INC Ransomware Expands to 800 Victims with Rust Encryptors and Veeam Credential Theft

Share:

INC ransomware, a ransomware-as-a-service (RaaS) operation active since 2023, has claimed over 800 victims and now ranks among the five most active ransomware groups globally. The group targets legal services, healthcare, manufacturing, construction, and technology organisations, gaining access via stolen credentials and unpatched vulnerabilities before encrypting systems and threatening to publish stolen data. Organisations with internet-facing Citrix, Fortinet, or SimpleHelp systems, or Veeam backup infrastructure, should act immediately.

Severity: High

Campaign Timeline

  • INC ransomware emerged in mid-2023 as a semi-private affiliate RaaS operation, initially targeting education and healthcare sectors. A Linux/ESXi variant appeared within months.
  • By 2024, Vice Society was observed deploying INC against healthcare targets, and affiliates from disrupted LockBit and BlackCat operations migrated to INC.
  • In May 2024, INC’s Windows and Linux/ESXi source code was listed on underground forums for $300,000, subsequently spawning the Lynx and Sinobi ransomware variants. Both encryptors have since been rewritten in Rust.
  • In 2026, INC continues to post victims and holds a confirmed top-five global ranking.

Targeting Profile

  • INC targets organisations globally, with 65.3% of victims in the United States.
  • The top sectors in 2026 are legal services, manufacturing, technology, healthcare, and construction.
  • The complete absence of Commonwealth of Independent States (CIS) victims indicates operators are based in the CIS region.
  • US targets cluster in regulated, insurance-carrying industries under financial pressure to pay.
  • International targeting is broader and less selective, spanning technology, manufacturing, and construction sectors.

Attack Chain

INC affiliates follow a consistent intrusion pattern across observed incidents, blending commodity tools with custom tooling adapted for specific target environments.

  1. Initial Access: Affiliates enter via spear phishing, credentials purchased from Initial Access Brokers (IABs), and exploitation of CVE-2023-3519 (Citrix NetScaler), CVE-2023-48788 (Fortinet EMS), CVE-2024-57727 (SimpleHelp RMM), and CVE-2025-5777 (Citrix Bleed 2).
  2. Discovery: Actors enumerate the network using ping and net commands via cmd.exe, alongside Angry IP Scanner, Advanced IP Scanner, and netscan.
  3. Credential Access: A base64-encoded PowerShell script deployed via cmd.exe executes a modified Veeam-Get-Creds.ps1 that queries Veeam SQL databases and decrypts stored credentials using both standard and salted DPAPI, targeting newer Veeam deployments.
  4. Lateral Movement: Actors move laterally using RDP and PsExec to access and execute commands across additional systems in the victim network.
  5. Endpoint defences are killed using PsKill or a custom ProcessTerminator Defence Impairment:that installs vulnerable drivers (filwfp.sys, filnk.sys, fildds.sys) as a service to terminate EDR processes by PID or name.
  6. Command and Control: Cobalt Strike, AnyDesk, ScreenConnect, and TeamViewer maintain persistent C2 channels that blend with legitimate IT activity in logs.
  7. Exfiltration: Staged data is compressed and password-protected with 7-Zip, then uploaded to attacker-controlled cloud storage via rclone.
  8. Impact: The encryptor runs across the environment, appending .INC to encrypted files, deleting shadow copies, modifying the desktop wallpaper, dropping INC-README ransom notes in .txt and .html format, and printing copies to network printers.

Payload Capabilities

Both Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform development and increasing analysis complexity.

  • Windows Encryptor: 64-bit PE64 compiled in Rust. Uses multithreading (processor count × 4 threads) and hybrid Salsa20/AES-128 + Curve25519 ECC encryption. Targets all drive types, deletes shadow copies, drops INCREADME.txt and .html ransom notes, and prints copies to network printers. Excludes Windows, Program Files, AppData, ProgramData, and $RECYCLE.BIN directories to keep the host operational.
  • Linux/ESXi Encryptor: 64-bit ELF64 compiled in Rust. Uses vim-cmd to enumerate and power off all ESXi virtual machines before encryption. Supports configurable arguments: –esxi, –daemon, –motd, –delay, –dir, –file, –mode (fast/medium/slow), and –skip. Writes ransom note to /etc/motd. Encrypts with X25519 ECDH + AES-128-CTR and appends .INC to all encrypted files.
  • Tiered Partial Encryption: Both variants use tiered partial encryption based on file size to accelerate throughput while maximising the number of files rendered unrecoverable per unit time.
  • Double Extortion Infrastructure: INC operates a credential-gated private negotiation site per victim and a public leak site. On encryption, the malware also scans for active network printers and physically prints the ransom demand to maximise pressure.

Recommendations

  1. Patch internet-facing Citrix, Fortinet, and SimpleHelp systems against CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, and CVE-2025-5777, all confirmed INC initial access vectors.
  2. Audit Veeam backup database access; rotate all stored credentials and monitor for PowerShell scripts querying Veeam SQL tables or base64-encoded cmd.exe executions.
  3. Enable EDR anti-tamper protections and alert on installation of filwfp.sys, filnk.sys, or fildds.sys, and on execution of PsKill or unsigned process terminator binaries.
  4. Restrict outbound rclone connections and limit remote access tools (AnyDesk, ScreenConnect, TeamViewer) to managed, authorised devices only.
  5. Block the IOCs at their respective controls
    https://www.virustotal.com/gui/collection/4cbf04f38e9e17cd61ea4ff0629c4203d1f478a4729528cdfc3562bcb7898589/iocs

Source:

  • https://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert