Executive Summary
Since August 2023, the INC ransomware group has rapidly evolved into a significant ransomware-as-a-service (RaaS) operation, claiming over 830 victims by June 2026. The group's attacks are characterized by the use of Rust-based encryptors for cross-platform compatibility and resistance to reverse engineering. They employ a diverse range of tools and techniques, including exploiting vulnerabilities in public-facing applications, credential dumping from Veeam backup servers, and utilizing living-off-the-land binaries (LOLBins) for lateral movement. Notably, INC has targeted unpatched edge devices for initial access and used commercial remote monitoring and management (RMM) tools for command-and-control operations.
The rise of INC ransomware underscores the adaptability of cybercriminals in leveraging existing vulnerabilities and tools to execute widespread attacks. Their success highlights the critical need for organizations to maintain up-to-date security measures, conduct regular vulnerability assessments, and implement robust incident response plans to mitigate the risks posed by such sophisticated ransomware operations.
Why This Matters Now
The rapid expansion of INC ransomware, with over 830 victims since August 2023, highlights the urgent need for organizations to bolster their cybersecurity defenses. The group's sophisticated tactics, including exploiting unpatched vulnerabilities and using advanced tools, pose a significant threat to various sectors. Immediate action is required to address these evolving threats and protect sensitive data.
Attack Path Analysis
The INC ransomware group initiates attacks by exploiting vulnerabilities in public-facing applications or using stolen credentials to gain initial access. Once inside, they escalate privileges by extracting sensitive credentials from compromised environments. They then move laterally using living-off-the-land binaries and remote desktop tools. For command and control, they deploy tools like Cobalt Strike and AnyDesk. Before encryption, they exfiltrate sensitive data using tools like Rclone. Finally, they execute the ransomware payload, encrypting files and demanding ransom.
Kill Chain Progression
Initial Compromise
Description
Attackers exploit vulnerabilities in public-facing applications such as Citrix Netscaler (CVE-2023-3519) and Fortinet EMS (CVE-2023-48788), or use stolen credentials to gain initial access.
Related CVEs
CVE-2023-3519
CVSS 9.8A code injection vulnerability in Citrix NetScaler ADC and Gateway allows unauthenticated remote code execution.
Affected Products:
Citrix NetScaler ADC and Gateway – 13.1 before 13.1-49.13, 13.0 before 13.0-91.13, 12.1 before 12.1-65.35, 12.0 before 12.0-63.24, 11.1 before 11.1-65.35
Exploit Status:
exploited in the wildCVE-2025-5777
CVSS 7.5A vulnerability in Citrix NetScaler ADC and Gateway could allow an attacker to bypass authentication.
Affected Products:
Citrix NetScaler ADC and Gateway – 13.1 before 13.1-50.28, 13.0 before 13.0-92.19, 12.1 before 12.1-66.47
Exploit Status:
exploited in the wildCVE-2023-48788
CVSS 9.8A vulnerability in Fortinet EMS allows remote code execution via crafted requests.
Affected Products:
Fortinet FortiClient EMS – 7.0.1 and below
Exploit Status:
exploited in the wildCVE-2024-57727
CVSS 9.8A vulnerability in SimpleHelp allows unauthenticated remote code execution.
Affected Products:
SimpleHelp SimpleHelp – 5.2.0 and below
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Exploit Public-Facing Application
Command and Scripting Interpreter
Valid Accounts
OS Credential Dumping
Remote Services: Remote Desktop Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Public-Facing Applications
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
INC ransomware's 830+ victim RaaS operation threatens patient data through lateral movement and exfiltration, requiring enhanced HIPAA compliance and zero trust segmentation.
Financial Services
Banking systems face critical risk from INC's expanded affiliate network post-LockBit disruption, demanding strengthened egress controls and encrypted traffic monitoring for regulatory compliance.
Government Administration
Public sector infrastructure vulnerable to INC's prolific ransomware operations, necessitating multicloud visibility, threat detection capabilities, and secure hybrid connectivity for critical services.
Information Technology/IT
IT service providers face heightened exposure as INC targets managed service environments, requiring Kubernetes security, cloud firewall protection, and comprehensive threat intelligence integration.
Sources
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.htmlVerified
- INC Ransomware: Tactics, Evolution, and Incident Response Guidehttps://www.provendata.com/blog/inc-ransomwareVerified
- Stolen data recovered from INC ransomware ganghttps://www.tech-arrow.com/2026/02/02/stolen-data-recovered-from-inc-ransomware-gang/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can significantly limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial access through exploited vulnerabilities or stolen credentials, it would likely limit the attacker's ability to move beyond the initially compromised workload.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust CNSF would likely limit the attacker's ability to use escalated privileges to access other workloads or sensitive data.
Control: East-West Traffic Security
Mitigation: Aviatrix Zero Trust CNSF would likely constrain the attacker's ability to move laterally by enforcing strict segmentation between workloads.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Zero Trust CNSF would likely limit the establishment of command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Zero Trust CNSF would likely restrict the attacker's ability to exfiltrate data by enforcing strict egress policies.
While Aviatrix Zero Trust CNSF may not prevent the execution of ransomware on the initially compromised workload, it would likely limit the blast radius by preventing the spread to other workloads.
Impact at a Glance
Affected Business Functions
- Legal Services
- Manufacturing Operations
- Construction Projects
- Technology Development
- Healthcare Services
Estimated downtime: 21 days
Estimated loss: $4,000,000
Sensitive client information, intellectual property, patient records, and proprietary business data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit attackers' ability to access critical systems.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized movements within the network.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration by controlling outbound traffic.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch public-facing applications to mitigate known vulnerabilities exploited by attackers.



