Researchers published new intelligence on INC Ransom, outlining a victim negotiation platform allegedly exposed at 178.20.41.208:1002 and describing a stack built on nginx, Yii/PHP, and a React/Redux/Socket.io frontend. The reporting says the group’s infrastructure spans clear-web and onion sites with repeated overlap in Russian hosting, and that INC has operated since 2023, listed more than 870 victims, and may share code or branding lineage with Lynx and possibly Sinobi. Separate technical reporting described INC as a multi-extortion operation that primarily targets healthcare, industrial, and education organizations in the U.S. and Europe, using living-off-the-land tools such as NETSCAN.EXE, AnyDesk, and SystemSettingsAdminFlows.exe, along with Defender tampering and a custom av.exe utility to disable EDR protections.
At the same time, multiple new victim claims attributed to incransom surfaced, affecting organizations in nonprofit services, manufacturing, healthcare support, and other sectors across the United States, Mexico, and Switzerland. Reported victims included Foundations to Freedom in Florida, DUCON in Colorado, minigrip.com.mx in Mexico, Della Casa Group AG in Switzerland, and a Minnesota-based residential care provider associated with eclmn.com. The victim summaries describe unauthorized access to confidential files including client data, financial records, R&D material, and project information; in the Swiss case, the leak allegedly involved 86,332 files in 15,359 folders totaling about 240 GB, underscoring INC Ransom’s continued emphasis on data theft and public leak pressure alongside encryption.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Harwal.net, identified as Harwal Group in the United Arab Emirates, was reported as a ransomware victim attributed to incransom. The report states the breach occurred on 2026-07-29 at 09:00 UTC, was discovered at 16:26 UTC, and involved 12 TB of data.
A Minnesota health and residential care organization associated with eclmn.com was reported as an incransom victim. The breach time was listed as 12:00 UTC and discovery at 13:26 UTC.
Della Casa Group AG in Switzerland was identified as a ransomware victim attributed to incransom. The report says the incident was discovered on July 28, 2026 and involved 86,332 files across 15,359 folders, including personal, client, finance, and project data.
Mexico-based manufacturer minigrip.com.mx was reported as a victim of incransom, with alleged access to client, R&D, and financial files. The breach was listed at 01:00 UTC and discovery at 02:01 UTC.
DUCON, a Colorado manufacturing organization, was reported as a victim of incransom with unauthorized access to confidential files including client, R&D, and financial data. The breach was listed at 01:00 UTC and discovery at 01:58 UTC.
Foundations to Freedom, a nonprofit in DeLand, Florida, was reported as a ransomware and data-breach victim attributed to incransom. The report lists the breach at 00:01 UTC and discovery at 01:03 UTC.
A threat-intelligence analysis reported that INC's negotiation panel was exposed at IP 178.20.41.208 on port 1002 and described its nginx, Yii/PHP, React, Redux, and Socket.io-based victim portal. The analysis also mapped overlapping clear-web and onion infrastructure and suggested possible links to Lynx and Sinobi.
A source states the INC ransomware project was advertised for sale on the RAMP forum in March 2024 for $300,000.
A published analysis described INC Ransom's targeting of healthcare, industrial, and education organizations and outlined its use of living-off-the-land tools, Windows Defender tampering, EDR-killing tooling, and encryption methods across Windows, Linux, and ESXi variants.
INC Ransomware was described as having operated since 2023, with one source more specifically stating the group has been active since July 2023.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
9 references tracked. Mallory keeps watching after this page renders.
hookphish.com
Open sourcemalware.news
Open sourcepicussecurity.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourcetheravenfile.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.