Home/Threat Actor/INC Ransom
Threat Actor

INC Ransom

inc_ransom · russia_speaking_cybercrime · active since 2023-07

INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber + The Register industry tracking.

Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 19, 2024 industry naming dispute "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks... Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest", curated as standalone with acknowledgment similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET dispute) is a Ransomware-as-a-Service operation active since July 2023 with canonical double-extortion model (encryption + data theft + threat to leak via leak site if ransom not paid)

Russia-speaking organized cybercrime attribution via SentinelOne + ReliaQuest (canonical August 2024 attack analysis "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month") + Black Point Cyber canonical TTP profile + Cybersecurity- Help May 14, 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute.

standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

operational target profile healthcare primary (NHS Dumfries Galloway Scotland March 2024 with 3TB threatened release of patient clinical data + Boston Children's adjacent) + education (Radford Public School + Afpa) + government (Pennsylvania AG November 2025 third Pennsylvania state entity ransomware breach following 2020 + 2017 prior incidents) + food retail (Ahold Delhaize) + manufacturing (Yamaha Motor Philippines October 25, 2023 employee data theft) + technology services (Xerox Business Solutions first canonical victim) + charities + U.S. + Canada + Europe + UK + Philippines geographic range per ReliaQuest; operational attack architecture: (1) cluster- defining Citrix NetScaler CVE-2023-3519 initial access exploit per SentinelOne + spearphishing email initial access.

(2) lateral movement to sensitive file harvest + download for ransom leverage.

(3) cluster-defining Impacket + Rclone tradecraft per ReliaQuest August 2024 + June 2025 analysis ("Inc Ransom used common tools like Impacket and Rclone for various functions, including credential access, lateral movement through pass- the-hash attacks, and malicious command-and-control C2 communications")

(4) cluster-defining pass- the-hash lateral movement per ReliaQuest.

(5) RDP + SMB lateral movement per Black Point Cyber TTP table.

(6) cluster-defining INC-README.TXT + INC-README.HTML ransom notes dropped per folder with encrypted files per Bleeping Computer.

(7) Windows + Linux/ESXi versions signature, Linux version December 2023 "revealing their understanding of the importance of Unix environments in modern enterprise infrastructures" + March 2024 enhanced Windows version with selective-encryption "--file" argument capability ("major updates every four to six months, bears witness to an organized development process") per SosRansomware August 2025 retrospective; (8) cluster-defining source code sale May 14, 2024 for $300,000 by "salfetka" on Exploit + XSS hacking forums with KELA threat intelligence- confirmed authenticity per Cybersecurity-Help, operationally significant RaaS source code commodification.

(9) cluster-defining new TOR blog Hunters International design similarity May 1, 2024 per Cybersecurity-Help ("Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations") , possible operator-relation signature.

(10) cluster-defining Microsoft Vanilla Tempest = Vice Society industry naming dispute per CyberForceQ September 2024 indicating possible operator continuity with earlier Vice Society Russia-aligned cybercrime operations.

cluster fills the July-2023- onward + Citrix-NetScaler-CVE-2023-3519 + Impacket- pass-the-hash-Rclone + INC-README ransom note + Linux-ESXi-versions + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

canonical illustration of healthcare/ education/government targeting + Citrix NetScaler vulnerability exploitation + Impacket + Rclone tradecraft + RaaS source-code commodification + Hunters International possible operator relation + Vanilla Tempest industry naming dispute cited in essentially all subsequent ransomware industry analyses through 2023-2026 period.

russia_speaking_cybercrime confidence: high 15 aliases MITRE ATT&CK G1032 ↗

Profile

INC Ransom (canonical industry naming per SentinelOne July 2023 first documentation + ReliaQuest + Bleeping Computer + Cybersecurity-Help + Black Point Cyber tracking.

Microsoft tracks adjacent activity as Vanilla Tempest = Vice Society per CyberForceQ September 2024 industry naming dispute, curated as standalone with acknowledgment) is a Ransomware-as- a-Service operation active since July 2023 with canonical double-extortion model. Russia-speaking organized cybercrime attribution (less definitive than BianLian) via SentinelOne July 2023 first documentation + ReliaQuest 2024-2025 analysis + Cybersecurity-Help May 2024 source code sale disclosure + Microsoft Vanilla Tempest = Vice Society industry naming dispute identification. Standalone cluster paralleling bianlian + base_8 + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.

