THREAT_ACTOR · G1032
INC Ransom
Also known as: INC Ransom, GOLD IONIC
Profile
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.
MITRE ATT&CK ↗Techniques
25 ATT&CK techniques attributed to this actor.
T1021.001 Remote Desktop ProtocolT1036.005 Match Legitimate Resource Name or LocationT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1059.003 Windows Command ShellT1069.002 Domain GroupsT1070.004 File DeletionT1071 Application Layer ProtocolT1074 Data StagedT1078 Valid AccountsT1087.002 Domain AccountT1105 Ingress Tool TransferT1135 Network Share DiscoveryT1190 Exploit Public-Facing ApplicationT1219 Remote Access ToolsT1486 Data Encrypted for ImpactT1537 Transfer Data to Cloud AccountT1560.001 Archive via UtilityT1566 PhishingT1569.002 Service ExecutionT1570 Lateral Tool TransferT1588.002 ToolT1657 Financial TheftT1685 Disable or Modify Tools
Software
8 malware/tools attributed to this actor.
PsExecNetTorNltestesentutlAdFindRcloneINC Ransomware
Related corpus activity
9,656 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to INC Ransom.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
Showing the top 30 by severity of 9,656.