INC Ransom is a ransomware-as-a-service (RaaS) operation active since mid-2023/August 2023 that uses double-extortion tactics, combining file encryption with theft and threatened publication of stolen data via negotiation and leak sites. It has been described as one of the most active ransomware operations in 2026, with reporting linking it to more than 800 victims worldwide, including more than 830 claimed victims. Targeting has included healthcare, education, manufacturing, government, legal services, construction, technology, and professional services, with a strong concentration of U.S.-based victims.
Observed initial access methods include compromised credentials, purchases from initial access brokers, exposed remote services, phishing, and exploitation of vulnerable internet-facing systems. Reported exploited technologies and vulnerabilities associated with INC activity include Citrix NetScaler ADC/Gateway (including CVE-2023-3519 and CVE-2025-5777), Fortinet FortiClient EMS (CVE-2023-48788), and SimpleHelp vulnerabilities. SOCRadar also linked FortiBleed, a large-scale credential-harvesting campaign against FortiGate devices, to downstream deployment of INC Ransom; researchers found an operator logged into both FortiBleed infrastructure and the INC negotiation panel, overlap between FortiBleed victims and organizations later listed by INC, and at least 12 ransomware deployments tied to FortiBleed-derived access.
Post-compromise behavior attributed to INC includes reconnaissance of domain controllers, backup infrastructure, virtualization platforms, file servers, and sensitive data repositories; credential dumping; privilege escalation; lateral movement using legitimate administrative tools and compromised accounts; and data exfiltration prior to encryption. Tools and techniques reported in INC intrusions include RDP, PsExec, PowerShell, Windows Management Instrumentation/wmic.exe, Cobalt Strike, AnyDesk, ScreenConnect, TeamViewer, 7-Zip, and rclone. INC has also been reported using a modified Veeam credential-dumping utility capable of extracting credentials from newer Veeam deployments protected with salted DPAPI encryption. For defense evasion and impact, affiliates have used Bring Your Own Vulnerable Driver techniques and vulnerable drivers including filwfp.sys, filnk.sys, and fildds.sys.
The malware has evolved technically: both Windows and Linux/ESXi encryptors were reported as fully rewritten in Rust, with cross-platform capability, multithreading, and partial-encryption modes to accelerate impact. Linux/ESXi variants can attempt to shut down virtual machines. Reported functionality includes deleting volume shadow copies, using wmic.exe to spread to multiple endpoints, identifying external USB and hard drives for encryption, identifying printers, and printing ransom notes. INC ransom notes observed in reporting include INC-README.TXT and INCRSA.README.TXT, and victims are directed to private negotiation portals.
INC has known relationships and overlaps with other ransomware families. Lynx emerged in 2024 and is widely assessed in the provided reporting as a rebrand, evolved variant, or code-related family derived from INC after underground sale of INC source code in 2024; Sinobi is also described as related. Reporting also notes Microsoft observed the financially motivated threat actor Vanilla Tempest using INC ransomware in an attack on the U.S. healthcare sector, and Microsoft linked Fox Tempest to affiliates and families including INC. Additional reporting tied INC to healthcare-sector attacks and noted a detection name of Troj/Inc-Gen in one identified incident.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-48788 ... SQL Injection Leading to RCE Fortinet FortiClient EMS 7.2.0 through 7.2.2 and 7.0.1 through 7.0.10 9.3 (Critical) 98.53% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2025-5777 ... Authentication Bypass / Session Hijacking Citrix NetScaler ADC and Citrix Gateway 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32 9.3 (Critical) 99.90% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2023-3519 ... Unauthenticated Remote Code Execution Citrix NetScaler ADC and Citrix Gateway 13.1 before 13.1-49.13 and 13.0 before 13.0-91.13 9.8 (Critical) 99.34% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2024-57727 ... Path Traversal Leading to RCE SimpleHelp versions 5.5.7 and earlier 7.5 (High) 95.07% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2023-35082 ... IoCs ... CVE-2023-35082 SimpleHelp RMM vulnerability, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2024-4885 ... IoCs ... CVE-2024-4885 WhatsUp Gold RCE, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2023-4966 ... IoCs ... CVE-2023-4966 Citrix Bleed (NetScaler), used for credential theft | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
This activity is significant as it may indicate an attempt to exploit CVE-2024-21378, where a custom MAPI form loads a potentially malicious DLL. If confirmed malicious, this could allow an attacker to execute arbitrary code, leading to further system compromise or data exfiltration.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Discovered in mid-2023, INC ransomware is another RaaS group that employs double extortion tactics... In its most recent iteration, both payloads are rewritten in Rust.
Microsoft revealed on Wednesday that its threat analysts have observed the financially motivated Vanilla Tempest threat actor using INC ransomware for the first time in an attack on the U.S. healthcare sector.
INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.
The ransomware-as-a-service (RaaS) group Tarnished Scorpius (aka INC Ransomware) has listed on its leak site an Israeli industrial machinery company, and replaced the company logo with a swastika.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
User awareness training. Regularly educate staff on phishing, social engineering and other tactics used by ransomware operators. | INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
the actors deployed a custom process terminator that drops vulnerable drivers (filwfp.sys, filnk.sys, fildds.sys) and installs them as a service.
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
deploy a base64 encoded script through cmd.exe. cmd.exe /Q /c powershell.exe -e ...
INC attackers gain initial access to victim organizations through spear phishing, valid account credentials obtained from initial access brokers, and exploitation of vulnerabilities in public-facing applications.
Exfiltrated data from an Asia-Pacific manufacturing copmany revealed the attacker specifically targeted Active Directory DPAPI backup master keys, which would enable offline decryption of all domain-protected credentials... At the root of the loot directory are three files containing Active Directory DPAPI backup master keys.
After gaining access, it’s been observed through multiple incidents that INC ransomware actors have performed discovery techniques through ping and net commands through cmd.exe.
Other than built-in commands, there were also cases where they have used tools like Angry IP scanner, Advanced IP scanner and netscan.
By invoking the native GetSystemInfo Windows API, the binary retrieves the active dwNumberOfProcessors core count metric.
To maximize the scope of its deployment, the payload initiates a systematic discovery loop targeting all connected storage infrastructure... iterating sequentially through the alphabet... identifies active volumes, distinguishing between local fixed disks, removable media and mapped network shares.
To move laterally within the victim’s environment, INC ransomware actors use living-off-the-land binaries (LOLBins), including remote desktop protocol (RDP)...
A second directory... hosted 1,853 files... sitting alongside encryptors, reconnaissance logs, and exfiltrated victim data... Two ZIP archives named after a victim company contained 884 files organized by data category; board reports, HR databases, domain controller data, etc.
Victims who refuse to pay face not only locked systems but also the exposure of sensitive corporate records on INC’s data leak site.
On January 28, 2026, the INC Ransom ransomware group claimed responsibility for the cyber attack on the LGBTQ Center of Orange County
the control flow falls through to a diagnostic block referencing the cleartext string literal "Successfully deleted shadow copies from "
Upon successful encryption, the malware modifies the host's desktop wallpaper to display the extortion demands and drops both .txt and .html versions of the INC-README note.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
99 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation linked in the reporting to FortiBleed-derived access via an operator observed logged into its negotiation panel.
Ransomware-as-a-Service operation active since mid-2023, described as targeting healthcare, education, and government organizations.
A ransomware-as-a-service operation linked in this report to the use of FortiGate credentials harvested via FortiBleed for ransomware deployment.
A ransomware-as-a-service operation active since mid-2023 that is explicitly linked in the article to FortiBleed-derived access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.