Operational target profile
  • Healthcare primary target (NHS Scotland 3TB leak + healthcare adjacent)
  • Education + government + food retail + manufacturing + technology services + charities.
  • U.S. + Canada + Europe + UK + Philippines per ReliaQuest + victim list Operational attack architecture: (1) Citrix NetScaler CVE-2023-3519 initial access (cluster-defining): per SentinelOne (2) Spearphishing email initial access (signature) (3) Impacket + Rclone tradecraft (cluster-defining): per ReliaQuest August 2024 + June 2025, credential access via Impacket + lateral movement via pass-the- hash + Rclone exfiltration (4) Pass-the-hash lateral movement (cluster- defining): per ReliaQuest (5) RDP + SMB lateral movement (signature) (6) Selective encryption "--file" argument (signature 2024): per SosRansomware March 2024 enhanced version (7) INC-README.TXT + INC-README.HTML ransom notes (signature): dropped per folder (8) Windows + Linux/ESXi versions (signature): Linux version December 2023, enhanced Windows version March 2024 (9) Source code sale May 14, 2024, $300,000 (signature): per Cybersecurity-Help, "salfetka" on Exploit + XSS forums, KELA-authenticated (10) New TOR blog Hunters International design similarity May 1, 2024 (signature): possible operator relation per Cybersecurity-Help (11) Microsoft Vanilla Tempest = Vice Society industry naming dispute (signature): per CyberForceQ September 2024 The cluster fills the July-2023-onward + Citrix- NetScaler-CVE-2023-3519 + source-code-sale-2024 + Hunters-International-blog-similarity + Vanilla- Tempest-naming-dispute position in the post-Conti- takedown 2022-2024 RaaS fragmentation operators cell.

Aliases

15
inc_ransominc ransominc_ransomwareinc ransomwareinc ransom groupinc ransom ransomware as a serviceinc ransom raas operation july 2023inc ransom nhs scotland xerox business solutions yamaha motor philippinesinc ransom pennsylvania ag ahold delhaize victiminc ransom citrix netscaler cve-2023-3519 initial accessinc-readme.txtinc-readme.htmlinc ransom source code sale 300000 salfetkainc ransom hunters international similarityinc ransom vanilla tempest vice society overlap industry dispute

MITRE ATT&CK aliases

1
Additional names MITRE lists for G1032.
GOLD IONIC

Notable Campaigns

12
2025INC Ransom Pennsylvania AG Data Breach (November 2025)
2024INC Ransom NHS Scotland, 3TB Data Leak Threat (March 2024)
2024INC Ransom Enhanced Windows Version (March 2024)
2024INC Ransom Source Code Sale, $300,000 (May 14, 2024)
2024INC Ransom New TOR Blog with Hunters International Design Similarity (May 1, 2024)
2024Microsoft Vanilla Tempest = Vice Society Industry Naming Dispute Identification (September 2024)
2024INC Ransom Ahold Delhaize Food Retail Giant Attack
2023-2026Continued Industry Reference Status (2023-2026)
2023INC Ransom Origin, Active Since July 2023
2023INC Ransom Xerox Business Solutions First Canonical Victim
2023INC Ransom Yamaha Motor Philippines (October 25, 2023)
2023INC Ransom Linux/ESXi Version (December 2023)

Attribution & Reporting

Attributed by
SentinelOne (canonical July 2023 first documentation)The Register (canonical March 28, 2024 NHS Scotland coverage)Bleeping Computer (canonical NHS Scotland + Yamaha Motor Philippines + Pennsylvania AG industry coverage)ReliaQuest (canonical August 2024 + June 2025 attack analysis retrospective)Black Point Cyber (canonical INC Ransom threat profile)Cybersecurity-Help (canonical May 14, 2024 source code sale + new TOR blog disclosure)KELA threat intelligence (canonical INC Ransom source code authenticity confirmation)SOSransomware Anatomy (canonical August 2025 retrospective)Infosecurity Magazine (canonical NHS Dumfries Galloway 2024 coverage)CyberForceQ (canonical September 19, 2024 Vanilla Tempest = Vice Society = INC industry naming dispute identification)Microsoft Threat Intelligence (canonical Vanilla Tempest tracking)
Key reporting
reportSentinelOne: canonical July 2023 INC Ransom first documentation
reportReliaQuest: Inc Ransom Attack Analysis, Extortion Methodologies (August 2024 + June 2025 retrospective), canonical attack analysis
reportBlack Point Cyber: INC Ransom Ransomware Threat Profile, canonical TTP table
reportBleeping Computer: NHS Scotland + Yamaha Motor Philippines + Pennsylvania AG canonical industry coverage
reportThe Register: INC Ransom claims responsibility for attack on NHS Scotland (March 28, 2024)
reportCybersecurity-Help: INC ransomware source code reportedly on sale for $300,000 (May 14, 2024), canonical source code sale + Hunters International blog disclosure
reportKELA threat intelligence: canonical INC Ransom source code authenticity confirmation
reportSosRansomware: INC Ransom anatomy 2025 retrospective, canonical detailed technical analysis
reportInfosecurity Magazine: NHS Trust Confirms Clinical Data Leaked (canonical NHS Dumfries Galloway 2024 coverage)
reportCyberForceQ: canonical September 2024 Vanilla Tempest = Vice Society = INC industry naming dispute identification
reportMicrosoft Threat Intelligence: canonical Vanilla Tempest tracking

