Home/Threat Actor/INC Ransom
Threat Actor

INC Ransom

inc_ransom · russia_speaking_cybercrime · active since 2023-07

INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber + The Register industry tracking.

Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 19, 2024 industry naming dispute "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks... Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest" - curated as standalone with acknowledgment similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET dispute) is a Ransomware-as-a-Service operation active since July 2023 with canonical double-extortion model (encryption + data theft + threat to leak via leak site if ransom not paid)

Russia-speaking organized cybercrime attribution via SentinelOne + ReliaQuest (canonical August 2024 attack analysis "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month") + Black Point Cyber canonical TTP profile + Cybersecurity- Help May 14, 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute.

standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

operational target profile healthcare primary (NHS Dumfries Galloway Scotland March 2024 with 3TB threatened release of patient clinical data + Boston Children's adjacent) + education (Radford Public School + Afpa) + government (Pennsylvania AG November 2025 third Pennsylvania state entity ransomware breach following 2020 + 2017 prior incidents) + food retail (Ahold Delhaize) + manufacturing (Yamaha Motor Philippines October 25, 2023 employee data theft) + technology services (Xerox Business Solutions first canonical victim) + charities + U.S. + Canada + Europe + UK + Philippines geographic range per ReliaQuest; operational attack architecture: (1) cluster- defining Citrix NetScaler CVE-2023-3519 initial access exploit per SentinelOne + spearphishing email initial access.

(2) lateral movement to sensitive file harvest + download for ransom leverage.

(3) cluster-defining Impacket + Rclone tradecraft per ReliaQuest August 2024 + June 2025 analysis ("Inc Ransom used common tools like Impacket and Rclone for various functions, including credential access, lateral movement through pass- the-hash attacks, and malicious command-and-control C2 communications")

(4) cluster-defining pass- the-hash lateral movement per ReliaQuest.

(5) RDP + SMB lateral movement per Black Point Cyber TTP table.

(6) cluster-defining INC-README.TXT + INC-README.HTML ransom notes dropped per folder with encrypted files per Bleeping Computer.

(7) Windows + Linux/ESXi versions signature - Linux version December 2023 "revealing their understanding of the importance of Unix environments in modern enterprise infrastructures" + March 2024 enhanced Windows version with selective-encryption "--file" argument capability ("major updates every four to six months, bears witness to an organized development process") per SosRansomware August 2025 retrospective; (8) cluster-defining source code sale May 14, 2024 for $300,000 by "salfetka" on Exploit + XSS hacking forums with KELA threat intelligence- confirmed authenticity per Cybersecurity-Help - operationally significant RaaS source code commodification.

(9) cluster-defining new TOR blog Hunters International design similarity May 1, 2024 per Cybersecurity-Help ("Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations") - possible operator-relation signature.

(10) cluster-defining Microsoft Vanilla Tempest = Vice Society industry naming dispute per CyberForceQ September 2024 indicating possible operator continuity with earlier Vice Society Russia-aligned cybercrime operations.

cluster fills the July-2023- onward + Citrix-NetScaler-CVE-2023-3519 + Impacket- pass-the-hash-Rclone + INC-README ransom note + Linux-ESXi-versions + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

canonical illustration of healthcare/ education/government targeting + Citrix NetScaler vulnerability exploitation + Impacket + Rclone tradecraft + RaaS source-code commodification + Hunters International possible operator relation + Vanilla Tempest industry naming dispute cited in essentially all subsequent ransomware industry analyses through 2023-2026 period.

