logo

INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks

ID: 3b02eb37-3a77-5625-ad18-b26817c7b69f

STIX ID: report--3b02eb37-3a77-5625-ad18-b26817c7b69f

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Tushar Subhra Dutta

...
...

INC ransomware, active since mid-2023 and responsible for over 800 victims worldwide, has matured into a high-risk Ransomware-as-a-Service operation that now uses Rust-based cross-platform encryptors (Windows and Linux/ESXi), credential-theft tooling, legitimate remote-access abuse, and a double-extortion model that threatens public data leaks. The report details updated capabilities (partial encryption, Veeam-targeting, use of rclone/7-Zip/PsKill/Cobalt Strike), exploited CVEs used for initial access and credential theft, a set of IoCs, and recommended mitigations such as MFA, patching specific CVEs, and isolated offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.