INC Ransom attack chain against V-Silicon

Based on the exposed tooling, the Cybernews team was able to reconstruct a partial attack chain of INC ransom.
Phase 1 - Microsoft Graph API reconnaissance
Scripts:
- deep_search.py (eba1f666a2948c6c11b0ef510adcd16582437c2a2881f1b02a0c8b707f287c92),
- search_ehv.py (9dbf0e0b8cc06aaf1680cb68a46c88b1b3c45238d400ba7b7ce889e8f0b7ac3f),
- search_emails.py (1f06ec9a4b01a194724050c2cdbb3600137fa0d6db8fc315b2efdb9c461d4972),
- grab_critical.py (add201e319ed523bfc9f676cc8f84641ac9af56ad02369bb744a045d450f24b0),
- grab_devices.py (74860c83a2f77ab0636eba7312178452ac29665c9333b3d253802beaf0072ae9)
Authenticated to Microsoft Graph using a compromised employee email and executed the following information gathering steps:
1. Email search queries (35+ keywords):
- Infrastructure: `tunnel site-to-site`, `IPsec VPN Shanghai`, `MPLS WAN link`, `Azure VPN`, `SD-WAN`, `SilverPeak`, `Meraki VPN`
- Remote access: `remote access Shanghai`, `jump host`, `bastion`, `RDP gateway`, `Citrix`, `anyconnect`, `openconnect`
- Public IPs: `58.33`, `58.247`, `public IP Shanghai`
- Staff targeting: `[Name redacted] password`, `[Name redactacted]`, `EHV admin`, `Eindhoven`
- Network: `10.31.0`, `ehv router`, `ehv cisco`, `Netherlands server`
2. OneDrive exfiltrated files:
- VPN guide for employees
- Network diagrams
- SSL vpn user guide
- Document describing steps taken when moving between datacenters.
3. SharePoint exfiltrated files:
- Network topology diagram
- Plaintext credentials file
- European asset inventory
- devices and accounts Excel file
- UnitedDS Semiconductor Co., Ltd. FTP credentials
- regional site bring-up notes
- Jbox jump server guide
Phase 2: VPN Access
Scripts/Logs:
- vpn.log(590d03033b3ef1cbf42b21fa94e3c51b0064f4fa9fe38bd364fcf1b53b57a8a2), vpn_pass
Connected to Palo Alto GlobalProtect VPN for the Eindhoven site, using credentials found and harvested in Phase 1.
Phase 3: Domain Controller full compromise
Scripts:
- domain_enum.py (556b3bf133d1bef65a884e3ab37f69ad237df691f9ace00e2d6b8ee45cf3d83c),
- dcsync_and_auth.py (4c8e0018bb295e547716bb61d76b13614c2aa96f8983c5bc4943b8d3627c2b7e),
- push_ntds.py (b4ea299b7cd80d7e83f69892e1f7aa7685f44d041a9bbac013ddd6e2dcf6c89a),
- ntds_extract.py (b4ea299b7cd80d7e83f69892e1f7aa7685f44d041a9bbac013ddd6e2dcf6c89a)
1. Used WinRM to sign in to the Shanghai Domain controller, authenticated using compromised employee credentials.
2. Enumerated AD domain/forest structure, trust relationships, all Domain Controllers across 4 sites.
3. Listed Domain Admins, Enterprise Admins, service accounts, NAS objects.
4. Extracted NTDS.dit + SAM, + SECURITY + SYSTEM via volume shadow copy.
5. Exfiltrated via HTTP PUT from Shanghai DC to the attacker’s staging server.
6. Processed Hashes with Impacket secretsdump.
Phase 4 Internal Pivot Tunneling
Scripts:
- tunnel_setup.py (11f914e1a04d3431a7cd5fd96ca4425bdbb8a3413d6b0984d63884141fadf8e5),
- start_tunnels.sh (995dd1d8751bcd7ee5088bcf5c8ceae54e04d74a231f78e1d667dba10df50b19)
Set up 5 netsh port proxies on Shanghai Domain Controller via WinRM, routing internal infrastructure web UIs to the attacker-controlled server.
Phase 5 - Storage infrastructure compromise
NetApp ONTAP
Scripts:
- netapp_ssh_api.py (b64685eaae6504f23d9403595afba69dc979fe3a6ae141c08a32869af44cafe0),
- netapp_auth.py (a4a74988dd4d923072381baf43a327304e463b50ae6d261b89be66787db69884)
1. Authenticated to NetApp ONTAP hosted in Eindhoven
2. Enumerated all SVMs (Storage Virtual Machines)
3. Retrieved NFS export policies for each SVM
4. Added NFS export rules allowing 0.0.0.0/0 read/write access with ‘sys’ security
5. This effectively opened all NetApp NFS shares to the world.
Huawei OceanStor
Scripts:
- oceanstor_auth.py (6cd5ca0c9c9bac3e47a1ea2c9617dbd9b6e72ce494840b557885c95e046dd716), os_super.py
- (9f74460ebd9c572d6599f9f3f7c84cafd685798da6e0fb4b6fd5d9dca37cb562),
- os_enum.py (9e3d0ea38de014de28ad125f84c82d52c731e4d20275c8637be42944db5d9314), os_users.py
- (583e7f1180a2abbfda0a1dd57bc795daafd8fa195212f25336bbac691fb7ef68)
1. Brute-forced auth with common credential pairs
2. Added SSH port proxy, prepping for direct access
3. OceanStor LDAP configuration enumeration staged
NAS Ransomware Preparation
Scripts:
- nas_locker.py (3f90f5adf226898e9a9d0bfdfb9bcef6d6b88467db0211e171ff352087261132)
