IncRansom is a ransomware family and associated extortion operation observed in enterprise intrusions during 2025 and 2026. It has been identified among active ransomware groups targeting organizations in multiple sectors, including healthcare, and has been linked to victim postings on a public leak site, indicating use of a double-extortion model in which stolen data is leveraged for coercion in addition to encryption-based disruption.
Observed ransomware intrusions involving IncRansom fit broader contemporary enterprise ransomware tradecraft. Reported cases show attackers obtaining access to corporate environments, conducting credential theft and post-compromise network operations, exfiltrating data before detonation, and then deploying ransomware across reachable systems. In enterprise incidents of this class, operators commonly abuse administrative shares and centralized management mechanisms to distribute payloads, target backup and virtualization infrastructure to inhibit recovery, and time encryption for off-hours execution. VMware and backup platforms are frequently prioritized in such attacks because disabling recovery options increases extortion pressure.
IncRansom has been observed affecting organizations in healthcare-related contexts and appears in reporting alongside other major ransomware families active in the same period, including Akira, LockBit, Fog, and Lynx. Available information supports classifying IncRansom as a ransomware threat used for data theft and extortion against enterprise victims, but does not provide high-confidence, family-specific technical details beyond its role in ransomware incidents and leak-site-based victim shaming.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
PsExec and direct access to administrative shares (ADMIN$, C$, etc.) remained present in some engagements... The most common approach involved executing the ransomware binary from a single compromised system — typically a domain controller or infrastructure server — and encrypting data on remote systems through administrative shares (ADMIN$, C$).
Amongst the approximately ten ransomware incidents investigated in 2025, all followed a double extortion model: data exfiltration preceded encryption... The ransomware families observed included Akira, LockBit, Fog, Incransom, and Lynx.
Prior to encryption, attackers systematically targeted backup infrastructure and virtualization platforms to maximize impact and eliminate recovery options: Hypervisors (VMware ESXi, Hyper-V) – Destruction or encryption of virtual machines at the hypervisor level; Backup infrastructure (Veeam) – Access via compromised privileged accounts or exploitation of known Veeam vulnerabilities to delete or encrypt backup repositories.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware identified as the cause of a healthcare breach affecting Community Connections.
분기 통계에서 활동을 유지한 중견 랜섬웨어 그룹으로만 언급된다.
Ransomware family observed in double-extortion incidents where data exfiltration preceded encryption.
Ransomware operation referenced as posting victims to a leak site (implying extortion/data leak component).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.