The Tale of Two INC Ransom Notes: A Ransomware Timeline
Huntress, Monday, September 21st, 2026
Huntress reconstructed an INC ransomware attack timeline, including BYOVD driver abuse to disable defenses, despite limited initial telemetry.
Huntress pieced together the timeline of an INC ransomware incident despite being installed on the organization only after the attack began, which limited visibility into the initial access vector.
Analysts couldn't determine how the attackers first got in due to the telemetry gap and time elapsed, but were able to trace the attack's later stages, including use of a Bring Your Own Vulnerable Driver (BYOVD) technique to disable security controls and an executable configured to run multiple scheduled tasks with randomized names.
The post frames the case as illustrating how much can still be reconstructed even with incomplete visibility.