← Back to all threat actors

INC Ransom

Also known as GOLD IONIC
Tracked as G1032

INC Ransom is a financially motivated ransomware and data-extortion operation active since at least July 2023. The group has targeted industrial, healthcare, and education organizations in the United States and Europe. Reported intrusions combine phishing or exploitation of internet-facing systems with credential abuse, network discovery, lateral movement, cloud-service exfiltration, and ransomware deployment.

How we source and review actor profiles
Motivation
ransomware
First seen
2023-07-01
Sectors
manufacturing, healthcare, education
Status
Active

Threat intelligence assessment

At a glance

INC Ransom conducts ransomware and data-extortion operations against organizations in the United States and Europe, with documented impact in industrial, healthcare, and education sectors.

Activity timeline

First observed
July 2023
Status
active

Attribution assessment

Operational playbook

Facts

  • INC Ransom combines hands-on-keyboard intrusion activity with ransomware and data-extortion pressure.
  • Operators stage stolen material and use third-party cloud services before encryption.
  • Remote administration and native Windows utilities are mixed with dedicated reconnaissance and exfiltration tools.

Initial access and identity targets

Facts

  • MITRE records phishing as an initial-access method.
  • The group has exploited CVE-2023-3519 in Citrix NetScaler appliances.
  • Compromised accounts are used to access victim environments and services.

Capabilities and evasion

Facts

  • Operators use command shell, WMI, service execution, and PsExec for execution and lateral movement.
  • AdFind, NETSCAN, Net, Nltest, and network-share discovery support Active Directory and network reconnaissance.
  • 7-Zip or WinRAR archives are staged before exfiltration through MegaSync, Rclone, or other cloud services.
  • AnyDesk and PuTTY provide remote access, while SystemSettingsAdminFlows.exe has been abused to impair Microsoft Defender.
  • The group deletes files and encrypts victim data after collection and exfiltration.

Infrastructure patterns

Facts

  • INC Ransom uses commercially available remote-access and cloud-transfer services alongside actor-controlled extortion infrastructure.
  • Cloud-service use can make exfiltration traffic resemble legitimate administrative activity.

Communication and pressure channels

Facts

  • Victims are pressured through encryption, negotiation, and threatened or actual publication of stolen data.

Channels

  • ransom note
  • victim negotiation portal
  • data-leak site

Observed targeting

Targeting, not victimization. Sector and region statements summarize reported incidents. The live victim table contains actor claims and labels them separately from independently confirmed incidents.

Facts

  • Documented targeting includes industrial, healthcare, and education organizations.
  • Reported activity spans the United States and Europe.

Defender guidance

Measures

  • Patch internet-facing Citrix NetScaler systems and hunt for evidence of CVE-2023-3519 exploitation.
  • Require phishing-resistant MFA for remote and privileged access, and investigate anomalous use of valid accounts.
  • Alert on unusual AdFind, NETSCAN, PsExec, WMI, AnyDesk, PuTTY, MegaSync, and Rclone activity in context.
  • Monitor attempts to invoke SystemSettingsAdminFlows.exe, weaken Microsoft Defender, or delete recovery and forensic artifacts.
  • Restrict outbound cloud-storage access and maintain tested offline or immutable backups.
Derived

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1032

Reviewed identity mapping approved on this date.

First listed
Victim claimjms building corporation listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimhttps://mediengruppethiel.de/ listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimcullottalaw.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimWellness Partners network(combined revenue) listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimmyglobal.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimAsfaltos y Pavimentos S.A. (Asfalpasa) listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimWestfield Public School District listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimTrucka listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimPoliclinico Triestino listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimMultiver Ltée listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimMetales Panamericanos listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimspecialtytextile.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimFFKR Architects listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimNew Century Ophthalmology Group listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimzummocorp.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimwww.lichtvision.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimwww.renorefractories.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimcimbsecurities.com listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimwittmann listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimOilquip Inc listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimRohloff Group listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
First listed
Victim claimRuby Seven Studios listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBENCIVIL listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimel-group listed by INC Ransom

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

The interactive view includes 105 dated events with category filters and paging.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

INC RansomCanonical Name
GOLD IONICAlias
G1032Tracking Id

Shared-name reviews

Every exact-name collision is reviewed. Same-actor decisions select a preferred profile while distinct and unresolved clusters remain separate.

Same actor high

The cited upstream records use spacing or punctuation variants of the same actor name. Source records remain separate for provenance, while exact-name resolution prefers the reviewed canonical profile.

Loading CVEs, techniques, indicators, malware, victims, and activity...