# INC Ransomware Emerges as Dominant RaaS Threat, Claiming 830+ Victims Since August 2023
Cybersecurity researchers have documented a dramatic rise in INC ransomware operations, transforming the group from a nascent ransomware-as-a-service (RaaS) platform into one of 2026's most prolific cybercrime enterprises. With more than 830 confirmed victims since its debut in August 2023, INC has positioned itself as a dominant force in the ransomware landscape—and its strategic innovations in code architecture and operational tactics suggest the threat will only accelerate in coming months.
## The Threat: Scale and Prevalence
INC has achieved remarkable market penetration in less than three years of operation. According to data compiled by ZeroFox, INC ranked as the fourth most prominent ransomware group during Q1 2026, accounting for over 120 separate incidents in just three months. This places INC behind only Qilin (338 incidents), Akira (197), and The Gentlemen (192)—but significantly ahead of legacy operations still operating in 2026.
The geographic distribution of INC's targets reveals a distinctly American-focused campaign: United States organizations represent more than 65% of all documented victims. However, the group operates a truly global extortion business, with victims spanning multiple continents and sectors.
Industry targeting data shows deliberate sector selection rather than opportunistic spray-and-pray attacks. The most frequently compromised sectors include:
This diversification across sectors—combined with geographic reach—indicates a mature, professionally managed criminal enterprise with multiple affiliate partners and a sophisticated victim selection strategy.
## Background and Context: The RaaS Succession
INC's explosive growth cannot be understood without examining the wider ransomware ecosystem disruptions of 2024-2025. The takedown of LockBit, historically the largest ransomware-as-a-service operation, and the voluntary shutdown of BlackCat (also known as ALPHV) created a significant power vacuum in the cybercriminal underworld.
"The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations," said Acronis researcher Darrel Virtusio. This migration pattern is not anomalous—when major platforms collapse, their affiliate networks typically seek alternative providers rather than exit the ransomware business entirely. INC's technical sophistication, reliable payment processing, and active development made it an attractive landing zone for displaced LockBit and BlackCat affiliates.
The group's evolution has also been accelerated by strategic decisions about code distribution. In May 2024, INC's Windows and Linux variants were offered for sale on the cybercrime underground, effectively commoditizing the ransomware source code itself. This move—similar to historical releases by other major groups—spawned derivative malware families including Lynx and Sinobi, which demonstrate "significant code overlap" with the original INC payloads. The emergence of these variants suggests INC variants may eventually account for a larger portion of overall ransomware activity than INC's branded operations alone.
## Technical Details: Engineering for Scale and Stealth
INC's technical architecture reveals a group that has learned from predecessors' operational failures. The most significant recent development is the complete rewrite of both Windows and Linux/ESXi encryptors in Rust.
### Why Rust Matters
The choice of Rust as INC's development language is strategic and revealing:
| Benefit | Impact |
|---------|--------|
| Cross-platform compatibility | Single codebase runs on Windows, Linux, and ESXi systems |
| Reverse engineering resistance | Compiled Rust binaries are significantly harder to analyze than C/C++ equivalents |
| Memory safety | Eliminates entire classes of buffer overflow and use-after-free vulnerabilities in the malware itself |
| Reduced maintenance burden | Fewer variants needed to target different platforms |
This architectural shift demonstrates INC's investment in long-term operational sustainability—a hallmark of mature criminal enterprises rather than ad-hoc cybercriminal groups.
### The Attack Chain
INC's operational playbook has been thoroughly documented by multiple security firms. The standardized attack sequence includes:
1. Initial Access
- Citrix NetScaler (CVE-2023-3519, CVE-2025-5777)
- Fortinet EMS (CVE-2023-48788)
- SimpleHelp (CVE-2024-57727)
2. Credential Extraction
INC has developed an updated credential dumper specifically engineered to target modern Veeam backup deployments. Earlier versions relied on straightforward credential extraction, but Veeam's adoption of salted DPAPI encryption (Data Protection API with salt randomization) forced INC to develop new extraction techniques. This arms race between defenders and attackers represents the continuous evolution of enterprise backup security.
3. Lateral Movement
INC affiliates leverage both "living off the land" binaries and commercial tools:
4. Defense Evasion
A particularly notable technique is the bring-your-own-vulnerable-driver (BYOVD) attack pattern, using legitimate but vulnerable drivers to disable security controls:
filwfp.sys — Windows Filtering Platform driverfilnk.sys — Windows Ink driverfildds.sys — DirectDraw Surface driverThese drivers contain known vulnerabilities that, when abused, can disable Windows Defender, AppLocker, and other endpoint protection mechanisms.
5. Data Exfiltration
Before encryption, INC stages sensitive files as password-protected archives and exfiltrates them using Rclone—a legitimate file synchronization tool that provides obfuscation benefits over direct data theft tools.
6. Encryption and Ransom
The final payload includes a command-line interface for operator control during hands-on deployments. Notable features include:
--esxi flag) that shut down virtual machines to prevent recovery## Implications: Supply Chain and Sector Risk
The sectors INC targets are not chosen randomly—they represent industries where operational downtime creates immediate, measurable financial damage. A manufacturing facility losing production for 24 hours faces concrete revenue loss. A construction project delayed by ransomware incurs sub-contractor penalties and timeline slippage. Healthcare systems face imminent patient safety risks and regulatory reporting requirements.
Supply chain amplification poses an additional risk layer. When a manufacturer is compromised, downstream partners—distributors, retailers, logistics companies—may all suffer cascading disruptions. Legal services firms often maintain sensitive data from multiple corporate clients, creating a "data concentration" risk where a single breach affects dozens of organizations.
The group's careful attention to industry selection and operational pressure points demonstrates sophisticated business acumen: INC operates less like opportunistic cybercriminals and more like a predatory consulting firm, identifying where pain creates willingness to pay.
## Recommendations: Defensive Strategies
Organizations in targeted sectors should implement layered defenses:
---
## HackWire Analysis
INC's rise is not accidental—it reflects a fundamental truth about ransomware markets that law enforcement disruptions often miss. When LockBit fell, FBI agents and international partners celebrated a major victory. But within months, a dozen alternative platforms emerged to service the displaced affiliate networks. INC's particular success stems from three factors that takedowns cannot eliminate: technical competence, reliable financial infrastructure, and operational discipline.
The Rust rewrite deserves special attention here. It signals that INC is not a short-term criminal enterprise building for quick exits; it's a long-term operation investing in architectural improvements that pay dividends across years. This level of software engineering sophistication suggests either direct employment of skilled developers or partnerships with established cybercriminal infrastructure providers. Either way, it indicates INC has access to capital and operational stability that most ransomware groups lack.
The commoditization of INC's source code through the emergence of Lynx and Sinobi variants reveals another uncomfortable truth: ransomware, as a category, is no longer dependent on any single group's operational survival. The playbooks are documented. The code is available. The targets are known. What matters now is organizational execution and market access—and INC has both.
For defenders, the real risk is not INC specifically, but what INC represents: a mature, scalable, professionally managed criminal operation operating at industrial scale with no technological barriers preventing competitors from replicating its success. The sectors being targeted—healthcare, legal, manufacturing, construction—are not targeted because they're the easiest, but because they have the highest willingness to pay. Until that fundamental economic equation changes, expect INC's victim count to continue climbing.
— HackWire Editorial
---
## Related Coverage