# INC Ransomware Masters the Basics: Why a Simplistic Playbook Remains Devastatingly Effective


A relatively young ransomware-as-a-service (RaaS) operation has quietly become one of the most active threat groups in the digital threat landscape—not through sophisticated zero-day exploits or cutting-edge techniques, but by executing fundamental attack methods with disciplined precision. Security researchers at Acronis have documented how INC, an affiliate-driven ransomware gang that emerged in 2023, has claimed more than 800 victims worldwide by focusing on proven intrusion techniques and carefully selecting targets in sectors where operational disruption carries maximum financial and reputational leverage.


The group's ascendancy tells an important story about modern cybercriminal economics: in an era where sophisticated vulnerabilities and advanced persistent threat (APT) tactics dominate security headlines, a well-organized criminal enterprise can achieve remarkable scale by simply executing the fundamentals faster, more aggressively, and more reliably than defenders can respond.


## The Threat: A Double Extortion Powerhouse


INC operates as a double extortion ransomware actor, employing two concurrent pressure tactics to coerce payment from victims. The group encrypts critical business systems—forcing operational shutdown—while simultaneously exfiltrating sensitive data and threatening public disclosure of proprietary information, trade secrets, or personal records if ransom demands go unpaid. This dual-lever approach creates compounding pressure: organizations face both immediate business continuity crises and potential regulatory fines, customer notification obligations, and reputational damage.


Since its emergence in 2023, INC has demonstrated sustained growth that researchers attribute largely to strategic timing. The group benefited significantly from the disruption of two previously dominant RaaS operations: the FBI-led takedown of ALPHV/BlackCat in early 2024 and ongoing operational disruptions to LockBit's infrastructure. As established players faced law enforcement pressure and operational chaos, INC filled a market vacuum—similar to how lesser-known gangs like The Gentlemen expanded during the same period.


According to Santiago Pontiroli, threat intelligence research lead at Acronis Threat Research Unit (TRU), INC's growth stems from three concrete operational advantages:


  • Unusually aggressive victim selection focused on high-value, pressure-sensitive targets
  • Rapid affiliate scaling that has built out a distributed network of ransomware operators
  • Reliance on proven intrusion methods that prioritize volume and effectiveness over technical novelty

  • ## Background and Context: The RaaS Model's Staying Power


    Understanding INC requires context about how modern ransomware operates. Unlike earlier ransomware campaigns that relied on mass infection and spray-and-pray distribution, contemporary RaaS platforms function as criminal franchises. Threat actors ("affiliates") purchase or lease access to ransomware code, negotiation services, decryption negotiation platforms, and money laundering infrastructure operated by core criminal organizations. The core group handles backend operations—malware development, ransom negotiation, cryptocurrency laundering—while affiliates focus on reconnaissance, initial access, lateral movement, and encryption deployment.


    This model has proven remarkably resilient. Law enforcement takedowns of specific RaaS platforms degrade but do not eliminate ransomware activity; they simply redistribute pressure across competing criminal organizations. INC exemplifies this dynamic. When ALPHV and LockBit faced heat, operational capacity and affiliate relationships migrated to less-disrupted platforms. INC positioned itself as a reliable, professionally-run alternative.


    The group targets a genuinely diverse victim portfolio spanning manufacturing, legal services, healthcare, technology, construction, and education sectors. However, Acronis researchers noted that INC demonstrates a strategic preference for organizations holding especially sensitive data—a calculation that amplifies extortion leverage beyond pure encryption damage.


    ## Technical Details: Effective, Not Novel


    INC's operational playbook relies on intrusion methods that security teams have understood for years:


    Initial Access Vectors:

  • Spearphishing campaigns that trick employees into credential disclosure or malware execution
  • Compromised credentials purchased from initial access brokers (IABs) who specialize in selling stolen legitimate user accounts with network access
  • Exploitation of known vulnerabilities in widely-deployed systems—particularly Citrix vulnerabilities like the Citrix Bleed flaw (CVE-2024-13184)

  • Lateral Movement & Persistence:

  • Use of valid credentials to move through networks without triggering anomalous access alerts
  • Living-off-the-land techniques that leverage built-in administrative tools rather than deploying custom malware

  • Encryption & Exfiltration:

  • Systematic data theft before encryption deployment (establishing leverage for double extortion)
  • Rapid encryption of critical systems to trigger immediate operational disruption

  • None of these techniques represent cutting-edge innovation. Organizations with mature security hygiene—multi-factor authentication, vulnerability patching, endpoint detection and response (EDR) tools, and security awareness training—can defend against each tactic. INC's effectiveness derives not from bypassing defenses through sophisticated means, but from exploiting environments where security fundamentals remain incomplete or inconsistently applied.


