Also known as: GOLD IONIC
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Executive Summary
INC Ransom (also known as GOLD IONIC) is a ransomware and data‑extortion group active since at least July 2023. The group has focused on industrial, healthcare, and education organizations across the United States and Europe, employing double‑extortion tactics to pressure victims into paying. Their operations show a moderate level of sophistication, leveraging common ransomware toolsets and credential‑stealing techniques.
Goals & Targeting
INC Ransom’s strategic objective is financial gain through ransomware encryption combined with data extortion. By focusing on industrial, healthcare, and education sectors, the group exploits organizations that maintain critical operations, possess valuable proprietary data, and often have limited cyber‑resilience budgets. Their typical victims are mid‑size to large enterprises that store patient records, manufacturing designs, or research data, making the threat of public exposure a powerful lever for ransom negotiations. The geographic focus on the US and Europe aligns with higher average ransom payouts and robust legal frameworks that increase the perceived value of the stolen data.
Enhanced Description
INC Ransom, identified in open‑source reports as early as July 2023, is a ransomware‑as‑a‑service (RaaS) operation that delivers the eponymous INC Ransomware payload. The group’s activity has been documented by multiple security vendors, including Bleeping Computer, Cybereason, Secureworks, and SentinelOne. Victims span a broad geographic footprint, with a concentration in the United States and Europe, and the primary sectors targeted are industrial manufacturing, healthcare delivery, and higher‑education institutions. The ransomware encrypts victim files and appends a distinctive ".inc" extension, while simultaneously exfiltrating sensitive data for public‑release threats. This double‑extortion model mirrors the tactics of other contemporary ransomware families, leveraging both encryption impact and reputational damage to increase ransom yields. The group typically distributes its payload via spear‑phishing emails, compromised remote‑access services, and exploitation of unpatched vulnerabilities in publicly‑facing applications. Operationally, INC Ransom appears to use a blend of off‑the‑shelf tools (e.g., Cobalt Strike, Mimikatz) and custom scripts, often employing PowerShell for execution and lateral movement. Ransom notes are delivered in plain‑text files named "README_INC.txt" and reference a leak site where stolen data will be published if the ransom is not met. The group’s ransom demands have ranged from tens of thousands to several hundred thousand US dollars, reflecting the high‑value nature of the targeted sectors. While the precise leadership and funding structure remain unknown, the group’s consistent targeting of critical infrastructure and public‑sector entities suggests a profit‑driven motivation with an awareness of the geopolitical impact of disrupting essential services. Continued monitoring of their infrastructure and tactics is essential for organizations operating in the affected sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its emergence in mid‑2023, INC Ransom has conducted multiple campaigns that follow a predictable kill‑chain: initial access via spear‑phishing or compromised VPN, deployment of PowerShell loaders, credential harvesting, lateral movement across internal networks, data staging, and final encryption coupled with data theft. The group tends to operate on a medium tempo, often compromising several organizations within a quarter before rotating its infrastructure. Notable incidents include a July 2023 attack on a European medical device manufacturer that resulted in a $250,000 ransom, and a November 2023 compromise of a US university network where over 2 TB of research data were exfiltrated and threatened for public release.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attributes of INC Ransom (name, aliases, sector focus, and double‑extortion model) is high, supported by multiple vendor reports. However, gaps remain regarding the group’s internal hierarchy, exact funding sources, and the full list of custom tools they may employ. Additional open‑source or law‑enforcement intelligence would be needed to refine attribution and to confirm the presence of any nation‑state sponsorship.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
25
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
11
Tactics