INC Ransom is a cybercriminal ransomware operation active since at least mid-2023 and commonly tracked as a ransomware-as-a-service group. Known aliases include INC, INCRansom, Gold Ionic, Tarnished Scorpius, and Water Anito. The group is associated with double-extortion activity, combining data theft with encryption and using a leak site to pressure victims and publicize attacks. Public victim claims number in the hundreds, with reporting frequently placing the total above 800. INC Ransom targets a broad range of sectors rather than a single vertical. Frequently affected industries include business services, healthcare, manufacturing, government, financial services, logistics, agriculture, and professional services. Victimology indicates a strong concentration on organizations in the United States, while attacks have also affected entities across Europe, Asia, Africa, and Latin America. Reporting has noted an apparent absence of targeting in CIS countries and China, consistent with patterns seen in some post-Soviet eCrime ecosystems. Operationally, INC Ransom is notable less for uniquely advanced malware than for disciplined, rapid, and highly automated enterprise-wide deployment. Intrusions have been described as smash-and-grab operations in which ransomware execution can follow initial access within roughly 72 hours. Observed tradecraft includes abuse of legitimate administrative mechanisms and common post-exploitation tooling, especially Active Directory, Group Policy Objects, SMB-based lateral movement, Impacket, remote management utilities, custom scripts, Windows LOLBins, and frameworks such as Cobalt Strike. After obtaining elevated or domain-level access, operators have been observed pushing startup scripts through domain policy to propagate at scale, disabling or weakening endpoint protections, adding antivirus exclusions, downloading payloads through native Windows utilities, and executing ransomware across domain-joined systems. The malware associated with the group has been tracked separately and includes Rust-based payloads that use multithreaded encryption and a hybrid public-key and symmetric cryptographic design. Observed functionality includes terminating services that could interfere with encryption, such as security, backup, database, and business application services. MITRE ATT&CK tracks the threat group as G1032 and the associated malware as S1139. INC Ransom has also been linked to exploitation of edge infrastructure for initial access. In 2026, reporting tied the group to zero-day exploitation of SonicWall SMA 1000 Series vulnerabilities CVE-2026-15409 and CVE-2026-15410, enabling unauthenticated access, command execution, credential and session theft, and lateral movement toward domain controllers, with ransomware deployment achieved in at least some cases. Separate reporting has linked INC Ransom to activity overlapping with the Lynx ransomware ecosystem, including notable code similarities between samples and broader campaign-level associations. The group has claimed attacks against government and public-sector entities, including U.S. state-level organizations and international agencies, alongside numerous private-sector victims worldwide. Overall, INC Ransom is best characterized as a mature, opportunistic, multi-sector extortion operation that relies on speed, standardization, and effective abuse of enterprise administration features to scale ransomware deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
55 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RaaS ransomware operator conducting double-extortion attacks with a highly automated attack chain. The group uses Active Directory, GPOs, Impacket, LOLBins, RMM tools, Cobalt Strike, and custom scripts to propagate ransomware rapidly across victim environments, typically prioritizing fast smash-and-grab operations.
Conducting a ransomware attack against v-silicon.com, a technology-sector organization in Taiwan.
Conducting a ransomware attack against FAST.COM.PH / FAST Logistics Group.
Conducting a ransomware attack resulting in a data breach against D.MAG New Material Technology Co., Ltd. Taiwan Giant.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.