The Containment Era is here. →Explore

Executive Summary

Since August 2023, the INC ransomware group has rapidly evolved into a significant ransomware-as-a-service (RaaS) operation, claiming over 830 victims by June 2026. The group's attacks are characterized by the use of Rust-based encryptors for cross-platform compatibility and resistance to reverse engineering. They employ a diverse range of tools and techniques, including exploiting vulnerabilities in public-facing applications, credential dumping from Veeam backup servers, and utilizing living-off-the-land binaries (LOLBins) for lateral movement. Notably, INC has targeted unpatched edge devices for initial access and used commercial remote monitoring and management (RMM) tools for command-and-control operations.

The rise of INC ransomware underscores the adaptability of cybercriminals in leveraging existing vulnerabilities and tools to execute widespread attacks. Their success highlights the critical need for organizations to maintain up-to-date security measures, conduct regular vulnerability assessments, and implement robust incident response plans to mitigate the risks posed by such sophisticated ransomware operations.

Why This Matters Now

The rapid expansion of INC ransomware, with over 830 victims since August 2023, highlights the urgent need for organizations to bolster their cybersecurity defenses. The group's sophisticated tactics, including exploiting unpatched vulnerabilities and using advanced tools, pose a significant threat to various sectors. Immediate action is required to address these evolving threats and protect sensitive data.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

INC ransomware attacks have highlighted vulnerabilities in organizations' patch management processes, insufficient monitoring of remote access tools, and inadequate incident response plans, emphasizing the need for comprehensive compliance measures.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it can significantly limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial access through exploited vulnerabilities or stolen credentials, it would likely limit the attacker's ability to move beyond the initially compromised workload.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust CNSF would likely limit the attacker's ability to use escalated privileges to access other workloads or sensitive data.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix Zero Trust CNSF would likely constrain the attacker's ability to move laterally by enforcing strict segmentation between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Zero Trust CNSF would likely limit the establishment of command and control channels by monitoring and controlling outbound communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Zero Trust CNSF would likely restrict the attacker's ability to exfiltrate data by enforcing strict egress policies.

Impact (Mitigations)

While Aviatrix Zero Trust CNSF may not prevent the execution of ransomware on the initially compromised workload, it would likely limit the blast radius by preventing the spread to other workloads.

Impact at a Glance

Affected Business Functions

  • Legal Services
  • Manufacturing Operations
  • Construction Projects
  • Technology Development
  • Healthcare Services
Operational Disruption

Estimated downtime: 21 days

Financial Impact

Estimated loss: $4,000,000

Data Exposure

Sensitive client information, intellectual property, patient records, and proprietary business data.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement and limit attackers' ability to access critical systems.
  • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized movements within the network.
  • Utilize Egress Security & Policy Enforcement to prevent unauthorized data exfiltration by controlling outbound traffic.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
  • Regularly update and patch public-facing applications to mitigate known vulnerabilities exploited by attackers.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image