Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-06

InCrease

Also known as:DEV-0206GOLD PRELUDEPurple VallhundTA569UNC1543Mustard Tempest

As of 2026-07-01, InCrease is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as DEV-0206, GOLD PRELUDE, Purple Vallhund, TA569. ATT&CK coverage spans 70 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1005 (Data from Local System), T1041 (Exfiltration Over C2 Channel), T1082 (System Information Discovery).

Tracked threats
33 high
First seen
2026-06-24
Last seen
2026-07-01
ATT&CK techniques
70across 3 of 3 threats
Related CVEs
0None referenced
3 tracked threat(s) · Categories: MALWARE

Activity timeline

InCrease appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

70 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (11), Execution (10), Command and Control (9), Discovery (9), Collection (5), Credential Access (5)
  • T1005 Data from Local System — Collectionobserved in 3 of 3 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 3 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1090 Proxy — Command and Controlobserved in 3 of 3 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 3 of 3 tracked threats
  • T1115 Clipboard Data — Collectionobserved in 3 of 3 tracked threats
  • T1614 System Location Discovery — Discoveryobserved in 3 of 3 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1056 Input Capture — Credential Accessobserved in 2 of 3 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats

Tracked threats