INCRANSOM

RANSOMWARE

INCRANSOM is an emerging ransomware group whose primary targets and attack vectors remain largely unknown due to limited confirmed data. However, based on the predicted correlations of CVEs linked to their activities, INCRANSOM appears to leverage critical vulnerabilities for initial access and lateral movement within targeted networks. The group's operational profile suggests a focus on sophisticated techniques such as credential harvesting and remote execution, indicative of an advanced threat actor capable of evading detection and establishing persistence.

Technically, INCRANSOM’s toolkit includes several common but powerful utilities like Mimikatz for credential dumping and PsExec for lateral movement, suggesting a high level of technical sophistication. The group's use of these tools alongside others such as AdFind and Advanced IP Scanner points to an approach that prioritizes reconnaissance and data exfiltration before encryption. Defenders should prioritize patching critical vulnerabilities and implementing robust authentication mechanisms to mitigate the risk of credential theft and lateral movement. Additionally, continuous monitoring for unusual network activity and behavioral anomalies can help detect INCRANSOM’s presence early in their attack lifecycle.

Confirmed CVEs (2)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2026-15409 CRITICAL SonicWall SMA1000 10.0 CVE-2026-15410 HIGH SonicWall SMA1000 7.2

Predicted CVEs (6) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2026-15409 CRITICAL SonicWall SMA1000 predicted 10.0 CVE-2025-23006 CRITICAL SonicWall SMA1000 predicted 9.8 CVE-2023-3519 CRITICAL Citrix NetScaler ADC predicted 9.8 CVE-2023-3519 CRITICAL Citrix NetScaler ADC high 9.8 CVE-2023-4966 HIGH Citrix NetScaler ADC predicted 7.5 CVE-2026-15410 HIGH SonicWall SMA1000 predicted 7.2

ATT&CK Techniques (25)

T1190 Exploit Public-Facing Application Initial Access T1566 Phishing Initial Access T1047 Windows Management Instrumentation Execution T1059.003 Command and Scripting Interpreter: Windows Command Shell Execution T1569.002 System Services: Service Execution Execution T1036.005 Masquerading: Match Legitimate Resource Name or Location Stealth T1070.004 Indicator Removal: File Deletion Stealth T1078 Valid Accounts Stealth T1046 Network Service Discovery Discovery T1049 System Network Connections Discovery Discovery T1069.002 Permission Groups Discovery: Domain Groups Discovery T1087.002 Account Discovery: Domain Account Discovery T1135 Network Share Discovery Discovery T1021.001 Remote Services: Remote Desktop Protocol Lateral Movement T1570 Lateral Tool Transfer Lateral Movement T1074 Data Staged Collection T1560.001 Archive Collected Data: Archive via Utility Collection T1537 Transfer Data to Cloud Account Exfiltration T1071 Application Layer Protocol Command and Control T1105 Ingress Tool Transfer Command and Control T1219 Remote Access Tools Command and Control T1486 Data Encrypted for Impact Impact T1657 Financial Theft Impact T1588.002 Obtain Capabilities: Tool Resource Development T1685 Disable or Modify Tools Defense Impairment