# INC Ransomware Masters the Basics: Why a Simplistic Playbook Remains Devastatingly Effective
A relatively young ransomware-as-a-service (RaaS) operation has quietly become one of the most active threat groups in the digital threat landscape—not through sophisticated zero-day exploits or cutting-edge techniques, but by executing fundamental attack methods with disciplined precision. Security researchers at Acronis have documented how INC, an affiliate-driven ransomware gang that emerged in 2023, has claimed more than 800 victims worldwide by focusing on proven intrusion techniques and carefully selecting targets in sectors where operational disruption carries maximum financial and reputational leverage.
The group's ascendancy tells an important story about modern cybercriminal economics: in an era where sophisticated vulnerabilities and advanced persistent threat (APT) tactics dominate security headlines, a well-organized criminal enterprise can achieve remarkable scale by simply executing the fundamentals faster, more aggressively, and more reliably than defenders can respond.
## The Threat: A Double Extortion Powerhouse
INC operates as a double extortion ransomware actor, employing two concurrent pressure tactics to coerce payment from victims. The group encrypts critical business systems—forcing operational shutdown—while simultaneously exfiltrating sensitive data and threatening public disclosure of proprietary information, trade secrets, or personal records if ransom demands go unpaid. This dual-lever approach creates compounding pressure: organizations face both immediate business continuity crises and potential regulatory fines, customer notification obligations, and reputational damage.
Since its emergence in 2023, INC has demonstrated sustained growth that researchers attribute largely to strategic timing. The group benefited significantly from the disruption of two previously dominant RaaS operations: the FBI-led takedown of ALPHV/BlackCat in early 2024 and ongoing operational disruptions to LockBit's infrastructure. As established players faced law enforcement pressure and operational chaos, INC filled a market vacuum—similar to how lesser-known gangs like The Gentlemen expanded during the same period.
According to Santiago Pontiroli, threat intelligence research lead at Acronis Threat Research Unit (TRU), INC's growth stems from three concrete operational advantages:
## Background and Context: The RaaS Model's Staying Power
Understanding INC requires context about how modern ransomware operates. Unlike earlier ransomware campaigns that relied on mass infection and spray-and-pray distribution, contemporary RaaS platforms function as criminal franchises. Threat actors ("affiliates") purchase or lease access to ransomware code, negotiation services, decryption negotiation platforms, and money laundering infrastructure operated by core criminal organizations. The core group handles backend operations—malware development, ransom negotiation, cryptocurrency laundering—while affiliates focus on reconnaissance, initial access, lateral movement, and encryption deployment.
This model has proven remarkably resilient. Law enforcement takedowns of specific RaaS platforms degrade but do not eliminate ransomware activity; they simply redistribute pressure across competing criminal organizations. INC exemplifies this dynamic. When ALPHV and LockBit faced heat, operational capacity and affiliate relationships migrated to less-disrupted platforms. INC positioned itself as a reliable, professionally-run alternative.
The group targets a genuinely diverse victim portfolio spanning manufacturing, legal services, healthcare, technology, construction, and education sectors. However, Acronis researchers noted that INC demonstrates a strategic preference for organizations holding especially sensitive data—a calculation that amplifies extortion leverage beyond pure encryption damage.
## Technical Details: Effective, Not Novel
INC's operational playbook relies on intrusion methods that security teams have understood for years:
Initial Access Vectors:
Lateral Movement & Persistence:
Encryption & Exfiltration:
None of these techniques represent cutting-edge innovation. Organizations with mature security hygiene—multi-factor authentication, vulnerability patching, endpoint detection and response (EDR) tools, and security awareness training—can defend against each tactic. INC's effectiveness derives not from bypassing defenses through sophisticated means, but from exploiting environments where security fundamentals remain incomplete or inconsistently applied.
## Why Healthcare? The Perfect Victim Profile
INC's repeated targeting of healthcare organizations—including NHS Dumfries & Galloway and Alder Hey Children's Hospital in Liverpool—reveals the group's strategic victim selection logic. Healthcare institutions present an ideal ransomware target profile:
When a hospital's electronic health record (EHR) system goes offline, administrators face genuine life-safety considerations. This operational reality creates asymmetric negotiating pressure—healthcare organizations often face stronger internal pressure to pay ransom quickly than organizations in less time-critical sectors.
## The Affiliate Model: Scale Through Distribution
INC's growth strategy relies on rapidly onboarding affiliate partners who conduct the actually dangerous, customer-facing intrusion work. This distribution model offers several advantages:
Researchers note that INC's rapid affiliate growth has been unusually aggressive compared to competitors, suggesting either significant financial incentives or explicit recruitment campaigns targeting experienced ransomware operators displaced by competing platforms' disruptions.
## Implications for Organizations
INC's success pattern carries important implications for cybersecurity strategy across all sectors:
Vulnerability patching remains critical. Citrix Bleed and similar publicly-disclosed vulnerabilities form core elements of INC's intrusion toolkit. Organizations that consistently patch known vulnerabilities eliminate a major attack surface.
Credential compromise represents the path of least resistance. Initial access brokers derive their inventory from credential theft, phishing, and account takeover. Strong multi-factor authentication, credential monitoring, and security awareness training directly counter this vector.
Healthcare organizations face disproportionate pressure. The operational realities of patient care create psychological leverage that attackers actively exploit. Healthcare providers should treat ransomware defense as a patient safety issue, not a technology budget line item.
EDR and monitoring matter at scale. Organizations deploying mature endpoint detection and response tools have significantly higher probability of detecting lateral movement before encryption deployment.
## Recommendations: Defending Against INC and Similar Groups
Organizations should prioritize these concrete defensive measures:
Immediate actions:
Medium-term priorities:
Governance:
---
## HackWire Analysis
INC's rise reveals something uncomfortable about cybersecurity's current state: sophisticated zero-day exploits and advanced persistent threat campaigns dominate industry discussion and academic research, yet the ransomware groups claiming the largest victim counts succeed through methodical execution of decade-old attack fundamentals. This is not a gap between headline-making threats and actual risk—it's a misalignment between where defenders concentrate resources and where attackers find success.
The timing of INC's emergence is particularly telling. Within months of law enforcement disrupting ALPHV and LockBit, a replacement operation scaled to 800+ victims. This demonstrates that ransomware-as-a-service isn't an exploitable vulnerability in criminal infrastructure; it's a persistent business model with multiple viable operators. Disrupting one platform doesn't eliminate the underlying demand or affiliate network—it simply creates market consolidation. INC filled that vacuum, and others will follow when enforcement pressure returns.
For healthcare organizations specifically, the pattern is darker still. INC's repeated targeting of NHS trusts and children's hospitals suggests deliberate targeting of institutions where operational disruption carries maximum emotional and regulatory pressure. Attackers understand institutional vulnerabilities at a level that security teams often miss: they're not just exploiting technical security gaps, they're exploiting the operational reality that hospital administrators face genuine life-and-death tradeoffs that corporate executives do not. This institutional asymmetry converts technical compromise into effective extortion.
The defensive implication is equally clear: ransomware defense for healthcare cannot remain a technology-budget problem. It must become a patient safety governance issue, integrated into hospital quality committees and board-level risk management the way infection control and medication safety are treated. Organizations waiting for perfect security posture before focusing on ransomware defense will continue providing profitable targets.
— *HackWire Editorial*
---
## Related Coverage