logo

INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

ID: 6f5e6d63-72cf-5880-a1e7-d68b42217003

STIX ID: report--6f5e6d63-72cf-5880-a1e7-d68b42217003

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: [email protected] (The Hacker News)

...
...

INC ransomware has evolved into a prolific RaaS operation since August 2023, claiming roughly 830 victims (more than 65% in the U.S.) and targeting sectors such as legal, manufacturing, construction, technology and health care; its Windows and Linux/ESXi encryptors have been rewritten in Rust, it uses an updated credential dumper that targets Veeam salted DPAPI credentials, exploits multiple public-facing CVEs for initial access, employs living-off-the-land and commercial RMM tools for lateral movement, uses BYOVD drivers to disable defenses, stages and exfiltrates data with Rclone, and supports hands-on operator control (including an --esxi argument to shut down VMs); the group's code sale has spawned related families (Lynx, Sinobi) and ZeroFox data ranked INC fourth in Q1 2026 with over 120 incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.