INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks
ID: 3b02eb37-3a77-5625-ad18-b26817c7b69f
STIX ID: report--3b02eb37-3a77-5625-ad18-b26817c7b69f
Feed Name: cybersecurityNews.com
INC ransomware, active since mid-2023 and responsible for over 800 victims worldwide, has matured into a high-risk Ransomware-as-a-Service operation that now uses Rust-based cross-platform encryptors (Windows and Linux/ESXi), credential-theft tooling, legitimate remote-access abuse, and a double-extortion model that threatens public data leaks. The report details updated capabilities (partial encryption, Veeam-targeting, use of rclone/7-Zip/PsKill/Cobalt Strike), exploited CVEs used for initial access and credential theft, a set of IoCs, and recommended mitigations such as MFA, patching specific CVEs, and isolated offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
