INC Ransom
INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber + The Register industry tracking.
Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 19, 2024 industry naming dispute "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks... Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest", curated as standalone with acknowledgment similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET dispute) is a Ransomware-as-a-Service operation active since July 2023 with canonical double-extortion model (encryption + data theft + threat to leak via leak site if ransom not paid)
Russia-speaking organized cybercrime attribution via SentinelOne + ReliaQuest (canonical August 2024 attack analysis "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month") + Black Point Cyber canonical TTP profile + Cybersecurity- Help May 14, 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute.
standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
operational target profile healthcare primary (NHS Dumfries Galloway Scotland March 2024 with 3TB threatened release of patient clinical data + Boston Children's adjacent) + education (Radford Public School + Afpa) + government (Pennsylvania AG November 2025 third Pennsylvania state entity ransomware breach following 2020 + 2017 prior incidents) + food retail (Ahold Delhaize) + manufacturing (Yamaha Motor Philippines October 25, 2023 employee data theft) + technology services (Xerox Business Solutions first canonical victim) + charities + U.S. + Canada + Europe + UK + Philippines geographic range per ReliaQuest; operational attack architecture: (1) cluster- defining Citrix NetScaler CVE-2023-3519 initial access exploit per SentinelOne + spearphishing email initial access.
(2) lateral movement to sensitive file harvest + download for ransom leverage.
(3) cluster-defining Impacket + Rclone tradecraft per ReliaQuest August 2024 + June 2025 analysis ("Inc Ransom used common tools like Impacket and Rclone for various functions, including credential access, lateral movement through pass- the-hash attacks, and malicious command-and-control C2 communications")
(4) cluster-defining pass- the-hash lateral movement per ReliaQuest.
(5) RDP + SMB lateral movement per Black Point Cyber TTP table.
(6) cluster-defining INC-README.TXT + INC-README.HTML ransom notes dropped per folder with encrypted files per Bleeping Computer.
(7) Windows + Linux/ESXi versions signature, Linux version December 2023 "revealing their understanding of the importance of Unix environments in modern enterprise infrastructures" + March 2024 enhanced Windows version with selective-encryption "--file" argument capability ("major updates every four to six months, bears witness to an organized development process") per SosRansomware August 2025 retrospective; (8) cluster-defining source code sale May 14, 2024 for $300,000 by "salfetka" on Exploit + XSS hacking forums with KELA threat intelligence- confirmed authenticity per Cybersecurity-Help, operationally significant RaaS source code commodification.
(9) cluster-defining new TOR blog Hunters International design similarity May 1, 2024 per Cybersecurity-Help ("Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations") , possible operator-relation signature.
(10) cluster-defining Microsoft Vanilla Tempest = Vice Society industry naming dispute per CyberForceQ September 2024 indicating possible operator continuity with earlier Vice Society Russia-aligned cybercrime operations.
cluster fills the July-2023- onward + Citrix-NetScaler-CVE-2023-3519 + Impacket- pass-the-hash-Rclone + INC-README ransom note + Linux-ESXi-versions + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.
canonical illustration of healthcare/ education/government targeting + Citrix NetScaler vulnerability exploitation + Impacket + Rclone tradecraft + RaaS source-code commodification + Hunters International possible operator relation + Vanilla Tempest industry naming dispute cited in essentially all subsequent ransomware industry analyses through 2023-2026 period.