Quick Summary
AllegedExecutive Summary
Doommageddon ransomware has listed INCOR Group, an India-based company operating in the commercial real estate and construction sectors, as a victim. This listing was identified by SOCRadar’s Dark Web Monitoring service on September 13, 2026. The Doommageddon group has been relatively low-volume, claiming four victims in the preceding 60 days, including INCOR Group. The threat actor’s recent activity shows a pattern of targeting companies in Turkey and India. Previous victims identified within the last two months include Akpera Gayrimenkul Yatırım A.Ş. and SITTNAK Lojistik A.Ş., both of which are based in Turkey and operate in the transportation and commercial property sectors. This suggests Doommageddon is actively targeting organizations within these specific geographic regions and industries.
Technical Analysis
For ransomware groups like Doommageddon, credentials harvested by infostealers serve as a crucial initial access vector. Threat actors or affiliated Initial Access Brokers (IABs) typically source fresh credential logs from underground marketplaces. These validated corporate credentials are then used to authenticate against VPN gateways or Microsoft 365 portals, paving the way for ransomware deployment. While the stealer-log telemetry queried did not return any records for the domain incor[.]in, it is important to note the limitations of such data. The queried dataset is paginated and bounded, meaning credentials could exist in feeds outside this specific slice or be associated with personal email aliases. Therefore, a null result should be treated as a lack of positive signal rather than confirmation of no compromise. The absence of immediately visible credential records does not rule out the possibility of compromise. Further monitoring and analysis are recommended to ensure the organization’s security posture. Actions such as continued dark web monitoring, proactive credential hygiene checks, password rotation, and multi-factor authentication review are advised.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.