Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [ransomware-group, supply-chain] · confidence: medium · affected_sectors: [] · au_impact: false

INC Ransom

INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.

Attribute Detail
ATT&CK ID G1032
Aliases GOLD IONIC
Attribution Not stated by MITRE ATT&CK
Class ecrime
Active since
ATT&CK entry created 2024-06-06
Techniques mapped 33

Attribution — as claimed

Not state-attributed; the activity is self-declared (public extortion/leak-site claims) or attributed to criminal reporting.

Known TTPs

Technique Name
T1021.001 Remote Desktop Protocol
T1036.005 Match Legitimate Resource Name or Location
T1046 Network Service Discovery
T1047 Windows Management Instrumentation
T1049 System Network Connections Discovery
T1059.003 Windows Command Shell
T1069.002 Domain Groups
T1070.004 File Deletion
T1071 Application Layer Protocol
T1074 Data Staged
T1078 Valid Accounts
T1087.002 Domain Account

(First 12 of 33 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Silence — similarly attributed-linked actor, same attribution class
  • Lapsus — similarly attributed-linked actor, same attribution class
  • Scattered Spider — similarly attributed-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1032 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.