russia_speaking_cybercrime confidence: high 15 aliases MITRE ATT&CK G1032 ↗

Profile

INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber tracking; Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 2024 industry naming dispute
  • curated as standalone with acknowledgment) is a Ransomware-as- a-Service operation active since July 2023 with canonical double-extortion model. Russia-speaking organized cybercrime attribution (less definitive than BianLian) via SentinelOne July 2023 first documentation + ReliaQuest 2024-2025 analysis + Cybersecurity-Help May 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute identification. Standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
Operational target profile
  • Healthcare primary target (NHS Scotland 3TB leak + healthcare adjacent)
  • Education + government + food retail + manufacturing + technology services + charities.
  • U.S. + Canada + Europe + UK + Philippines per ReliaQuest + victim list Operational attack architecture: (1) Citrix NetScaler CVE-2023-3519 initial access (cluster-defining): per SentinelOne (2) Spearphishing email initial access (signature) (3) Impacket + Rclone tradecraft (cluster-defining): per ReliaQuest August 2024 + June 2025.
  • credential access via Impacket + lateral movement via pass-the- hash + Rclone exfiltration (4) Pass-the-hash lateral movement (cluster- defining): per ReliaQuest (5) RDP + SMB lateral movement (signature) (6) Selective encryption "--file" argument (signature 2024): per SosRansomware March 2024 enhanced version (7) INC-README.TXT + INC-README.HTML ransom notes (signature): dropped per folder (8) Windows + Linux/ESXi versions (signature): Linux version December 2023, enhanced Windows version March 2024 (9) Source code sale May 14, 2024.
  • $300,000 (signature): per Cybersecurity-Help.
  • "salfetka" on Exploit + XSS forums, KELA-authenticated (10) New TOR blog Hunters International design similarity May 1, 2024 (signature): possible operator relation per Cybersecurity-Help (11) Microsoft Vanilla Tempest = Vice Society industry naming dispute (signature): per CyberForceQ September 2024 The cluster fills the July-2023-onward + Citrix- NetScaler-CVE-2023-3519 + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in the post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

Aliases

15
inc_ransominc ransominc_ransomwareinc ransomwareinc ransom groupinc ransom ransomware as a serviceinc ransom raas operation july 2023inc ransom nhs scotland xerox business solutions yamaha motor philippinesinc ransom pennsylvania ag ahold delhaize victiminc ransom citrix netscaler cve-2023-3519 initial accessinc-readme.txtinc-readme.htmlinc ransom source code sale 300000 salfetkainc ransom hunters international similarityinc ransom vanilla tempest vice society overlap industry dispute

MITRE ATT&CK aliases

1
Additional names MITRE lists for G1032.
GOLD IONIC

Notable Campaigns

12
2025INC Ransom Pennsylvania AG Data Breach (November 2025)
2024INC Ransom NHS Scotland - 3TB Data Leak Threat (March 2024)
2024INC Ransom Enhanced Windows Version (March 2024)
2024INC Ransom Source Code Sale - $300,000 (May 14, 2024)
2024INC Ransom New TOR Blog with Hunters International Design Similarity (May 1, 2024)
2024Microsoft Vanilla Tempest = Vice Society Industry Naming Dispute Identification (September 2024)
2024INC Ransom Ahold Delhaize Food Retail Giant Attack
2023-2026Continued Industry Reference Status (2023-2026)
2023INC Ransom Origin - Active Since July 2023
2023INC Ransom Xerox Business Solutions First Canonical Victim
2023INC Ransom Yamaha Motor Philippines (October 25, 2023)
2023INC Ransom Linux/ESXi Version (December 2023)

Attribution & Reporting

Attributed by
SentinelOne (canonical July 2023 first documentation)The Register (canonical March 28, 2024 NHS Scotland coverage)Bleeping Computer (canonical NHS Scotland + Yamaha Motor Philippines + Pennsylvania AG industry coverage)ReliaQuest (canonical August 2024 + June 2025 attack analysis retrospective)Black Point Cyber (canonical INC Ransom threat profile)Cybersecurity-Help (canonical May 14, 2024 source code sale + new TOR blog disclosure)KELA threat intelligence (canonical INC Ransom source code authenticity confirmation)SOSransomware Anatomy (canonical August 2025 retrospective)Infosecurity Magazine (canonical NHS Dumfries Galloway 2024 coverage)CyberForceQ (canonical September 19, 2024 Vanilla Tempest = Vice Society = INC industry naming dispute identification)Microsoft Threat Intelligence (canonical Vanilla Tempest tracking)
Key reporting
Sources & links