1. Targeted a separate NAS in the Eindhoven site.
2. Mapped 5 SMB shares using compromised employee credentials.
3. Uploaded locker.exe (ransomware binary) to C:/Windows/Temp.
4. Created a scheduled task “WinUpdate” running at midnight with the highest privileges.
Phase 6: Virtualization and Backup Attack
VMware vSphere
Scripts:
- vc_pwreset.py (598aa256ace62267b329df9a81d56f8cfee521a84b74b26c972b79c39b187fdf),
- vc_snap_reset.py (37c3d1f5c088c928d893ef45b56da42a2e79ff18f75fdaf6f8fb3201ecbe9752),
- vc_reset.py (b4c30735187fdaad1b377396df6a44f4d59fd4b7de4d221dc281209c44ddb671),
- vc_perms.py (fb4487fd0b8339c775481029ef4f3bc200b2d7e238a9c4f9b2096cd0fcb48db2),
- download_vmware_archive.py (a62673a4a9f3bc2d7f20f9f66e422d866782fe6bf0e6ab5f199b7bea8db0455f)
1. Authenticated to vCenter hosted in Shanghai, using compromised employee credentials
2. Attempted guest operations ticket theft via session token
3. Explored clone ticket acquisition, VIX interactive session, and ExtensionManager abuse
4. Password reset for vCenter administrator
5. VM snapshot manipulation scripts staged (delete snapshots)
6. Script to bulk download VM templates/archives from VMware content library
Veeam Backup Decryption
Scripts:
- veeam_decrypt.ps1 (3f51b7d5bbe891a0c2084a7ddc86146d8358fa48a63fd1b9f7b424ab4c8d4192),
- veeam2.ps1 (88e0cab9a1f0cd1f12409f60445da03d813ebe88b5402739ade85c10d09a8d71), vdecrypt.ps1
- (9db08465fd4e594c108b7d73ad14efa2d8565d376c5330d869f67cc0af4c68db)
1. PowerShell scripts targeting Veeam Backup & Replication encryption
2. Decryption of Veeam backup configs to access backup repositories
3. Credential extraction from Veeam encrypted stores
Phase 7: Multi-Architecture Persistent Implant
Cross-compiled binary payload for 14 architectures:
| Binary | Architecture | Sha256 | Target |
| x86_64-unknown-linux-esxi | x86_64 Linux ESXi | 753207ad5e72ddc6b13889132e5de18836b1a2acf954443655fea82b430e4c99 | VMware ESXi hypervisors |
| x86_64-pc-windows-gnu | x86_64 Windows | ef394149c8da3af730c37d550027df8639a3aaa6feaccea60112461ae6955829 | Windows servers/DCs |
| x86_64-unknown-linux-gnu | x86_64 Linux | c616e11a2ce7feb3207c1808714d056c9c216f429ad6b840e781f3494ac8485d | Linux servers |
| x86_64-unknown-linux-musl | x86_64 Linux (musl) | 126597ea3130600a83ba2ced62e70abb985fcd401ab70525650bb9a1354ca955 | Alpine/containers |
| aarch64-unknown-linux-gnu | ARM64 Linux | 034ac761c0a2baf754f9cc200824ab29fe7124402469d38afc3c5422567d17c8 | ARM servers (AWS Graviton, etc.) |
| arm-unknown-linux-gnueabi | ARM32 soft-float | 3ac3fa5f39372c2dd2822ee63f38852f6ec34a74bdbc46e34a142f8033ccb969 | Embedded ARM |
| arm-unknown-linux-gnueabihf | ARM32 hard-float | 7dc832f876ace2d6b763f7c19f29a206dd74a5265a76dc9009fde9e8c0846656 | Raspberry Pi, embedded |
| armv7-unknown-linux-gnueabi | ARMv7 soft-float | db29c0b4d16a4f02bb1631a2eca6e589e13fb6470f20453a393604954b53562e | Legacy ARM |
| armv7-unknown-linux-gnueabihf | ARMv7 hard-float | b3ec3e4e7ab1cae84d9c4cdd63425318588e5d94c2dd720387842969b3bb8507 | Older embedded |
| riscv64gc-unknown-linux-gnu | RISC-V 64 | 4e83e8236ad7ef73ba0197ffe72b595c29e3ce5efd5c6c98c7663ad55e1646d0 | RISC-V systems |
| powerpc-unknown-linux-gnu | PowerPC 32 | 5341a686d27b38b7ee580febddcd5817aeef5f94815ff291e508ecaf78cb1070 | Legacy industrial |
| powerpc64-unknown-linux-gnu | PowerPC | 644aaa4cc22addcf3bb54c5ffa16bd2be4b0b0b0437edb29b844b496abc64b9eec | IBM POWER |
| s390x-unknown-linux-gnu | IBM z/Architecture | e9ccbb0df3f01ed4a94f7677c802a032edfe8d23c5769522482f94016c81b507 | Mainframe |
| sparc64-unknown-linux-gnu | SPARC 64 | 7477da223bbb0752653f32e60c05eb5c03daf3a5afe89d6565958525a274e211 | Oracle/Sun legacy |