CARDS
CARDS
INC Ransom is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in July 2023 and has rapidly become one of the most prolific cybercriminal groups, significantly increasing its activity in 2025 and 2026. The group is assessed with moderate confidence to be of Eastern European origin, with some reports linking it to Russian criminals. What distinguishes INC Ransom is its systematic targeting of sectors traditionally avoided by other ransomware groups, such as healthcare, education, and government, demonstrating a departure from informal cybercriminal 'rules'. They also uniquely employ methods such as printing ransom notes on network printers and changing desktop wallpapers to display demands. The group is also known as GOLD IONIC and is closely associated with Lynx ransomware, which is widely believed to be a successor or rebrand of INC Ransom, especially after INC Ransom reportedly sold its source code in 2024.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Identity
Targeting
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| FortiBleed Credential Exposure Campaign7,8,9,10 | FortiBleed Credential Exposure Campaign is retained in the campaign database for INC Ransom. FortiBleed is retained as a Fortinet/FortiGate credential-exposure campaign in which public reporting tied exposed or stolen Fortinet edge credentials to downstream ransomware activity involving INC Ransom and Lynx. IntelliOS treats FortiBleed as a campaign/operation context rather than proof that every exposed Fortinet environment was compromised or deployed with ransomware. |
| SonicWall SMA1000 Zero-Day Exploitation Campaign11,12,13,14,15 | SonicWall SMA1000 Zero-Day Exploitation Campaign is retained in the campaign database for INC Ransom. Attackers chained unauthenticated CVE-2026-15409 with CVE-2026-15410 to move from WebSocket proxy access to root-level execution on SonicWall SMA1000 appliances. Rapid7's public technical post confirms active exploitation, credential/session/TOTP theft, and lateral movement. Dark Reading reports that Rapid7 tied the activity to INC Ransom and that one case progressed to ransomware. Volexity independently tracks observed activity as UTA0533. |
Indicators
SOCRadar reports 53 IOCs for this profile. IntelliOS currently retains 39 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 4 source groups tracked; 2 currently contribute retained observable or context rows.
Retained Observables
Showing 39 of 39
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a54495 | Acronis |
| SHA-256 Hash | 1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac115 | Acronis |
| SHA-256 Hash | 24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db75 | Acronis |
| SHA-256 Hash | 31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc2755025 | Acronis |
| SHA-256 Hash | 589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe8805 | Acronis |
| SHA-256 Hash | 5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf2415 | Acronis |
| SHA-256 Hash | 60aeb9f7bccf377ff02ed64783e66a62c0f976878d9729b067bc7e5b0b9da9d65 | Acronis |
| SHA-256 Hash | 6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743f5 | Acronis |
| SHA-256 Hash | 6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf1415 | Acronis |
| SHA-256 Hash | 765508aa2ec6a1b73a76a23f4fa559d32355622748c91a46ed7b315eae2ee60a5 | Acronis |
| SHA-256 Hash | 7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb2455 | Acronis |
| SHA-256 Hash | 8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df45 | Acronis |
| SHA-256 Hash | 90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294c5 | Acronis |
| SHA-256 Hash | 97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce25 | Acronis |
| SHA-256 Hash | acce811c4fc2a6e3fddd4231e386f1648ca44f039d2d275316bc0a0fc96e0af45 | Acronis |
| SHA-256 Hash | bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efc5 | Acronis |
| SHA-256 Hash | d26bfb0147f60dc6500a9298d521ee67b49daaf4b8f8be54e7cc8fd86a5975705 | Acronis |
| SHA-256 Hash | d65120291dee76c694f8bea54841f7f68329b499b28f4aee5ea5c9369a7432cb5 | Acronis |
| SHA-256 Hash | dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7da5 | Acronis |
| SHA-256 Hash | ea721240c14e3d14f8d88e0020880448c6c602f1180a1e5dbe40871cfeedcc225 | Acronis |
