INC ransomware has grown into one of the most active ransomware-as-a-service operations, with researchers attributing its rise to aggressive affiliate expansion, broad victim targeting, and effective use of established intrusion methods rather than novel exploits. The group, active since 2023 and linked to more than 800 claimed victims, uses double extortion by encrypting systems and threatening to leak stolen data, with early concentration on healthcare and other high-pressure sectors now expanding into education, legal, manufacturing, construction, and technology organizations.
Researchers said INC has upgraded both its Windows and Linux/ESXi encryptors by rewriting them in Rust, improving cross-platform operations and resilience while affiliates continue to rely on spearphishing, stolen credentials, and exploitation of known flaws including Citrix Bleed 2, Citrix NetScaler, SimpleHelp RMM, and Fortinet EMS vulnerabilities. Post-compromise activity has included abuse of legitimate remote administration tools, credential theft from Veeam environments, living-off-the-land lateral movement, use of EDR killers, and cloud-based exfiltration with tools such as rclone; analysts also linked INC code to related strains including Lynx, Sinobi, and Knoba after the group’s source code was reportedly sold to multiple parties.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
A July 2026 analysis of exposed INC infrastructure reconstructed how the group automates ransomware deployment after gaining domain-level access, using Active Directory, Group Policy Objects, SYSVOL-hosted scripts, Impacket, and Windows LOLBins. The report also described operators disabling Microsoft Defender and UAC before downloading and executing the Rust-based payload across domain-joined systems, and published Sigma detection opportunities for these behaviors.
A new report said legal services had become INC ransomware's top targeting priority, ahead of manufacturing, technology, health care, and construction. The article said law firms are attractive targets because they hold highly sensitive documents that can increase extortion pressure if stolen and leaked.
Researchers found exposed INC affiliate servers in mid-June 2026 that contained a Rust-based Linux encryptor suite cross-compiled for 14 CPU architectures, including IBM POWER, SPARC64, s390x, and RISC-V. The finding indicated INC had expanded beyond previously documented x86-64 Linux and ESXi targeting toward enterprise and mainframe platforms.
Researchers reported that INC used a Veeam credential-stealing utility, BYOVD techniques, remote administration tools for persistence and evasion, and Rclone for data exfiltration before encryption. The report also described intrusion paths including spear-phishing, Initial Access Broker credentials, and exploitation of Citrix NetScaler, Fortinet EMS, and SimpleHelp systems.
Acronis reported that INC fully rewrote its Windows and Linux/ESXi ransomware variants in Rust. The change was described as improving cross-platform capability, operational reliability, and evasion in newer attacks.
Acronis researchers assessed INC as one of the most active ransomware-as-a-service groups in 2026, with more than 800 claimed victims. They attributed its growth to aggressive victim selection, rapid affiliate scaling, and reliance on proven intrusion methods.
ZeroFox placed INC in its global top five ransomware groups for the first quarter of 2026, citing 124 incidents. Analysts said the group's growth appeared uneven and may reflect affiliate churn and reconsolidation.
In 2024, INC's source code was reportedly sold to at least three parties. Researchers believe related ransomware strains such as Lynx, Sinobi, and Knoba show code overlap tied to that sale.
The references describe INC as a ransomware-as-a-service operation that emerged in 2023 and later grew into a major global ransomware group.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
27 references tracked. Mallory keeps watching after this page renders.
ctrlaltintel.com
Open sourcemedium.com
Open sourceblog.knowbe4.com
Open sourcesecpod.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.