Overview
Platforms:
—
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
Valid Accounts · Exploit Public-Facing Application · Phishing
Top countries:
US · CA · AU · DE · IT
Observed sectors:
Manufacturing · Professional Services · Healthcare · Technology · Construction
Tracked victims:
904
Victims
OnSolve / CodeRED
CONFIRMED
Technology organization in United States.
McLaren Health Care
CLAIMED
Healthcare organization in United States.
NHS Dumfries and Galloway
CONFIRMED
Healthcare organization in United Kingdom.
Xerox Business Solutions (U.S.)
CLAIMED
Professional Services organization in United States.
Operational Activity
Initial Access
Compromised credentials and external remote services
INC Ransom affiliates have used compromised or purchased valid credentials to access exposed infrastructure and remote services, including RDP and VPN environments.
Exploitation of public-facing applications
INC Ransom has exploited known vulnerabilities in internet-facing systems, including CVE-2023-3519 in Citrix NetScaler.
Spearphishing
Spearphishing has been reported as an initial-access method used in INC Ransom campaigns.
Recent Observations
Government advisory on INC Ransom operations
March 2026
Affiliate activity
The ACSC, CERT Tonga and New Zealand NCSC described INC Ransom as an active RaaS operation using credential abuse, vulnerability exploitation, data theft and encryption.
LOLBin activity before encryption
May 2024
Defense evasion
Huntress observed SystemSettingsAdminFlows.exe used to disable Windows Defender as part of recurring pre-ransomware activity associated with INC deployments.
RDP access, staging and ransomware deployment
August 2023
Intrusion activity
Huntress documented valid-account RDP access, internal reconnaissance, 7-Zip staging, MEGASync exfiltration, credential dumping, lateral movement and ransomware deployment across multiple systems.
TTPs
ATT&CK coverage:
21 techniques
· 10 tactics
T1078
Valid Accounts
VERIFIEDInitial Access / Persistence
Compromised valid accounts are used to access victim environments.
T1190
Exploit Public-Facing Application
VERIFIEDInitial Access
INC Ransom has exploited public-facing systems, including CVE-2023-3519 in Citrix NetScaler.
Show more TTPs (18)
T1021.001
Remote Desktop Protocol
VERIFIEDLateral Movement
RDP is used for access and lateral movement.
T1219
Remote Access Tools
VERIFIEDCommand and Control
AnyDesk and PuTTY have been observed on compromised systems.
T1560.001
Archive via Utility
VERIFIEDCollection
7-Zip and WinRAR are used to archive collected data before exfiltration.
T1537
Transfer Data to Cloud Account
VERIFIEDExfiltration
MEGASync has been used for cloud-based exfiltration.
T1047
Windows Management Instrumentation
VERIFIEDExecution
WMIC has been used to deploy ransomware across endpoints.
T1569.002
Service Execution
VERIFIEDExecution
Service execution and PsExec have been used to launch ransomware.
T1570
Lateral Tool Transfer
VERIFIEDLateral Movement
Ransomware executables have been copied to multiple endpoints before execution.
T1685
Disable or Modify Tools
VERIFIEDDefense Evasion
SystemSettingsAdminFlows.exe has been used to disable Windows Defender.
T1105
Ingress Tool Transfer
VERIFIEDCommand and Control
Additional tooling is downloaded to compromised systems.
T1036.005
Match Legitimate Resource Name or Location
VERIFIEDDefense Evasion
PsExec was renamed to winupd to resemble a legitimate Windows component.
T1046
Network Service Discovery
VERIFIEDDiscovery
Network scanning is used during internal reconnaissance.
T1657
Financial Theft
VERIFIEDImpact
Stolen and encrypted data is used to pressure victims into ransom payment.
CVEs
Citrix
— NetScaler ADC / NetScaler Gateway
Exploited by INC Ransom for initial access to internet-facing systems.
Associated since:
November 2023
Infrastructure
Leak site
Tor-based data leak site
ONLINE
Last checked:
September 16, 2026
Attribution
GOLD IONIC
UNCONFIRMED
Vendor tracking name
Tarnished Scorpion
UNCONFIRMED
Vendor tracking name
Relationships
Lynx
UNCONFIRMED
Reported relationship
Unit 42 documented substantial source-code overlap between INC and Lynx after INC ransomware source code was offered for sale. The relationship is not treated as a simple alias because INC activity continued independently.
Affiliates
Vanilla Tempest
Microsoft-observed ransomware deployer associated with INC ransomware activity against the U.S. healthcare sector.
First seen:
September 2024
Timeline
2026-09
Continued tracked activity
INC Ransom remained tracked as an active ransomware operation in September 2026.
2026-03
Joint government advisory
The ACSC, CERT Tonga and New Zealand NCSC published a joint advisory describing the continuing threat from INC Ransom and its affiliate network.
2025-11
OnSolve CodeRED disruption
The OnSolve CodeRED emergency-alert environment was disrupted in an incident attributed in public reporting to INC Ransom.
Show more events (6)
2024-09
Vanilla Tempest deployment activity
Vanilla Tempest was reported deploying INC ransomware against the U.S. healthcare sector.
2024-07
Lynx emerges
Unit 42 documented substantial source-code overlap between INC ransomware and Lynx ransomware.
2024-03
NHS Dumfries and Galloway breach
INC Ransom published a proof pack after the breach; the health board confirmed that published patient data was genuine.
2023-12
Xerox Business Solutions claim
INC Ransom claimed the compromise of Xerox Business Solutions in the United States; Xerox confirmed a security incident at the subsidiary.
2023-08
Early incident-response documentation
Huntress documented INC Ransom activity involving RDP access, collection, exfiltration, credential access, lateral movement and encryption.
2023-07
First observed activity
MITRE ATT&CK records INC Ransom activity from at least July 2023.
Sources
INC Ransom Affiliate Model Enabling Targeting of Critical Networks
Australian Cyber Security Centre / CERT Tonga / New Zealand NCSC
Show more sources (10)
LOLBin to INC Ransomware
Huntress
Ransomware Spotlight: INC
Trend Micro
Lynx Ransomware: A Rebranding of INC Ransomware
Palo Alto Networks Unit 42
OnSolve CodeRED cyberattack
BleepingComputer
McLaren Health Care says data breach impacts 743,000 patients
BleepingComputer
Xerox confirms security incident at subsidiary
The Register
INC Ransom activity tracking
Ransomware.live