INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Inc Ransomware Emerges as Major Threat in 2026

| 2026-06-18 14:12 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is shifting rapidly, with ransomware-as-a-service (RaaS) groups like INC continuing to evolve and expand their operations. Their ability to target various sectors, including healthcare, legal services, technology, and construction, has made them a major concern for organizations worldwide. Inc's diversification of tools and techniques, such as the use of living-off-the-land binaries and credential dumpers, has enabled it to adapt quickly to changing security landscapes. As researchers like Darrel Virtusio at Acronis have noted, INC's success lies in its ability to leverage widely known techniques without requiring advanced tradecraft or bespoke tooling, making them a formidable force in the cybercrime world.
Technical Mitigations AI-generated
* Implement regular security updates and patches for Windows and Linux systems to prevent exploitation of known vulnerabilities. * Use a reputable antivirus software and keep it up-to-date to detect and block ransomware attacks. * Conduct thorough vulnerability scanning on networks and devices before allowing remote access or use of sensitive data. * Educate users about phishing scams, spear-phishing, and other social engineering tactics used by ransomware attackers. * Implement multi-factor authentication (MFA) whenever possible to prevent unauthorized access to systems and data.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
RansomHubRansomHubQilinQilinINC RansomwareINC RansomwareBlackCatBlackCatALPHVALPHVCobalt StrikeCobalt Strike CVE-2025-5777CVE-2025-5777 CVE-2023-48788CVE-2023-48788 CVE-2024-57727CVE-2024-57727 CVE-2023-3519CVE-2023-3519
Target & Sectors
NORTH_AMERICA NORTH_AMERICA manufacturingmanufacturing healthhealth legallegal technologytechnology healthcarehealthcare mediamedia
Incident Timeline
‎August 2023
Inc's ransomware-as-a-service operation has evolved into a major threat with 830+ victims since August 2023.
tactic Ransomware
victims 830 Victims
organisation Vulnerability / Enterprise Security
general_metric 18  Jun
general_metric 2026  Jun
organisation LockBit
organisation INC
organisation DPAPI
infrastructure Windows
infrastructure Linux
organisation Windows and Linux
‎May 2024
Ransomware groups, including those affiliated with INC ransomware, utilize a diverse range of tools and techniques to target victims.
tactic Ransomware
infrastructure Windows
infrastructure Linux
organisation Sinobi
organisation CVE-2023-3519
organisation CVE-2023-48788
organisation CVE-2025
organisation Fortinet EMS
organisation SimpleHelp
organisation PsExec
organisation ScreenConnect
organisation TeamViewer
organisation RMM
organisation Rclone
‎late 2025
Incident Topic: Ransomware threat emerges as major ransomware-as-a-service (RaaS) attack in late 2025.
‎Q1 2026
Threat actors used INC ransomware to target 338+ victims since Q1 2023.
tactic Ransomware
organisation ZeroFox
organisation INC ransomware
malware Qilin
general_metric 338 Qilin
general_metric 197 Akira
general_metric 192 Gentlemen
general_metric 120 incidents
‎2026/06/17
Researchers with security vendor Acronis published a blog post covering RaaS gang INC, a group that emerged in 2023 and has claimed more than 800 victims to date.
organisation RaaS gang INC
victims 800 victims
‎Jun 18, 2026
Threat actors used a ransomware attack tool to target organizations in the Middle East and North Africa region.
‎2026/06/18
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023.
victims 830 Victims
financial 3 backup rule
organisation Mastering the Basics
organisation LockBit
organisation INC
organisation Sinobi
infrastructure Windows
infrastructure Linux
organisation CVE-2023-3519
organisation CVE-2023-48788
organisation CVE-2025
organisation Fortinet EMS
organisation SimpleHelp
organisation ZeroFox
organisation Cl0p
organisation NHS Dumfries & Galloway
organisation Alder Hey Children's Hospital
organisation Advanced IP
organisation the Acronis Threat Research Unit
organisation EDR
organisation Pontiroli
organisation ClickFix Delivery INC's
organisation YARA
Tactical Metrics
Metrics
victims
830
Victims
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
financial
3
Backup Rule
Metrics
victims
800
Victims
Intelligence Sources