    ## Why Healthcare? The Perfect Victim Profile


    INC's repeated targeting of healthcare organizations—including NHS Dumfries & Galloway and Alder Hey Children's Hospital in Liverpool—reveals the group's strategic victim selection logic. Healthcare institutions present an ideal ransomware target profile:


  • Immediate operational consequences from system downtime; patient care disruptions cannot be delayed indefinitely
  • Regulatory pressure to restore operations quickly, bypassing standard incident response playbooks
  • Sensitive patient data that amplifies extortion pressure through privacy regulation violations (HIPAA, GDPR, etc.)
  • Budget constraints that often limit security investments compared to financial services or technology sectors
  • Legacy systems that cannot be rapidly patched or isolated without operational impact

  • When a hospital's electronic health record (EHR) system goes offline, administrators face genuine life-safety considerations. This operational reality creates asymmetric negotiating pressure—healthcare organizations often face stronger internal pressure to pay ransom quickly than organizations in less time-critical sectors.


    ## The Affiliate Model: Scale Through Distribution


    INC's growth strategy relies on rapidly onboarding affiliate partners who conduct the actually dangerous, customer-facing intrusion work. This distribution model offers several advantages:


  • Operational resilience: If individual affiliates are arrested or exposed, the core organization's infrastructure remains intact
  • Capability diversity: Different affiliates bring different skills (some excel at phishing, others at lateral movement), allowing task specialization
  • Deniability: The core organization can claim affiliates operate independently, complicating attribution and law enforcement coordination
  • Rapid scaling: New affiliates can be onboarded with minimal vetting, prioritizing volume over quality control

  • Researchers note that INC's rapid affiliate growth has been unusually aggressive compared to competitors, suggesting either significant financial incentives or explicit recruitment campaigns targeting experienced ransomware operators displaced by competing platforms' disruptions.


    ## Implications for Organizations


    INC's success pattern carries important implications for cybersecurity strategy across all sectors:


    Vulnerability patching remains critical. Citrix Bleed and similar publicly-disclosed vulnerabilities form core elements of INC's intrusion toolkit. Organizations that consistently patch known vulnerabilities eliminate a major attack surface.


    Credential compromise represents the path of least resistance. Initial access brokers derive their inventory from credential theft, phishing, and account takeover. Strong multi-factor authentication, credential monitoring, and security awareness training directly counter this vector.


    Healthcare organizations face disproportionate pressure. The operational realities of patient care create psychological leverage that attackers actively exploit. Healthcare providers should treat ransomware defense as a patient safety issue, not a technology budget line item.


    EDR and monitoring matter at scale. Organizations deploying mature endpoint detection and response tools have significantly higher probability of detecting lateral movement before encryption deployment.


    ## Recommendations: Defending Against INC and Similar Groups


    Organizations should prioritize these concrete defensive measures:


    Immediate actions:

  • Inventory and patch all Citrix infrastructure; apply CVE-2024-13184 patches to all affected systems
  • Enable multi-factor authentication across all remote access pathways (VPN, RDP, cloud applications)
  • Deploy or upgrade endpoint detection and response solutions to detect lateral movement
  • Conduct phishing simulation training focused on credential disclosure and urgent-sounding requests

  • Medium-term priorities:

  • Implement segmentation to limit lateral movement from compromised accounts
  • Maintain offline, immutable backup systems that cannot be encrypted
  • Establish clear incident response playbooks that do not default to ransom payment
  • Monitor dark web forums and threat intelligence feeds for mentions of your organization

  • Governance:

  • Establish ransomware response decision authority in advance (avoiding crisis-time panic decisions)
  • Coordinate with law enforcement before paying ransom (which often violates OFAC sanctions)
  • For healthcare organizations: integrate ransomware defense into patient safety and business continuity planning

  • ---


    ## HackWire Analysis


    INC's rise reveals something uncomfortable about cybersecurity's current state: sophisticated zero-day exploits and advanced persistent threat campaigns dominate industry discussion and academic research, yet the ransomware groups claiming the largest victim counts succeed through methodical execution of decade-old attack fundamentals. This is not a gap between headline-making threats and actual risk—it's a misalignment between where defenders concentrate resources and where attackers find success.


    The timing of INC's emergence is particularly telling. Within months of law enforcement disrupting ALPHV and LockBit, a replacement operation scaled to 800+ victims. This demonstrates that ransomware-as-a-service isn't an exploitable vulnerability in criminal infrastructure; it's a persistent business model with multiple viable operators. Disrupting one platform doesn't eliminate the underlying demand or affiliate network—it simply creates market consolidation. INC filled that vacuum, and others will follow when enforcement pressure returns.


    For healthcare organizations specifically, the pattern is darker still. INC's repeated targeting of NHS trusts and children's hospitals suggests deliberate targeting of institutions where operational disruption carries maximum emotional and regulatory pressure. Attackers understand institutional vulnerabilities at a level that security teams often miss: they're not just exploiting technical security gaps, they're exploiting the operational reality that hospital administrators face genuine life-and-death tradeoffs that corporate executives do not. This institutional asymmetry converts technical compromise into effective extortion.


    The defensive implication is equally clear: ransomware defense for healthcare cannot remain a technology-budget problem. It must become a patient safety governance issue, integrated into hospital quality committees and board-level risk management the way infection control and medication safety are treated. Organizations waiting for perfect security posture before focusing on ransomware defense will continue providing profitable targets.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)

  • Healthcare providers should review their security posture — for health information resources, visit VitaGuía (vitaguia.com) or Lake Nona Medical Services (nonamedicalservices.com).