Overview

Platforms: —
Variants: —
Extensions: —
ATT&CK software: —
Initial access: Valid Accounts · Exploit Public-Facing Application · Phishing
Top countries: US · CA · AU · DE · IT
Observed sectors: Manufacturing · Professional Services · Healthcare · Technology · Construction
Tracked victims: 904

Victims

OnSolve / CodeRED CONFIRMED
November 2025 United States Technology
Technology organization in United States.
McLaren Health Care CLAIMED
July 2024 United States Healthcare
Healthcare organization in United States.
NHS Dumfries and Galloway CONFIRMED
March 2024 United Kingdom Healthcare
Healthcare organization in United Kingdom.
Xerox Business Solutions (U.S.) CLAIMED
December 2023 United States Professional Services
Professional Services organization in United States.

Operational Activity

Initial Access

Compromised credentials and external remote services
INC Ransom affiliates have used compromised or purchased valid credentials to access exposed infrastructure and remote services, including RDP and VPN environments.
Exploitation of public-facing applications
INC Ransom has exploited known vulnerabilities in internet-facing systems, including CVE-2023-3519 in Citrix NetScaler.
Spearphishing
Spearphishing has been reported as an initial-access method used in INC Ransom campaigns.

Recent Observations

Government advisory on INC Ransom operations
March 2026
Affiliate activity
The ACSC, CERT Tonga and New Zealand NCSC described INC Ransom as an active RaaS operation using credential abuse, vulnerability exploitation, data theft and encryption.
LOLBin activity before encryption
May 2024
Defense evasion
Huntress observed SystemSettingsAdminFlows.exe used to disable Windows Defender as part of recurring pre-ransomware activity associated with INC deployments.
RDP access, staging and ransomware deployment
August 2023
Intrusion activity
Huntress documented valid-account RDP access, internal reconnaissance, 7-Zip staging, MEGASync exfiltration, credential dumping, lateral movement and ransomware deployment across multiple systems.

TTPs

ATT&CK coverage: 21 techniques · 10 tactics
T1078 Valid Accounts
VERIFIED
Initial Access / Persistence
Compromised valid accounts are used to access victim environments.
T1190 Exploit Public-Facing Application
VERIFIED
Initial Access
INC Ransom has exploited public-facing systems, including CVE-2023-3519 in Citrix NetScaler.
T1566 Phishing
VERIFIED
Initial Access
Phishing and spearphishing have been reported in INC campaigns.
Show more TTPs (18)
T1021.001 Remote Desktop Protocol
VERIFIED
Lateral Movement
RDP is used for access and lateral movement.
T1219 Remote Access Tools
VERIFIED
Command and Control
AnyDesk and PuTTY have been observed on compromised systems.
T1560.001 Archive via Utility
VERIFIED
Collection
7-Zip and WinRAR are used to archive collected data before exfiltration.
T1074 Data Staged
VERIFIED
Collection
Collected data is staged before exfiltration.
T1537 Transfer Data to Cloud Account
VERIFIED
Exfiltration
MEGASync has been used for cloud-based exfiltration.
T1047 Windows Management Instrumentation
VERIFIED
Execution
WMIC has been used to deploy ransomware across endpoints.
T1569.002 Service Execution
VERIFIED
Execution
Service execution and PsExec have been used to launch ransomware.
T1570 Lateral Tool Transfer
VERIFIED
Lateral Movement
Ransomware executables have been copied to multiple endpoints before execution.
T1486 Data Encrypted for Impact
VERIFIED
Impact
INC Ransomware encrypts victim data for extortion.
T1685 Disable or Modify Tools
VERIFIED
Defense Evasion
SystemSettingsAdminFlows.exe has been used to disable Windows Defender.
T1070.004 File Deletion
VERIFIED
Defense Evasion
Tools have been removed or uninstalled after use.
T1105 Ingress Tool Transfer
VERIFIED
Command and Control
Additional tooling is downloaded to compromised systems.
T1036.005 Match Legitimate Resource Name or Location
VERIFIED
Defense Evasion
PsExec was renamed to winupd to resemble a legitimate Windows component.
T1046 Network Service Discovery
VERIFIED
Discovery
Network scanning is used during internal reconnaissance.
T1087.002 Domain Account
VERIFIED
Discovery
Domain administrator accounts are enumerated.
T1069.002 Domain Groups
VERIFIED
Discovery
Domain groups are enumerated on targeted hosts.
T1135 Network Share Discovery
VERIFIED
Discovery
Remote folders and network shares are inspected.
T1657 Financial Theft
VERIFIED
Impact
Stolen and encrypted data is used to pressure victims into ransom payment.

CVEs

Citrix — NetScaler ADC / NetScaler Gateway
Exploited by INC Ransom for initial access to internet-facing systems.
Associated since: November 2023

Infrastructure

Leak site
Tor-based data leak site
ONLINE
Last checked: September 16, 2026

Attribution

GOLD IONIC UNCONFIRMED
Vendor tracking name
Tarnished Scorpion UNCONFIRMED
Vendor tracking name

Relationships

Lynx UNCONFIRMED
Reported relationship
Unit 42 documented substantial source-code overlap between INC and Lynx after INC ransomware source code was offered for sale. The relationship is not treated as a simple alias because INC activity continued independently.

Affiliates

Vanilla Tempest
Microsoft-observed ransomware deployer associated with INC ransomware activity against the U.S. healthcare sector.
First seen: September 2024

Timeline

2026-09
Continued tracked activity
INC Ransom remained tracked as an active ransomware operation in September 2026.
2026-03
Joint government advisory
The ACSC, CERT Tonga and New Zealand NCSC published a joint advisory describing the continuing threat from INC Ransom and its affiliate network.
2025-11
OnSolve CodeRED disruption
The OnSolve CodeRED emergency-alert environment was disrupted in an incident attributed in public reporting to INC Ransom.
Show more events (6)
2024-09
Vanilla Tempest deployment activity
Vanilla Tempest was reported deploying INC ransomware against the U.S. healthcare sector.
2024-07
Lynx emerges
Unit 42 documented substantial source-code overlap between INC ransomware and Lynx ransomware.
2024-03
NHS Dumfries and Galloway breach
INC Ransom published a proof pack after the breach; the health board confirmed that published patient data was genuine.
2023-12
Xerox Business Solutions claim
INC Ransom claimed the compromise of Xerox Business Solutions in the United States; Xerox confirmed a security incident at the subsidiary.
2023-08
Early incident-response documentation
Huntress documented INC Ransom activity involving RDP access, collection, exfiltration, credential access, lateral movement and encryption.
2023-07
First observed activity
MITRE ATT&CK records INC Ransom activity from at least July 2023.

Sources