Compiled from this incident record and the threat intelligence profile for Incransom. Figures and technique mappings are quoted from the source data, not inferred.
Incransom, a prolific ransomware-as-a-service operation first recorded on August 6, 2023, listed Metales Panamericanos on its dark web leak site on September 2, 2026. The company, which provides construction and steel supplies to the Panama Construction industry and offers services such as electrical solutions, equipment, devices, window structures, and gypsum among others, was targeted with these cyber tactics.
About Metales Panamericanos
English Metales Panamericanos, previously known as ACERO PANAMA, is the main construction & steel supplier to the Construction industry in Panama, initially focus in steel materials, now our new mission is extended to different constructions systems, Electrical Solutions, Equipment & Devices, zing ceilings, strollers, metal wires, windows structures, gypsum, among others. Spanish Metales Panamericanos S.A. (METALPAN), previamente conocida como ACERO PANAMA, es una dinmica y exitosa sociedad 100% panamea que se constituyo como METALPAN en el ao 1991, y que ha sabido transformarse y crecer con firmeza para responder de manera rpida y eficaz a las exigencias del clientes con altos niveles de competitividad presentes en el mercado nacional.
Source record: ransomware.live
About the Incransom group
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits. Incransom has listed 893 victims since August 2023.
How Incransom is documented to operate
Valid Accounts
T1078
Stealth
Persistence
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network.
Mitigations:
Application Developer Guidance, User Training, Password Policies, User Account Management, Privileged Account Management, Multi-factor Authentication
MITRE ATT&CK reference โ
Exploit Public-Facing Application
T1190
Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers.
Mitigations:
Vulnerability Scanning, Limit Access to Resource Over Network, Filter Network Traffic, Network Segmentation, Privileged Account Management, Application Isolation and Sandboxing
MITRE ATT&CK reference โ
Phishing
T1566
Initial Access
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems. Phishing may also be conducted via third-party services, like social media platforms.
Mitigations:
Network Intrusion Prevention, Restrict Web-Based Content, User Training, Antivirus/Antimalware, Software Configuration, Audit
MITRE ATT&CK reference โ
Windows Management Instrumentation
T1047
Execution
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
Mitigations:
Execution Prevention, Behavior Prevention on Endpoint, User Account Management, Privileged Account Management
MITRE ATT&CK reference โ
MITRE ATT&CK techniques attributed to Incransom across its recorded activity, not a finding about how Metales Panamericanos was reached.