INC Ransom is a Russia-linked ransomware-as-a-service operation active since at least mid-2023 and tracked by MITRE ATT&CK as G1032. The group is widely known as INC Ransom or IncRansom and has also been referred to as Gold Ionic, Tarnished Scorpius, and Water Anito. It conducts double-extortion intrusions, stealing data before encrypting systems and then using a leak site to pressure victims and advertise activity to affiliates. Public victim claims indicate a high operational tempo, with hundreds of organizations impacted globally and a concentration of victims in the United States. The group targets multiple sectors rather than a single industry, with observed victims spanning healthcare, manufacturing, business and professional services, government, logistics, agriculture, and technology. Reporting has associated it with damaging attacks against public-sector entities and other high-profile organizations in 2025 and 2026. Geographic victimology is broad across North America, Europe, Asia, and Africa, while available reporting notes an apparent absence of targeting in CIS countries and China. INC Ransom’s tradecraft emphasizes speed, automation, and abuse of legitimate enterprise administration mechanisms more than novel malware design. Observed operations show rapid progression from initial access to domain-wide ransomware deployment, often within a short dwell time. The group has been linked to exploitation of edge infrastructure for initial access, including SonicWall SMA 1000 Series zero-days CVE-2026-15409 and CVE-2026-15410. After gaining privileged access, operators have used Active Directory, Group Policy Objects, Impacket, remote management tooling, custom scripts, and common Windows LOLBins to propagate across domain-joined systems. Documented behavior includes uploading startup scripts through SYSVOL, disabling or weakening Microsoft Defender and User Account Control, downloading payloads through native utilities, and executing ransomware at scale from centralized policy mechanisms. The malware associated with the group is tracked by MITRE ATT&CK as S1139. Analyzed samples have been described as Rust-based and multithreaded, using hybrid public-key and symmetric encryption. The ransomware is operationally integrated into a broader intrusion workflow that may also involve credential theft, session theft, lateral movement toward domain controllers, and earlier-stage data exfiltration. Analysts have assessed that the consistency of these procedures suggests comparatively strong central control over affiliates within the RaaS model. INC Ransom has also been linked in reporting to the Lynx ransomware operation based on code and operational similarities, and separate research has connected both brands to broader campaigns involving mass exploitation and custom tooling. Overall, INC Ransom is best characterized as a mature, high-volume cybercriminal enterprise whose effectiveness derives from disciplined orchestration, scalable post-compromise automation, and reliable use of standard administrative pathways to achieve enterprise-wide impact.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
INC ransomware is known to gain access to their target victims through spear phishing, valid account credentials from Initial Access Brokers (IAB) and exploitation of vulnerabilities in public-facing applications such as CVE-2023-3519 (Citrix Netscaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM) and CVE-2025-5777 (Citrix Bleed 2).
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
55 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against Health Law Advocates, a U.S.-based non-profit public interest law firm.
Conducting a ransomware attack resulting in a data breach against autismuslink.ch / Stiftung Autismuslink in Switzerland.
Conducting a ransomware attack against Cabin Creek Health Systems, a healthcare organization in the United States.
Ransomware group described as maintaining continuous monthly victim claims since 2023 and being based in Russia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.