SophiaX
🔍
LIVE
· New victim: Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· New victim: 3,979 new IOCs ingested in last 24h Portable Intelligence Inc www.portable-intelligence.com serviced by an IT company Computer... — blacknevas· New victim: Riker Danzig Scherer Hyland & Perretti — SilentRansomGroup· New victim: Hightech Signs — kairos· New victim: Riker Danzig LLP — SilentRansomGroup· New victim: gamaus.com — incransom· New KEV: CVE-2026-72898 · Metabase· New KEV: CVE-2026-20349 · Cisco· New KEV: CVE-2026-68820 · Microsoft· New KEV: CVE-2026-8037 · Progress· New KEV: CVE-2026-63077 · JetBrains· 3,979 new IOCs ingested in last 24h

inc ransom

💰 eCrimeMotivation: financialLast active: 2026-08-08First seen: 2024-06-06G1032
1
linked CVEs
Also known as
GOLD IONICincransom
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationEnergyFinancial ServicesHealthcareManufacturingNot FoundPublic SectorTechnologyTelecommunicationTransportation/Logistics
Targeted regions
AEARATAUBRBSCACZDEESFRGBINITMXROSASESGSITRTWUS
[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Source: misp_galaxy · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits1 CVE
threat_actor_cve → cves / exploits.cve_ids
CVE-2024-40766
suspected

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

KEVransomware
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used25 techniques
Across 13 tactics
Discovery5 techniques
🛰️ Infrastructure & IOCs3
sha25636eb4290aa11a950e60d12ab18a8e139d25464355ce761f98891e1ea94f394452024-05-01
sha256fc39cca5d71b1a9ed3c71cca6f1b86cfe03466624ad78cdb57580dba908478512024-05-01
sha256accd8bc0d0c2675c15c169688b882ded17e78aed0d914793098337afc57c289c2023-08-11
📰 Threat Intel Coverage3
Digest reports mentioning this actor (incl. aliases)
Nowhere, man: The 2026 Active Adversary Reportmatched as Gold Ionic2026-02-24
LOLBin to INC Ransomware | Huntressmatched as INC Ransom2024-05-01
Investigating New INC Ransom Group Activity | Huntressmatched as INC Ransom2023-08-11