Operational

State sponsor
Operationally separate from state-sponsored APT activity
  • RaaS operation with affiliate-based model. Industry consensus: Russia-speaking organized cybercrime operation though attribution remains less definitive than BianLian. Microsoft Vanilla Tempest = Vice Society overlap suggests possible operator continuity with earlier Vice Society (Russia-aligned cybercrime) operations. Attribution chain: (1) SentinelOne canonical July 2023 first documentation: per SentinelOne + The Register + Bleeping Computer: "INC Ransom is a relatively new gang on the block, spinning up in July 2023 and posting targets indiscriminately." First documented victim Xerox Business Solutions (US division of tech giant Xerox) per The Register. (2) ReliaQuest canonical August 2024 attack analysis: per ReliaQuest June 2025 retrospective: "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month. The threat group has completed ransomware attacks on large organizations, like Xerox Business Solutions and National Health Service (NHS) Scotland, which typically have mature cybersecurity programs." (3) Microsoft Vanilla Tempest = Vice Society industry naming dispute identification September 2024: per CyberForceQ September 19, 2024: "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks. While some other threat actors may create custom versions of their own. Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest." Operationally significant industry naming dispute curated as standalone with acknowledgment (similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET). (4) Cybersecurity-Help canonical May 14, 2024 source code sale + new TOR blog disclosure: per Cybersecurity-Help: "INC ransomware source code reportedly on sale for $300,000... The ransomware source code was put up for sale on the Exploit and XSS hacking forums by an individual who goes online as 'salfetka.'... Security researchers at threat intelligence firm KELA have confirmed the authenticity of the sale... Additionally, the INC Ransom operation appears to be undergoing significant changes. On May 1, 2024, INC Ransom announced its transition to a new data leak extortion blog, with a new TOR address. The old leak site is slated for closure within the next two to three months. Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations." (5) NHS Scotland canonical 3TB data leak March 2024: per Bleeping Computer + The Register + Infosecurity Magazine: NHS Dumfries and Galloway Scotland attack March 15, 2024 with 3TB threatened release including patient clinical data. (6) Pennsylvania AG canonical November 2025 attack: per Bleeping Computer November 17, 2025: third Pennsylvania state entity ransomware breach following Delaware County 2020 + Pennsylvania Senate Democratic Caucus 2017. Operational mission objective: Banking/financial + healthcare + government data theft + encryption double-extortion via RaaS affiliate model. Per Black Point Cyber: "operates in the double extortion method, where victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
" Operational target profile
  • Healthcare primary target sector (NHS Scotland + Boston Children's adjacent)
  • Education sector targeting.
  • Government sector targeting (Pennsylvania AG + NHS Scotland UK-public-sector)
  • U.S. + Canada + Europe geographic primary per ReliaQuest The cluster fills the July-2023-onward + Citrix-NetScaler-initial-access + source-code-sale- 2024 + Hunters-International-blog-similarity position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
Motivations
financial_extortion_double_extortion_data_theft_plus_encryption, healthcare_education_government_sector_targeting, raas_operation_affiliate_model, citrix_netscaler_cve_2023_3519_spearphishing_initial_access, source_code_sale_300000_may_2024, hunters_international_extortion_blog_similarity_2024
Sectors
Regions

Public detection by layer

60 techniques
Across this actor’s 60 mapped techniques, the share for which public detection content exists in each layer (published detection content across Sigma, Elastic, MITRE CAR, Snort/Suricata, YARA, and Nuclei). Low bars mean little ready-made detection is published for this adversary, so you would likely have to write your own. This is a view of available public content, not of the rules you have deployed.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%
SIEM (Splunk ESCU)55/60 · 91%
SIEM (Elastic)58/60 · 96%
SIEM (Azure Sentinel)18/60 · 30%

