INC Ransom is a financially motivated ransomware operation active since at least 2023 and commonly tracked under aliases including INC, INC Ransomware, INCRansom, Gold Ionic, and G1032. The group is associated with ransomware and data-theft extortion activity and has been linked to an affiliate-based ecosystem. Reporting also describes Lynx as an evolution of the INC ransomware lineage, and separate reporting has tied affiliates associated with the INC ecosystem to deployment of other ransomware families such as DeadLock. INC Ransom has repeatedly targeted organizations in North America and other regions, with a notable concentration on professional services firms, particularly law firms. Confirmed victim reporting also shows activity against financial services, healthcare, technology, engineering and construction-related organizations. Publicly documented targeting spans the United States, Canada, the United Kingdom, Germany, the United Arab Emirates, Australia, Malaysia, and Brazil, indicating broad international reach. The group has been associated with exploitation of internet-facing remote access infrastructure for initial access, including SSL VPN appliances and SonicWall SMA1000 devices. This aligns with broader ransomware tradecraft focused on exploiting exposed enterprise access points. INC Ransom has also been linked to use of AdFind, indicating Active Directory and enterprise environment reconnaissance during intrusions. Observed behavior supports a double-extortion operating model in which victim data is stolen and victims are pressured through threatened publication of exfiltrated information. Multiple incidents attributed to the group were explicitly described as ransomware attacks accompanied by data breaches, and victim data categories reportedly included client, financial, contractual, operational, and medical information. The operation is also publicly tracked through leak-site claims, consistent with extortion-driven ransomware activity. Overall, INC Ransom is best characterized as a cybercriminal ransomware actor focused on monetizing intrusions through encryption-linked extortion and theft of sensitive business data, with a demonstrated preference for service-sector targets and use of common enterprise intrusion and ransomware affiliate tradecraft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
17 CVEs this actor has used in observed campaigns. 17 of them exploited in the wild.
Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities Catalog.
Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities Catalog.
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
12 more CVEs tied to this actor tracked in Mallory.
94 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against SSF International GmbH, an engineering and professional services firm in Germany.
Conducting a ransomware attack against a professional services organization in the United Arab Emirates.
Ransomware group with 7 public claims in week 33 of 2026; noted in the content as the only current top-10 group with regularly documented presence across multiple prior weeks.
Named as the ransomware group responsible for the attack and data breach against Third Coast Bancshares.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.