#Incransomware
Blue/Red Team, also #CISO, CIO and IT Dept - I've spent the last hours redacting an #incidentadvisory for you.

The #Sinobi RaaS is a rebrand of #Lynx - which has lineage from #INCRansomware - and uses no different TTPs.

Enjoy the cheatsheet: ransomnews.online/hub/ransomne...
July 5, 2025 at 1:15 PM
Just in: Another day, another ransomware attack! #DollarTree is the latest victim of the INC Ransomware gang, which claims to have stolen 1.2TB of sensitive data.

Read: hackread.com/inc-ransomwa...

#CyberSecurity #INCRansomware #Ransomware #CyberAttack #DataBreach
Inc Ransomware Claims 1.2TB Data Breach at Dollar Tree
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
July 30, 2025 at 1:35 PM
Ahold Delhaize confirms data breach of 2.2 million records amid #INCRansomware claims. Employee financial and health data at risk

More: hackread.com/ahold-delhai...

#Cybersecurity #DataBreach #AholdDelhaize #CyberAttack #Ransomware
Ahold Delhaize Confirms Data Breach of 2.2M amid INC Ransomware Claims
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
June 30, 2025 at 7:52 AM
Individuata una nuova campagna di distribuzione del #ransomware RaaS INC, che sta colpendo realtà operative in Italia 🇮🇹

www.cybertrends.it/inc-ransomwa...

#malware #INCransomware
INC Ransomware: identificata diffusione contro organizzazioni italiane - Rivista Cybersecurity Trends
È stata individuata una nuova campagna di distribuzione del ransomware INC, che sta colpendo realtà operative in Italia.  Questo malware,Leggi di più
www.cybertrends.it
April 17, 2025 at 8:37 AM
📢 Double note de rançon INC Ransomware : BYOVD et possible courtier d'accès initial impliqués

Huntress (blog.huntress.com), publié le 23 septembre 2026. L'analyse porte sur une attaque INC ransomware détectée fin août 2026 sur…

🟡 vérification factuelle moyenne
#BYOVD #INCRansomware #Cyberveille
Double note de rançon INC Ransomware : BYOVD et possible courtier d'accès initial impliqués
Huntress (blog.huntress.com), publié le 23 septembre 2026. L'analyse porte sur une attaque INC ransomware détectée fin août 2026 sur une organisation cliente, après l'installation de l'agent Huntress en réaction à un incident en cours.
cyberveille.ch
September 24, 2026 at 10:30 AM
SonicWall SMA 1000 appliances faced two exploited zero-days, chaining /wsproxy bypass and path traversal to gain root access. Activity tied to UTA0533 and INC Ransomware, with ROOTRUN and KNUCKLEBALL seen. #SonicWall #INCRansomware #UTA0533
Resecurity | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain
SonicWall’s SMA 1000 series was hit by two actively exploited zero-days, CVE-2026-15409 and CVE-2026-15410, which let attackers chain a pre-auth /wsproxy bypass and a path-traversal flaw to gain root access on exposed VPN appliances. The abuse was attributed to UTA0533 and later linked to INC Ransomware, with observed malware including ROOTRUN, KNUCKLEBALL, Suo5, and ORANGETAIL. #SonicWall #SMA1000 #CVE-2026-15409 #CVE-2026-15410 #UTA0533 #INCRansomware #ROOTRUN #KNUCKLEBALL #Suo5 #ORANGETAIL
www.hendryadrian.com
August 5, 2026 at 10:45 AM
A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.

#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #PotatoSecurity #UTA0533
August 3, 2026 at 2:29 AM
INC Ransomware Climbs Into Top Tier of Cybercrime Operations, Surpasses 830 Victims #BYOVDAttack #Incransomware #LockBit
INC Ransomware Climbs Into Top Tier of Cybercrime Operations, Surpasses 830 Victims
  The ransomware operation known as INC has grown into one of the most active cybercrime groups of 2026, with security researchers linking it to more than 830 victims since it first appeared in August 2023. According to researchers at Acronis, the group's rise coincided with disruptions affecting major ransomware brands such as LockBit and BlackCat. As affiliates sought alternative platforms, INC appears to have benefited from that shift. More than 65% of the victims listed by the group are based in the United States, with legal firms, healthcare providers, manufacturers, construction companies, and technology organizations among the most frequently targeted sectors. Researchers also observed major changes to the ransomware itself. INC's malware for Windows and Linux/VMware ESXi systems has been rewritten in Rust, a programming language increasingly adopted by malware developers because it supports multiple operating systems and can complicate reverse-engineering efforts. The group's toolkit has expanded as well. Recent attacks have involved a credential-stealing utility capable of extracting authentication data from newer Veeam backup deployments that use salted DPAPI encryption. Access to backup infrastructure can give attackers valuable credentials while also making recovery efforts more difficult for victims. Acronis noted that the sale of INC's Windows and Linux ransomware variants on underground cybercrime forums in May 2024 contributed to the appearance of related ransomware families, including Lynx and Sinobi. Researchers identified significant code similarities between the groups. Investigators found that INC affiliates rely on several entry points to compromise networks, including spear-phishing campaigns, credentials purchased from Initial Access Brokers (IABs), and the exploitation of publicly exposed systems running vulnerable versions of Citrix NetScaler, Fortinet EMS, and SimpleHelp software. Once inside a network, attackers harvest credentials, move between systems using legitimate administrative tools such as RDP and PsExec, and attempt to weaken security controls through a technique known as Bring Your Own Vulnerable Driver (BYOVD). Researchers observed the use of vulnerable drivers including filwfp.sys, filnk.sys, and fildds.sys. The group also deploys tools such as Cobalt Strike, AnyDesk, ScreenConnect, and TeamViewer to maintain access and control compromised environments. Before encryption begins, stolen files are collected and transferred using Rclone, often after being packaged into password-protected archives. The ransomware then encrypts systems using multithreading and partial-encryption techniques to speed up the process. When launched against VMware ESXi environments, the malware can also attempt to shut down virtual machines. Data from ZeroFox ranked INC as the fourth most active ransomware operation during the first quarter of 2026, recording more than 120 incidents. Researchers said the group's growth demonstrates how ransomware operators can build large-scale campaigns using widely available tools, stolen credentials, and unpatched systems rather than relying on highly specialized malware.
dlvr.it
June 19, 2026 at 3:29 PM
The Inc ransomware group claims breaches at Conveyors, Inc. and Greenology Products, exposing sensitive employee data, HR budgets, purchase orders, and corporate agreements. #IncRansomware #DataBreach #US
Inc Ransomware Breaches Conveyors, Inc. and Greenology Products
The Inc ransomware group claims to have compromised multiple organizations, posting a list of alleged victims that includes Conveyors, Inc. and Greenology Products. The allegedly exposed files include I-9 employee verification forms, internal employee lists and HR budgets, purchase orders, billing and delivery records, corporate agreements and NDAs, and internal memos....
www.hendryadrian.com
March 30, 2026 at 1:40 PM
February 25, 2026 at 1:00 AM