Operational

State sponsor

Operationally separate from state-sponsored APT activity, RaaS operation with affiliate-based model. Industry consensus: Russia-speaking organized cybercrime operation though attribution remains less definitive than BianLian. Microsoft Vanilla Tempest = Vice Society overlap suggests possible operator continuity with earlier Vice Society (Russia-aligned cybercrime) operations.

Attribution chain: (1) SentinelOne canonical July 2023 first documentation: per SentinelOne + The Register + Bleeping Computer: "INC Ransom is a relatively new gang on the block, spinning up in July 2023 and posting targets indiscriminately." First documented victim Xerox Business Solutions (US division of tech giant Xerox) per The Register. (2) ReliaQuest canonical August 2024 attack analysis: per ReliaQuest June 2025 retrospective: "First identified in July 2023, Inc Ransom is a highly active double-extortion ransomware group who, since their emergence, have successfully extorted an average of 11 organizations per month. The threat group has completed ransomware attacks on large organizations, like Xerox Business Solutions and National Health Service (NHS) Scotland, which typically have mature cybersecurity programs." (3) Microsoft Vanilla Tempest = Vice Society industry naming dispute identification September 2024: per CyberForceQ September 19, 2024: "INC is also tracked under the name Vice Society, that employs already existing lockers to execute their attacks.

While some other threat actors may create custom versions of their own. Microsoft's threat intelligence team is tracking the activity under the name Vanilla Tempest." Operationally significant industry naming dispute curated as standalone with acknowledgment (similar to v0.1.139 Mekotio = Melcoz handling per Kaspersky vs ESET). (4) Cybersecurity-Help canonical May 14, 2024 source code sale + new TOR blog disclosure: per Cybersecurity-Help: "INC ransomware source code reportedly on sale for $300,000...

The ransomware source code was put up for sale on the Exploit and XSS hacking forums by an individual who goes online as 'salfetka.'... Security researchers at threat intelligence firm KELA have confirmed the authenticity of the sale... Additionally, the INC Ransom operation appears to be undergoing significant changes.

On May 1, 2024, INC Ransom announced its transition to a new data leak extortion blog, with a new TOR address. The old leak site is slated for closure within the next two to three months. Interestingly, the design of the new extortion page bears similarity to that of Hunters International, hinting at a potential connection between the two RaaS operations." (5) NHS Scotland canonical 3TB data leak March 2024: per Bleeping Computer + The Register + Infosecurity Magazine: NHS Dumfries and Galloway Scotland attack March 15, 2024 with 3TB threatened release including patient clinical data.

(6) Pennsylvania AG canonical November 2025 attack: per Bleeping Computer November 17, 2025: third Pennsylvania state entity ransomware breach following Delaware County 2020 + Pennsylvania Senate Democratic Caucus 2017. Operational mission objective: Banking/financial + healthcare + government data theft + encryption double-extortion via RaaS affiliate model. Per Black Point Cyber: "operates in the double extortion method, where victim data is stolen and leaked via a data leak site if the ransom demand is not paid.

" Operational target profile
  • Healthcare primary target sector (NHS Scotland + Boston Children's adjacent)
  • Education sector targeting.
  • Government sector targeting (Pennsylvania AG + NHS Scotland UK-public-sector)
  • U.S. + Canada + Europe geographic primary per ReliaQuest The cluster fills the July-2023-onward + Citrix-NetScaler-initial-access + source-code-sale- 2024 + Hunters-International-blog-similarity position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
Motivations
financial_extortion_double_extortion_data_theft_plus_encryption, healthcare_education_government_sector_targeting, raas_operation_affiliate_model, citrix_netscaler_cve_2023_3519_spearphishing_initial_access, source_code_sale_300000_may_2024, hunters_international_extortion_blog_similarity_2024
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MARCH 2024 ENHANCED WINDOWS VERSION WITH FILE SELECTION --FILE ARGUMENTMICROSOFT VANILLA TEMPEST = VICE SOCIETY INDUSTRY NAMING DISPUTESPEARPHISHING EMAIL INITIAL ACCESS

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin