INC Ransom is a financially motivated ransomware-as-a-service operation that emerged in 2023 and became one of the more active extortion groups by 2026. The group is known for double-extortion operations in which data is stolen prior to encryption and victims are pressured through leak-site publication and negotiation portals. Common aliases include INC, INC Ransom, INC Ransomware, and Gold Ionic. Lynx is widely assessed as a closely related successor, rebrand, or evolved variant of the same broader criminal ecosystem, and some reporting has identified operational overlap between the two brands. INC Ransom has targeted organizations across multiple sectors worldwide, including healthcare, education, government, manufacturing, technology, construction, legal services, and professional services. Reporting in 2026 indicated a notable focus on legal-sector victims, likely because of the coercive value of confidential case materials, settlement records, and other sensitive business documents. The group has also been associated with attacks affecting nonprofits and public-interest organizations. The operation follows a typical affiliate-driven intrusion model. Initial access has been associated with spearphishing, use of valid accounts obtained from initial access brokers, exploitation of vulnerable internet-facing applications, abuse of exposed remote services, and credential-based compromise of perimeter infrastructure. Once inside a network, operators conduct reconnaissance, identify domain controllers and other high-value systems, dump credentials, escalate privileges, move laterally with legitimate administrative tooling, exfiltrate sensitive data, and then deploy ransomware for impact. Public reporting and ATT&CK-aligned analysis have associated the group with techniques including Valid Accounts, credential theft, remote services abuse, command and scripting interpreters, account manipulation, privilege escalation, remote system discovery, local data collection, exfiltration, and data encryption for impact. INC Ransom has shown cross-platform capability. Exposed affiliate infrastructure in 2026 revealed active Windows and Linux encryptor development and deployment activity, including Rust-based Linux tooling compiled for a broad range of processor architectures. That infrastructure also showed evidence of enterprise-focused tradecraft such as Active Directory enumeration, Kerberos ticket handling, password cracking activity, VPN-enabled victim access, and targeted exfiltration of sensitive business data. These observations indicate a mature operational model oriented toward large heterogeneous environments rather than opportunistic single-host encryption. Multiple 2026 investigations linked INC Ransom to the FortiBleed credential-harvesting campaign targeting Fortinet FortiGate devices. Researchers reported direct evidence that an operator tied to FortiBleed infrastructure had access to INC Ransom negotiation systems, and victim overlap suggested that stolen firewall and VPN access was being operationalized for downstream ransomware deployment. Those findings support the assessment that INC Ransom either works closely with, or purchases access from, organized initial access broker activity. Separate reporting described FortiBleed as likely run by a Russian-speaking criminal team, but public evidence does not conclusively establish INC Ransom itself as a state-sponsored actor. INC Ransom is recognized in MITRE ATT&CK as a cybercriminal group associated with double-extortion ransomware activity. The group’s growth has been attributed to aggressive affiliate recruitment, sustained operational tempo, and the broader reshaping of the ransomware market after disruption of other major crews. By 2026, it had claimed hundreds of victims that year alone and was widely regarded as a prolific and operationally mature extortion threat.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware and data extortion attack against the LGBTQ Center of Orange County, claiming responsibility for the intrusion, exfiltrating confidential data, and threatening to publish the stolen dataset unless ransom demands were met.
Referenced as part of the ransomware ecosystem linked to FortiBleed-derived access, with an operator observed logged into its negotiation panel.
Ransomware group linked by researchers to the FortiBleed credential-theft campaign; stolen FortiGate credentials were assessed to have been passed to or directly used by this group for ransomware deployment, and some FortiBleed organizations appeared in INC victim lists.
Ransomware-as-a-service operation conducting broad ransomware attacks across multiple industries, with recent prioritization of legal sector organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.