INC Ransomware is a ransomware family used by the INC Ransom ransomware-as-a-service operation, active since 2023. It targets organizations worldwide, with healthcare prominently represented among its victims, alongside government and other enterprise organizations. The operation uses double extortion: affiliates steal sensitive information before encrypting systems and threaten to publish or sell the stolen data if payment is refused.
INC has Windows and Linux locker variants supporting multithreaded encryption and configurable encryption modes. The lockers can encrypt selected files, directories, network shares, and hidden or recovery volumes. Additional functionality includes process and service termination, console hiding, and shadow-copy deletion to hinder recovery. The Windows variant can register an automatically starting service running as LocalSystem. Ransom demands may be delivered through notes, desktop wallpaper changes, and connected printers.
Affiliates obtain access through credential-stealing phishing, purchased compromised credentials, exposed remote services, and exploitation of vulnerabilities in Citrix and Fortinet products. INC deployments have also followed Gootloader infections: Vanilla Tempest used the Supper backdoor before deploying INC in September 2024. Initial access brokers using the FortiBleed credential-compromise campaign have supplied access to INC-associated ransomware affiliates.
During intrusions, affiliates harvest credentials, abuse session tokens, move laterally using legitimate administrative tools, and establish persistence through services, scheduled tasks, remote-management software, and backdoors. They stage stolen data in archives and use cloud-transfer utilities for exfiltration. Defense evasion includes clearing logs, disabling security services, and bring-your-own-vulnerable-driver techniques to impair endpoint protection. These intrusion activities are performed by affiliates and supporting tools rather than necessarily being built into the INC encryptor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The following flaws have been exploited by INC affiliates: CVE-2023-4966 (Citrix Bleed) — Information disclosure vulnerability in Citrix NetScaler ADC / NetScaler Gateway.
The following flaws have been exploited by INC affiliates: CVE-2023-27997 — Remote code execution vulnerability in Fortinet FortiGate / FortiOS SSL-VPN.
The following flaws have been exploited by INC affiliates: CVE-2023-3519 — Remote code execution vulnerability in Citrix NetScaler ADC / NetScaler Gateway.
The following flaws have been exploited by INC affiliates: CVE-2023-48788 — SQL injection in Fortinet FortiClient EMS (Endpoint Management Server).
For SharePoint, CISA confirmed ransomware activity tied to CVE-2026-45659, a high-severity remote code execution flaw stemming from deserialization of untrusted data. It allows an attacker with low privileges to run arbitrary code on unpatched servers, and Microsoft has noted it can be exploited reliably in low-complexity attacks.
Separately, CISA linked ransomware activity to two SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410), including a maximum-severity server-side request forgery vulnerability.
Separately, CISA linked ransomware activity to two SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410), including a maximum-severity server-side request forgery vulnerability.
CVE-2025-5777 ... Authentication Bypass / Session Hijacking Citrix NetScaler ADC and Citrix Gateway 14.1 before 14.1-43.56 and 13.1 before 13.1-58.32 9.3 (Critical) 99.90% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
CVE-2024-57727 ... Path Traversal Leading to RCE SimpleHelp versions 5.5.7 and earlier 7.5 (High) 95.07% | INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2023-35082 ... IoCs ... CVE-2023-35082 SimpleHelp RMM vulnerability, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
Security teams are advised to ... patch known vulnerabilities including ... CVE-2024-4885 ... IoCs ... CVE-2024-4885 WhatsUp Gold RCE, used for initial access | INC ransomware has grown from a newcomer threat into one of the most dangerous ransomware operations worldwide. The group runs under a Ransomware-as-a-Service model. Both the Windows and Linux/ESXi encryptors have been fully rewritten in Rust.
This activity is significant as it may indicate an attempt to exploit CVE-2024-21378, where a custom MAPI form loads a potentially malicious DLL. If confirmed malicious, this could allow an attacker to execute arbitrary code, leading to further system compromise or data exfiltration.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ransomware locker malware itself has two known variants capable of targeting Linux and Windows systems.
Gootloader ... handing off access to Vanilla Tempest to load the Supper backdoor before deploying INC ransomware in September 2024.
An affiliate likely conducted at least five intrusions between February 2026 and April 2026, gaining initial access through internet-exposed FortiGate VPN appliances before deploying INC ransomware across VMware ESXi and Windows systems.
The affiliate mapped five SMB NAS shares to drive letters on a compromised Windows pivot and launched the Windows INC encryptor against those mapped drives.
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.
Microsoft revealed on Wednesday that its threat analysts have observed the financially motivated Vanilla Tempest threat actor using INC ransomware for the first time in an attack on the U.S. healthcare sector.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
184 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
143 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware linked to the FortiBleed campaign, in which attackers compromise internet-facing FortiGate devices using stolen or cracked credentials. The content does not describe INC Ransom's specific deployment or encryption behavior.
Ransomware linked to the FortiBleed campaign. SOCRadar connected the INC operation to the campaign after accessing its negotiation panel on a campaign server. The FBI describes FortiBleed-compromised access as an initial entry point for ransomware affiliates.
Ransomware whose operators reportedly purchase network footholds established through the FortiBleed credential-compromise campaign. The content does not describe its payload or encryption behavior.
Named ransomware whose affiliates are linked to purchasing access obtained through the FortiBleed credential-harvesting campaign. The article does not detail its technical behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.