created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false
INC Ransom
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1032 |
| Aliases | GOLD IONIC |
| Attribution | Not stated by MITRE ATT&CK |
| Class | ecrime |
| Active since | — |
| ATT&CK entry created | 2024-06-06 |
| Techniques mapped | 33 |
Attribution — as claimed
Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.
Known TTPs
| Technique | Name |
|---|---|
T1021.001 |
Remote Desktop Protocol |
T1036.005 |
Match Legitimate Resource Name or Location |
T1046 |
Network Service Discovery |
T1047 |
Windows Management Instrumentation |
T1049 |
System Network Connections Discovery |
T1059.003 |
Windows Command Shell |
T1069.002 |
Domain Groups |
T1070.004 |
File Deletion |
T1071 |
Application Layer Protocol |
T1074 |
Data Staged |
T1078 |
Valid Accounts |
T1087.002 |
Domain Account |
(First 12 of 33 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Silence — similarly attributed-linked actor, same attribution class
- Lapsus — similarly attributed-linked actor, same attribution class
- Scattered Spider — similarly attributed-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1032 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.