INC Ransom is a ransomware-as-a-service operation active since at least mid-2023 that has become one of the more prolific extortion threats globally. It conducts double-extortion attacks, combining data theft with file encryption and public leak-site pressure, and has been associated with hundreds of victims across multiple sectors, with a strong concentration in the United States. Frequently targeted industries include healthcare, manufacturing, legal services, education, construction, technology, government, and business services. The operation is also tracked under aliases including Gold Ionic, Tarnished Scorpius, and Water Anito.
INC uses affiliate-driven intrusions and commonly relies on compromised credentials, purchased access, phishing, and exploitation of exposed edge or remote-access systems for initial entry. Reported intrusion paths include abuse of vulnerable Citrix, Fortinet, and remote-management infrastructure. In some campaigns, access linked to large-scale credential-harvesting activity against FortiGate environments was later used to support INC ransomware deployment.
Post-compromise tradecraft emphasizes speed, automation, and abuse of legitimate administrative mechanisms. Operators perform reconnaissance of Active Directory environments, credential theft, privilege escalation, and lateral movement using common enterprise tools and Windows-native utilities, including RDP, PsExec, PowerShell, WMI, Group Policy, Impacket, and remote administration software. Observed operations have used startup-script deployment through domain policy to propagate ransomware broadly, disabled Microsoft Defender and User Account Control, added security exclusions, and leveraged tools such as Cobalt Strike, AnyDesk, ScreenConnect, and TeamViewer. INC activity has also been associated with Bring Your Own Vulnerable Driver techniques and custom process-termination tooling to impair endpoint defenses.
The malware itself has evolved substantially. Both Windows and Linux/ESXi encryptors have been rewritten in Rust, improving cross-platform portability and complicating analysis. Observed samples use modern hybrid cryptography based on X25519 or Curve25519 together with AES in a multithreaded encryption workflow, and support partial-encryption modes to accelerate impact. The ransomware can terminate services and processes that interfere with encryption, delete shadow copies to inhibit recovery, and in ESXi environments attempt to shut down virtual machines. It can also identify additional attached storage and printers, and has been reported to print ransom instructions in some cases.
INC’s operational ecosystem has shown notable overlap with related ransomware families, especially Lynx and Sinobi, following underground sales of INC source code in 2024. Multiple researchers have reported significant code similarities between INC and Lynx, and some assessments treat Lynx as an evolved variant or rebrand. The group’s growth has also been linked to disruption of other major ransomware brands, which likely displaced experienced affiliates into the INC ecosystem. Overall, INC is characterized less by uniquely novel malware than by disciplined affiliate operations, rapid domain-wide deployment, effective use of legitimate tooling, and sustained double-extortion pressure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On July 14, the cybersecurity vendor SonicWall published a security advisory regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410. Together they could allow any random, unauthenticated attacker to gain remote code execution (RCE) powers and then run commands on the box at the root level. ... CVE-2026-15409 should warrant special concern. It's a server-side request forgery (SSRF) issue in the SMA's "Work Place" Web interface... It requires no authentication... Rapid7 ... has been using CVE-2026-15409 and CVE-2026-15410 as zero-days.
On July 14, the cybersecurity vendor SonicWall published a security advisory regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410. Together they could allow any random, unauthenticated attacker to gain remote code execution (RCE) powers and then run commands on the box at the root level. ... CVE-2026-15410 earned a lesser but still high 7.2 out of 10 CVSS score... If they are, they can use this code injection vulnerability to execute arbitrary operating system (OS)-level commands.
