SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

inc ransom

💰 eCrimeMotivation: financialLast active: 2026-09-25First seen: 2024-06-06G1032 ↗
1
linked CVEs
Also known as
GOLD IONICincransom
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationEnergyFinancial ServicesHealthcareManufacturingNot FoundPublic SectorTechnologyTelecommunicationTransportation/Logistics
Targeted regions
AEARATAUBRBSCACZDEESFRGBINITMXROSASESGSITRTWUS
[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Source: misp_galaxy · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits1 CVE
threat_actor_cve → cves / exploits.cve_ids
CVE-2024-40766
suspected

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS 9.8
KEVransomware
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used25 techniques
Across 13 tactics
Discovery5 techniques
🛰️ Infrastructure & IOCs3
sha256fc39cca5d71b1a9ed3c71cca6f1b86cfe03466624ad78cdb57580dba90847851—2024-05-01
sha25636eb4290aa11a950e60d12ab18a8e139d25464355ce761f98891e1ea94f39445—2024-05-01
sha256accd8bc0d0c2675c15c169688b882ded17e78aed0d914793098337afc57c289c—2023-08-11
📰 Threat Intel Coverage3
Digest reports mentioning this actor (incl. aliases)
Nowhere, man: The 2026 Active Adversary Reportmatched as Gold Ionic2026-02-24
LOLBin to INC Ransomware | Huntressmatched as INC Ransom2024-05-01
Investigating New INC Ransom Group Activity | Huntressmatched as INC Ransom2023-08-11