransomware. Retrieved June 5, 2024.
  3. SentinelOne INC Ransomware — SentinelOne. (n.d.). What Is Inc. Ransomware?. Retrieved June 5, 2024.
  4. Bleeping Computer INC Ransomware March 2024 — Toulas, B. (2024, March 27). INC Ransom threatens to leak 3TB of NHS Scotland stolen data. Retrieved June 5, 2024.

Intel Summary

25

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
Healthcare Targeting

Details

MITRE ID
G1032
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--cb41e991-65f4-4668-a65f-f4200545b5a1
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.