logo

INC Ransomware Explained: How It Attacks Healthcare and Education

ID: 5253e693-ebc2-5a09-85e9-1dd3e8ca770b

STIX ID: report--5253e693-ebc2-5a09-85e9-1dd3e8ca770b

Feed Name: Picus Security Articles

Threat Score
78/100

Date Published: 2026-07-29

Date Updated: 2026-07-29

Author: [email protected] (Umut Bayram)

...
...

INC Ransom is a multi-extortion ransomware group active since July 2023 that targets healthcare, industrial, and education organizations in the US and Europe. The report describes their use of living-off-the-land tools (NETSCAN.EXE, AnyDesk, SystemSettingsAdminFlows.exe), exploitation of Citrix CVEs for initial access, Defender tampering and EDR-killing utilities, credential harvesting (lsassy.py), data staging/exfiltration (7-Zip, MEGASync, rclone), and ransomware families that employ Salsa20/AES/Curve25519 on Windows and X25519/AES-128-CTR on Linux/ESXi, including operator-configurable options that can render systems non-bootable and support double-extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.