| SHA-256 Hash | f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb3475 | Acronis |
| SHA-256 Hash | ff5da8f0330a4c581c37284c74aae2683c007dc6e406e1e2e6803e7bb398b77b5 | Acronis |
| Filename | INC Encryptor.exe6 | SentinelOne |
| Filename | INC-README.html6 | SentinelOne |
| Filename | INC-README.txt6 | SentinelOne |
| Filename | inc.exe6 | SentinelOne |
| File Path | C:\source\INC Encryptor\Release\INC Encryptor.pdb6 | SentinelOne |
| Tool / Process | anydesk.exe6 | SentinelOne |
| Tool / Process | bcdedit.exe6 | SentinelOne |
| Tool / Process | netscan.exe6 | SentinelOne |
| Tool / Process | ping.exe6 | SentinelOne |
| Tool / Process | psexec.exe6 | SentinelOne |
| Tool / Process | vssadmin.exe6 | SentinelOne |
| Tool / Process | wevtutil.exe6 | SentinelOne |
| Tool / Process | wmic.exe6 | SentinelOne |
| Network Indicator | inc-decrypt[.]onion6 | SentinelOne |
| Network Indicator | incblog[.]su5 | Acronis |
| Network Indicator | incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad[.]onion5 | Acronis |
| Network Indicator | incpaykabjqc2mtdxq6c23nqh4x6m5dkps5fr6vgdkgzp5njssx6qkid[.]onion5 | Acronis |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar2 | 53 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| Acronis TRU5 | N/A | 25 | Public observables retained and displayed. |
| SentinelOne6 | N/A | 14 | Public filenames, paths, tool, or infrastructure observables retained and displayed. |
| MITRE ATT&CK / CTI3 | N/A | 0 | Technique and identity context retained; not treated as raw IOC feed for this card. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | INC Ransom | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | INC Ransom | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor/ransomware | Baseline actor-card corpus source for retained profile fields. |
| 2 | SOCRadar Actor Profile https://socradar.io/free-tools/ransomware-intelligence/groups/inc-ransom | Per-actor SOCRadar profile source for ransomware profile metadata and IOC count when available. |
| 3 | MITRE ATT&CK https://attack.mitre.org/groups/G1032/ | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 4 | MITRE CTI https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json | Open MITRE CTI source used for ATT&CK enrichment. |
| 5 | Acronis TRU: The evolution of INC ransomware https://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/ | IOC Source |
| 6 | SentinelOne: Inc. Ransomware analysis https://www.sentinelone.com/anthology/inc-ransom/ | Threat Actor Profile |
| 7 | FortiBleed campaign linked to INC and Lynx ransomware operations https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/ | SOCRadar campaign row source for FortiBleed Credential Exposure Campaign. |
| 8 | Critical FortiBleed campaign https://www.recordedfuture.com/blog/critical-fortibleed-campaign | Recorded Future campaign row source for FortiBleed Credential Exposure Campaign. |
| 9 | FortiBleed campaign traced to INC and Lynx ransomware operations https://www.cybersecuritydive.com/news/fortibleed-campaign-traced-to-inc-and-lynx-ransomware-operations/824348/ | Cybersecurity Dive campaign row source for FortiBleed Credential Exposure Campaign. |
| 10 | FortiBleed credential theft linked to INC and Lynx ransomware https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html | The Hacker News campaign row source for FortiBleed Credential Exposure Campaign. |
| 11 | SonicWall PSIRT SNWLID-2026-0008 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 12 | CISA KEV Catalog https://www.cisa.gov/known-exploited-vulnerabilities-catalog | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 13 | Rapid7 SMA1000 zero-day analysis https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/ | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 14 | Volexity UTA0533 analysis https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
| 15 | Dark Reading INC reporting https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days | SonicWall, CISA, Rapid7, Volexity, NVD, and Dark Reading campaign row source for SonicWall SMA1000 Zero-Day Exploitation Campaign. |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for INC Ransom.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |