INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims
ID: 69df8a8f-11d1-5ea4-bf28-8fbfa685e94a
STIX ID: report--69df8a8f-11d1-5ea4-bf28-8fbfa685e94a
Feed Name: GBHackers
**INC ransomware overview:** The report describes how the INC ransomware family matured into a prolific 2026 ransomware operation (700–800+ victims) that uses double extortion, cross-platform Rust-built encryptors (Windows PE64 and Linux/ESXi ELF64), ESXi-targeting routines, advanced cryptography (Curve25519/X25519 plus AES/Salsa), credential dumping tailored to Veeam, and novel pressure tactics such as automated network printing of ransom notes; it lists IOCs and recommends patching exposed services, protecting backup credentials, monitoring for rclone and credential-dumping activity, and detecting unauthorized print jobs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