Public detection by technique

60/60
Public detection content exists for 60 of this actor’s 60 mapped techniques (100%); 0 have no published detection content. The ones with no published rule are listed first - you would need to source or write detection for those. This reflects published rules, not your own deployment. Per-account coverage, where you upload your own rules and we compute your real gaps, is on the roadmap.
has rules T1059.001 PowerShell Sigma 219 rules 26
has rules T1190 Exploit Public-Facing Application Sigma 146 rules 63
has rules T1218 System Binary Proxy Execution Sigma 153 rules 10
has rules T1112 Modify Registry Sigma 95 rules 66
has rules T1059 Command and Scripting Interpreter Sigma 95 rules 20
has rules T1078 Valid Accounts Sigma 61 rules 51
has rules T1027 Obfuscated Files or Information Sigma 94 rules 4
has rules T1003.001 LSASS Memory Sigma 79 rules 10
has rules T1053.005 Scheduled Task Sigma 51 rules 17
has rules T1068 Exploitation for Privilege Escalation Sigma 29 rules 32
has rules T1218.011 Rundll32 Sigma 43 rules 16
has rules T1055 Process Injection Sigma 35 rules 23
has rules T1059.003 Windows Command Shell Sigma 45 rules 7
has rules T1036 Masquerading Sigma 40 rules 8
has rules T1071.001 Web Protocols Sigma 41 rules 6
has rules T1204.002 Malicious File Sigma 36 rules 9
has rules T1033 System Owner/User Discovery Sigma 30 rules 14
has rules T1485 Data Destruction Sigma 20 rules 24
has rules T1082 System Information Discovery Sigma 33 rules 10
has rules T1021.002 SMB/Windows Admin Shares Sigma 38 rules 3
has rules T1203 Exploitation for Client Execution Sigma 33 rules 6
has rules T1003 OS Credential Dumping Sigma 36 rules 2
has rules T1204 User Execution Sigma 10 rules 27
has rules T1018 Remote System Discovery Sigma 17 rules 18
has rules T1059.005 Visual Basic Sigma 28 rules 4
has rules T1021.001 Remote Desktop Protocol Sigma 16 rules 15
has rules T1083 File and Directory Discovery Sigma 24 rules 5
has rules T1046 Network Service Discovery Sigma 20 rules 6
has rules T1070 Indicator Removal Sigma 20 rules 6
has rules T1090 Proxy Sigma 22 rules 3
has rules T1070.004 File Deletion Sigma 15 rules 7
has rules T1133 External Remote Services Sigma 20 rules 2
has rules T1140 Deobfuscate/Decode Files or Information Sigma 18 rules 2
has rules T1005 Data from Local System Sigma 14 rules 5
has rules T1048 Exfiltration Over Alternative Protocol Sigma 11 rules 8
has rules T1087 Account Discovery Sigma 16 rules 3
has rules T1218.005 Mshta Sigma 8 rules 11
has rules T1053 Scheduled Task/Job Sigma 12 rules 6
has rules T1016 System Network Configuration Discovery Sigma 12 rules 5
has rules T1021 Remote Services Sigma 11 rules 5
has rules T1071 Application Layer Protocol Sigma 7 rules 9
has rules T1102 Web Service Sigma 13 rules 1
has rules T1106 Native API Sigma 14
has rules T1041 Exfiltration Over C2 Channel Sigma 5 rules 6
has rules T1135 Network Share Discovery Sigma 7 rules 4
has rules T1057 Process Discovery Sigma 7 rules 2
has rules T1119 Automated Collection Sigma 5 rules 4
has rules T1090.001 Internal Proxy Sigma 6 rules 2
has rules T1136 Create Account Sigma 3 rules 2
has rules T1095 Non-Application Layer Protocol Sigma 3 rules 1
has rules T1129 Shared Modules Sigma 2 rules 1
has rules T1195 Supply Chain Compromise Sigma 1 rules 2
has rules T1014 Rootkit Sigma 1 rules 1
has rules T1056 Input Capture Sigma 2
has rules T1090.002 External Proxy Sigma 2
has rules T1027.002 Software Packing Sigma 1

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MARCH 2024 ENHANCED WINDOWS VERSION WITH FILE SELECTION --FILE ARGUMENTMICROSOFT VANILLA TEMPEST = VICE SOCIETY INDUSTRY NAMING DISPUTESPEARPHISHING EMAIL INITIAL ACCESS

CVEs Exploited

1
External lookups - second-class, for what we don’t hold ourselves