INC
❔ UnknownLast active: 2026-09-22First seen: 2026-09-21
0
linked CVEs
In late August, an organization was compromised by INC ransomware across at least 175 endpoints. The attack timeline spanned from early to late August with a 17-day gap, suggesting involvement of an initial access broker and a separate ransomware affiliate. Early August activity included scheduled tasks with randomized names and lateral movement via RDP using a compromised account. After the lull, attackers deployed AnyDesk for remote access, used Bring Your Own Vulnerable Driver tactics to disable security controls, and executed ransomware via Impacket tools. Uniquely, two ransom notes were discovered: the standard INC-README.txt and a subsequent DATALEAK_PRESS_RELEASE.txt containing detailed stolen file listings, threatening to contact media, employees, and partners within 48 hours to increase pressure on victims.
Source: otx · Collected: 2026-09-24
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs2
| domain | throughoutes.net | — | 2026-09-22 |
| ip | 213.111.185.108 | — | 2026-09-22 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.