RainINC is a ransomware variant associated in the provided reporting with the INC ransomware operation, which is described as a ransomware-as-a-service (RaaS) group that emerged in mid-2023. In the documented incident, a U.S. victim detected RainINC encrypting a production Microsoft SQL Server, and the payload was executed from the Windows PerfLogs directory, a location noted in the content as increasingly used by ransomware actors for staging. The investigation by DFIR firm Cyber Centaurs linked the broader activity to attacker infrastructure used by the INC gang and recovered encrypted exfiltrated data from 12 unrelated U.S. organizations. The recovered victim set spanned healthcare, manufacturing, technology, and services. The content states that INC-related artifacts included renamed binaries such as "winupdate.exe," PowerShell scripts intended to execute the legitimate backup tool Restic, and a script named "new.ps1" containing Base64-encoded Restic commands with hardcoded repository configuration, access keys, repository paths, and S3 passwords for encrypted repositories. Cyber Centaurs assessed that Restic was not used in the specific investigated intrusion, but that leftover Restic-related artifacts exposed persistent attacker infrastructure used across campaigns. Additional INC tooling referenced in the content includes cleanup tools, remote access software, and network scanners. High-confidence indicators and artifacts directly mentioned include execution from the PerfLogs directory, the renamed binary "winupdate.exe," and the PowerShell script "new.ps1" with Base64-encoded Restic commands and hardcoded repository credentials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload observed encrypting a victim production SQL Server; executed from the Windows PerfLogs directory used for staging.
A variant of the INC ransomware payload used for execution/encryption in the described attack (staged/executed from the Windows PerfLogs directory).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.