INC Ransom
INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber + The Register industry tracking.
Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 19, 2024 industry naming dispute "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks... Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest" - curated as standalone with acknowledgment similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET dispute) is a Ransomware-as-a-Service operation active since July 2023 with canonical double-extortion model (encryption + data theft + threat to leak via leak site if ransom not paid)
Russia-speaking organized cybercrime attribution via SentinelOne + ReliaQuest (canonical August 2024 attack analysis "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month") + Black Point Cyber canonical TTP profile + Cybersecurity- Help May 14, 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute.
standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
operational target profile healthcare primary (NHS Dumfries Galloway Scotland March 2024 with 3TB threatened release of patient clinical data + Boston Children's adjacent) + education (Radford Public School + Afpa) + government (Pennsylvania AG November 2025 third Pennsylvania state entity ransomware breach following 2020 + 2017 prior incidents) + food retail (Ahold Delhaize) + manufacturing (Yamaha Motor Philippines October 25, 2023 employee data theft) + technology services (Xerox Business Solutions first canonical victim) + charities + U.S. + Canada + Europe + UK + Philippines geographic range per ReliaQuest; operational attack architecture: (1) cluster- defining Citrix NetScaler CVE-2023-3519 initial access exploit per SentinelOne + spearphishing email initial access.
(2) lateral movement to sensitive file harvest + download for ransom leverage.
(3) cluster-defining Impacket + Rclone tradecraft per ReliaQuest August 2024 + June 2025 analysis ("Inc Ransom used common tools like Impacket and Rclone for various functions, including credential access, lateral movement through pass- the-hash attacks, and malicious command-and-control C2 communications")
(4) cluster-defining pass- the-hash lateral movement per ReliaQuest.
(5) RDP + SMB lateral movement per Black Point Cyber TTP table.
(6) cluster-defining INC-README.TXT + INC-README.HTML ransom notes dropped per folder with encrypted files per Bleeping Computer.
(7) Windows + Linux/ESXi versions signature - Linux version December 2023 "revealing their understanding of the importance of Unix environments in modern enterprise infrastructures" + March 2024 enhanced Windows version with selective-encryption "--file" argument capability ("major updates every four to six months, bears witness to an organized development process") per SosRansomware August 2025 retrospective; (8) cluster-defining source code sale May 14, 2024 for $300,000 by "salfetka" on Exploit + XSS hacking forums with KELA threat intelligence- confirmed authenticity per Cybersecurity-Help - operationally significant RaaS source code commodification.
(9) cluster-defining new TOR blog Hunters International design similarity May 1, 2024 per Cybersecurity-Help ("Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations") - possible operator-relation signature.
(10) cluster-defining Microsoft Vanilla Tempest = Vice Society industry naming dispute per CyberForceQ September 2024 indicating possible operator continuity with earlier Vice Society Russia-aligned cybercrime operations.
cluster fills the July-2023- onward + Citrix-NetScaler-CVE-2023-3519 + Impacket- pass-the-hash-Rclone + INC-README ransom note + Linux-ESXi-versions + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
canonical illustration of healthcare/ education/government targeting + Citrix NetScaler vulnerability exploitation + Impacket + Rclone tradecraft + RaaS source-code commodification + Hunters International possible operator relation + Vanilla Tempest industry naming dispute cited in essentially all subsequent ransomware industry analyses through 2023-2026 period.
Profile
- curated as standalone with acknowledgment) is a Ransomware-as- a-Service operation active since July 2023 with canonical double-extortion model. Russia-speaking organized cybercrime attribution (less definitive than BianLian) via SentinelOne July 2023 first documentation + ReliaQuest 2024-2025 analysis + Cybersecurity-Help May 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute identification. Standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
- Healthcare primary target (NHS Scotland 3TB leak + healthcare adjacent)
- Education + government + food retail + manufacturing + technology services + charities.
- U.S. + Canada + Europe + UK + Philippines per ReliaQuest + victim list Operational attack architecture: (1) Citrix NetScaler CVE-2023-3519 initial access (cluster-defining): per SentinelOne (2) Spearphishing email initial access (signature) (3) Impacket + Rclone tradecraft (cluster-defining): per ReliaQuest August 2024 + June 2025.
