INC Ransom
G10326 reportsaliases · INC Ransom · GOLD IONIC
6
Reports
12
Techniques
7
Tactics
7
Countries
32%
Hunt coverage
2
Aliases
Analyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1588.006 (Vulnerabilities), T1588.007 (Artificial Intelligence).
- Primary targeting: US, BR, CA, AR.
- Activity declining: 1 report(s) in last 30d vs 3 prior (-67%).
- Recent movement: 28 new technique(s), 3 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 32% of 38 observed techniques (26 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DecliningLast 30d: 1 vs 3 prior (-67%)· first reported 2026-07-06 · last 2026-09-15
1
7d
1
30d
6
90d
6
All
0.5
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1587.001T1087.001T1530T1082T1190T1552T1611T1021T1136.001T1595T1059T1552.001Targeting lost
ARBRCAMXUSNew infrastructure
e78393397@proton.me45.131.66.10664.20.53.230Vulnerabilities in this actor's reporting · 2
- CVE-2025-3248KEV1 rpt
- CVE-2026-24858KEV1 rpt
Overview
Analyst triage
Intelligence summary
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1589.001 · Credentialsconf 655
- T1588.006 · Vulnerabilitiesconf 654
- T1588.007 · Artificial Intelligenceconf 601
- T1556.006 · Multi-Factor Authenticationconf 601
- T1684.001 · Impersonationconf 601
- AML.T0073 · Impersonationconf 601
- T1590.005 · IP Addressesconf 601
- T1684 · Social Engineeringconf 601
- T1584.008 · Network Devicesconf 601
- T1491 · Defacementconf 601
- T1587.001 · Malwareconf 601
- T1087.001 · Local Accountconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|