The INC ransomware group is rapidly evolving into one of the most active and dangerous actors in cybercrime. According to cybersecurity researchers, the organization, which emerged as a relatively unknown ransomware-as-a-service (RaaS), has recorded at least 830 victims since August 2023 , confirming that it is now one of the protagonists of the global cyber extortion ecosystem .

The collapse of competitors paved the way
Acronis experts point out that the neutralization of LockBit and the disruption of BlackCat 's activity created a significant gap in the ransomware market. INC immediately took advantage of the situation, attracting affiliates and partners who were looking for new platforms to continue their attacks.
The United States is at the heart of the group's operations, accounting for more than 65% of recorded incidents. The most targeted industries include legal services, manufacturing, construction, technology companies, and healthcare organizations.
See also: What you need to know about Ransomware-as-a-Service (RaaS)
Turning to Rust for greater efficiency
One of the standout elements of INC ransomware's strategy is its technological upgrade. The Windows and Linux/ESXi versions of the encryptors have been rewritten in the Rust programming language , a choice that offers greater flexibility in developing malware across multiple platforms.
At the same time, the use of Rust complicates the reverse engineering processes implemented by cybersecurity companies, making malware analysis more time-consuming and complex.
The team has also integrated an upgraded credential sniffing tool, which can target newer Veeam that use credential encryption via salted DPAPI.
The birth of new ransomware families
The sale of INC versions for Windows and Linux on the cybercrime darknet in May 2024 had another consequence. New ransomware families, such as Lynx and Sinobi, which bear a remarkable similarity in code to the original INC ransomware malware.

This phenomenon demonstrates that the modern ransomware ecosystem now operates with characteristics of a business model, where tools, source code, and know-how are traded and reused with the aim of creating new digital extortion operations.
See also: The Evolution of Ransomware in 2026: Techniques and Organizational Protection
The INC ransomware attack chain
INC attacks follow a highly methodical approach. Initial access to victims' networks is gained through targeted spear-phishing messages, purchasing stolen credentials from Initial Access Brokers, and exploiting known vulnerabilities in publicly accessible applications.
After compromising an environment, attackers proceed to extract sensitive credentials and use living-off-the-land binaries (LOLBins) tools , such as RDP and PsExec, to move laterally within the corporate network.
They then exploit the Bring Your Own Vulnerable Driver (BYOVD), using vulnerable system drivers to bypass or neutralize security defenses.
For remote management and control of compromised systems, well-known tools such as Cobalt Strike, AnyDesk, ScreenConnect and TeamViewer, while data extraction is carried out via Rclone after compression and password protection.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The final phase involves the execution of the encryptor, which leverages multithreading and partial encryption to accelerate the attack. In virtual environments, the malware even attempts to terminate virtual machines, maximizing the operational impact.
See also: RaaS: A growing threat in cyberspace

The new reality of ransomware
ZeroFox data ranks INC as the fourth most significant ransomware group in the first quarter of 2026, with more than 120 incidents, behind only the Qilin, Akira, and The Gentlemen.
The INC ransomware case proves that modern cybercrime groups do not necessarily need to develop cutting-edge tools or invest in highly sophisticated techniques. Systematic exploitation of known vulnerabilities, proper operational organization, and continuous improvement of available tools are enough to create a highly efficient digital extortion machine.
Particularly concerning is the fact that INC focuses on sectors where even a few hours of downtime can cause severe financial losses. The reliance of these organizations on uninterrupted services and complex supply chains significantly increases the risk of contagion to suppliers, partners and entire business ecosystems, making ransomware not just a technological but also a broader business threat.
