Inc Ransom
ActiveIncransom · INC Ransom · GOLD IONIC also known as
Total victims
172
This month
10
Active
—
DayBreach AI intelligence
How it operates
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.
MITRE ATT&CK profile
G1032
[INC Ransom](https://attack.mitre.org/groups/G1032) is a ransomware and data extortion threat group associated with the deployment of [INC Ransomware](https://attack.mitre.org/software/S1139) that has been active since at least July 2023. [INC Ransom](https://attack.mitre.org/groups/G1032) has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.(Citation: Bleeping Computer INC Ransomware March 2024)(Citation: Cybereason INC Ransomware November 2023)(Citation: Secureworks GOLD IONIC April 2024)(Citation: SentinelOne INC Ransomware)
Techniques it uses
Data Encrypted for Impact
T1021.001Remote Desktop Protocol
T1657Financial Theft
T1047Windows Management Instrumentation
T1566Phishing
T1059.003Windows Command Shell
T1537Transfer Data to Cloud Account
T1087.002Domain Account
T1074Data Staged
T1071Application Layer Protocol
T1046Network Service Discovery
T1569.002Service Execution
T1219Remote Access Tools
T1685Disable or Modify Tools
T1588.002Tool
T1036.005Match Legitimate Resource Name or Location
Associated malware and tools