惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The Cloudflare Blog
U
Unit 42
D
Docker
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
Recent Announcements
Recent Announcements
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
V
Visual Studio Blog
I
InfoQ
Google DeepMind News
Google DeepMind News
小众软件
小众软件
L
LangChain Blog
C
Check Point Blog
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
J
Java Code Geeks
罗磊的独立博客

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
INC Ransomware
Intel 471 · 2024-09-06 · via Intel 471 Blog

Threat Overview - INC Ransomware

INC Ransomware is a malware variant that was first observed in July/August of 2023, and has since been a part of major disruptions mostly in North America and Europe. Recently in August 2024, they have been tied to the attack and disruption of the major healthcare network McLaren Health Care - affecting IT infrastructure/devices and phone systems. The threat group, known by the same name as the ransomware (INC Ransom group), has typically been financially motivated and employs a double-extortion system after encrypting targeted systems - double-extortion referring to the exfiltration of proprietary data and threatening to release it to the public if the victim does not adhere to demands. The techniques that are utilized by INC Ransomware are similar to other Ransomware variants, with related methods of initial access, reconnaissance, lateral movement and ultimately the encryption of the system - furthermore, newly discovered Lynx ransomware has been observed in July 2024 to potentially be a fork of the malware strain. INC Ransomware is considered to be an active threat, and thus poses a significant and present risk that organizations should ascertain and be prepared for

GO TO COLLECTION

DOWNLOAD THE REPORT

Get your FREE Community Account today on the HUNTER471 Platform and get access to behavioral threat hunting content for your SIEM, EDR, NDR, and XDR platforms.

GET YOUR FREE HUNTER471 COMMUNITY ACCOUNT!

Hunt Packages

7-zip Archive Collection with File Exclusions

This Threat Hunt package identifies malicious activity where attackers leverage 7-Zip to collect and compress files prior to exfiltration. The method involves selectively including files of interest while excluding common, non-sensitive file types such as executables, videos, and virtual disk files. By using 7-Zip\u2019s compression capabilities with exclusion filters, adversaries can gather only critical or high-value data for exfiltration while avoiding files that might attract attention or bloat the payload. This tactic highlights the importance of monitoring file compression activities, especially when certain file types are deliberately excluded.

ACCESS HUNT PACKAGE

First Time Script Or Sysinternals Execution - Registry Key Modification

This package is designed to capture the first time execution of scripts and sysinternal executable. If it is the first time running some scripts or most Windows Sysinternal programs, the user much accept the End User License Agreement. This can be done in two ways: 1) Issue the -accepteula commandline argument OR 2) Click agree when the pop-up prompts you. Either way, when this happens a registry key is modified to save these changes and next time the program is run the prompt will not pop up.

ACCESS HUNT PACKAGE

Potential Exfiltration - Common Rclone Arguments

This will identify processes executed with common arguments associated with rclone activity used to exfiltrate.

ACCESS HUNT PACKAGE

Advanced IP Scanner Tool Utilization

This Threat Hunt package identifies instances where Advanced IP Scanner tool was used within a target environment, which may be leveraged by malicious actors to perform network discovery actions. This package can also identify activity even if the execution is run as a portable exe instead of an installation of the tool.

ACCESS HUNT PACKAGE

Remote WMI Command Attempt

This hunt searches for wmic.exe being launched with parameters to operate on remote systems. This could uncover an attacker abusing WMI functionality, in order to potentially perform remote executions or to simply gather information.

ACCESS HUNT PACKAGE

Remote Process Instantiation via WMI

This use case is meant to identify wmic.exe being launched with parameters to spawn a process on a remote system.

ACCESS HUNT PACKAGE

MEGA Sync Installation

This Threat Hunt package identifies instances where MEGA Sync installations are present within a target environment, which may be leveraged by malicious actors to exfiltrate sensitive data. MEGA Sync, a cloud storage synchronization tool, can be exploited by adversaries to quietly transfer files from compromised systems to external MEGA accounts, bypassing traditional security controls. This package focuses on detecting unauthorized installations and configurations of MEGA Sync that could indicate active or potential data exfiltration activities.

ACCESS HUNT PACKAGE