CVE-2023-48788 ... SQL Injection Leading to RCE Fortinet FortiClient EMS 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10 9.3 (Critical) 98.53% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2025-5777 ... Authentication Bypass / Session Hijacking Citrix NetScaler ADC and Citrix Gateway 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32 9.3 (Critical) 99.90% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2023-3519 ... Unauthenticated Remote Code Execution Citrix NetScaler ADC and Citrix Gateway 13.1 before 13.1-49.13 and 13.0 before 13.0-91.13 9.8 (Critical) 99.34% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2024-57727 ... Path Traversal Leading to RCE SimpleHelp versions 5.5.7 and earlier 7.5 (High) 95.07% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2023-35082 ... IoCs ... CVE-2023-35082 SimpleHelp RMM vulnerability, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2024-4885 ... IoCs ... CVE-2024-4885 WhatsUp Gold RCE, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2023-4966 ... IoCs ... CVE-2023-4966 Citrix Bleed (NetScaler), used for credential theft | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
This activity is significant as it may indicate an attempt to exploit CVE-2024-21378, where a custom MAPI form loads a potentially malicious DLL. If confirmed malicious, this could allow an attacker to execute arbitrary code, leading to further system compromise or data exfiltration.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
INC Ransom is an active ransomware and data extortion group that has been operating since at least July 2023 and is associated with the INC Ransomware malware family.
Discovered in mid-2023, INC ransomware is another RaaS group that employs double extortion tactics... In its most recent iteration, both payloads are rewritten in Rust.
Microsoft revealed on Wednesday that its threat analysts have observed the financially motivated Vanilla Tempest threat actor using INC ransomware for the first time in an attack on the U.S. healthcare sector.
The ransomware-as-a-service (RaaS) group Tarnished Scorpius (aka INC Ransomware) has listed on its leak site an Israeli industrial machinery company, and replaced the company logo with a swastika.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
User awareness training. Regularly educate staff on phishing, social engineering and other tactics used by ransomware operators. | INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
the actors deployed a custom process terminator that drops vulnerable drivers (filwfp.sys, filnk.sys, fildds.sys) and installs them as a service.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
deploy a base64 encoded script through cmd.exe. cmd.exe /Q /c powershell.exe -e ...
Exfiltrated data from an Asia-Pacific manufacturing copmany revealed the attacker specifically targeted Active Directory DPAPI backup master keys, which would enable offline decryption of all domain-protected credentials... At the root of the loot directory are three files containing Active Directory DPAPI backup master keys.
After gaining access, it’s been observed through multiple incidents that INC ransomware actors have performed discovery techniques through ping and net commands through cmd.exe.
Other than built-in commands, there were also cases where they have used tools like Angry IP scanner, Advanced IP scanner and netscan.
By invoking the native GetSystemInfo Windows API, the binary retrieves the active dwNumberOfProcessors core count metric.
To maximize the scope of its deployment, the payload initiates a systematic discovery loop targeting all connected storage infrastructure... iterating sequentially through the alphabet... identifies active volumes, distinguishing between local fixed disks, removable media and mapped network shares.
To move laterally within the victim’s environment, INC ransomware actors use living-off-the-land binaries (LOLBins), including remote desktop protocol (RDP)...
A second directory... hosted 1,853 files... sitting alongside encryptors, reconnaissance logs, and exfiltrated victim data... Two ZIP archives named after a victim company contained 884 files organized by data category; board reports, HR databases, domain controller data, etc.
Victims who refuse to pay face not only locked systems but also the exposure of sensitive corporate records on INC’s data leak site.
The group primarily conducts double extortion attacks, combining data exfiltration with the encryption of victims’ systems.
Analysis of the imported functions indicates the use of Windows Service Control Manager APIs... This suggests that the malware is capable of stopping services that could interfere with the encryption process, such as database servers, business applications, backup solutions, or security software.
the control flow falls through to a diagnostic block referencing the cleartext string literal "Successfully deleted shadow copies from "
Upon successful encryption, the malware modifies the host's desktop wallpaper to display the extortion demands and drops both .txt and .html versions of the INC-README note.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
100 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family used in double-extortion operations. It encrypts files, appends the .INC extension, drops an INC-README.txt ransom note, disables Windows Defender and UAC prior to execution, uses fast automated propagation via Active Directory/GPO and Impacket, and employs hybrid X25519 plus AES-CTR encryption with multithreaded file encryption.
Ransomware operation linked in the reporting to FortiBleed-derived access via an operator observed logged into its negotiation panel.
Ransomware-as-a-Service operation active since mid-2023, described as targeting healthcare, education, and government organizations.
A ransomware-as-a-service operation linked in this report to the use of FortiGate credentials harvested via FortiBleed for ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.