- credential access via Impacket + lateral movement via pass-the- hash + Rclone exfiltration (4) Pass-the-hash lateral movement (cluster- defining): per ReliaQuest (5) RDP + SMB lateral movement (signature) (6) Selective encryption "--file" argument (signature 2024): per SosRansomware March 2024 enhanced version (7) INC-README.TXT + INC-README.HTML ransom notes (signature): dropped per folder (8) Windows + Linux/ESXi versions (signature): Linux version December 2023, enhanced Windows version March 2024 (9) Source code sale May 14, 2024.
- $300,000 (signature): per Cybersecurity-Help.
- "salfetka" on Exploit + XSS forums, KELA-authenticated (10) New TOR blog Hunters International design similarity May 1, 2024 (signature): possible operator relation per Cybersecurity-Help (11) Microsoft Vanilla Tempest = Vice Society industry naming dispute (signature): per CyberForceQ September 2024 The cluster fills the July-2023-onward + Citrix- NetScaler-CVE-2023-3519 + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in the post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
Aliases
15MITRE ATT&CK aliases
1Notable Campaigns
12Attribution & Reporting
Operational
- RaaS operation with affiliate-based model. Industry consensus: Russia-speaking organized cybercrime operation though attribution remains less definitive than BianLian. Microsoft Vanilla Tempest = Vice Society overlap suggests possible operator continuity with earlier Vice Society (Russia-aligned cybercrime) operations. Attribution chain: (1) SentinelOne canonical July 2023 first documentation: per SentinelOne + The Register + Bleeping Computer: "INC Ransom is a relatively new gang on the block, spinning up in July 2023 and posting targets indiscriminately." First documented victim Xerox Business Solutions (US division of tech giant Xerox) per The Register. (2) ReliaQuest canonical August 2024 attack analysis: per ReliaQuest June 2025 retrospective: "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month. The threat group has completed ransomware attacks on large organizations, like Xerox Business Solutions and National Health Service (NHS) Scotland, which typically have mature cybersecurity programs." (3) Microsoft Vanilla Tempest = Vice Society industry naming dispute identification September 2024: per CyberForceQ September 19, 2024: "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks. While some other threat actors may create custom versions of their own. Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest." Operationally significant industry naming dispute curated as standalone with acknowledgment (similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET). (4) Cybersecurity-Help canonical May 14, 2024 source code sale + new TOR blog disclosure: per Cybersecurity-Help: "INC ransomware source code reportedly on sale for $300,000... The ransomware source code was put up for sale on the Exploit and XSS hacking forums by an individual who goes online as 'salfetka.'... Security researchers at threat intelligence firm KELA have confirmed the authenticity of the sale... Additionally, the INC Ransom operation appears to be undergoing significant changes. On May 1, 2024, INC Ransom announced its transition to a new data leak extortion blog, with a new TOR address. The old leak site is slated for closure within the next two to three months. Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations." (5) NHS Scotland canonical 3TB data leak March 2024: per Bleeping Computer + The Register + Infosecurity Magazine: NHS Dumfries and Galloway Scotland attack March 15, 2024 with 3TB threatened release including patient clinical data. (6) Pennsylvania AG canonical November 2025 attack: per Bleeping Computer November 17, 2025: third Pennsylvania state entity ransomware breach following Delaware County 2020 + Pennsylvania Senate Democratic Caucus 2017. Operational mission objective: Banking/financial + healthcare + government data theft + encryption double-extortion via RaaS affiliate model. Per Black Point Cyber: "operates in the double extortion method, where victim data is stolen and leaked via a data leak site if the ransom demand is not paid.
- Healthcare primary target sector (NHS Scotland + Boston Children's adjacent)
- Education sector targeting.
- Government sector targeting (Pennsylvania AG + NHS Scotland UK-public-sector)
- U.S. + Canada + Europe geographic primary per ReliaQuest The cluster fills the July-2023-onward + Citrix-NetScaler-initial-access + source-code-sale- 2024 + Hunters-International-blog-similarity position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.