INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
ID: 92c8695e-74bc-5135-99b8-15469a449939
STIX ID: report--92c8695e-74bc-5135-99b8-15469a449939
Feed Name: CosmicBytez Labs
INC ransomware is a rapidly growing RaaS extortion group active since August 2023 that claims 830+ victims and has expanded by recruiting affiliates from disrupted groups (LockBit, BlackCat); the report details initial access vectors (vulnerability exploitation, VPN credential abuse, phishing), days-to-weeks dwell time for data exfiltration, cross-platform encryption modes (Windows and Linux/ESXi), use of legitimate remote-access tools for lateral movement, sectoral targeting (healthcare, education, manufacturing, critical infrastructure), a public data-leak site, and prioritized defensive measures (patching, MFA, network segmentation, monitoring for specific TTPs, and immutable backups).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
