A recent report published by Acronis Threat Research Unit (TRU) examines the attack chain, victim profile and latest techniques used by INC, one of the most active ransomware groups of 2026
Acronis, global leader in the protection informatica published a report on the evolution of the INC ransomware, analyzing the attack chain, victim profile, tools, tactics, techniques and procedures (TTP). Prepared by the Acronis Threat Research Unit (TRU), the report also provides recommendations for detection, mitigation and risk reduction.
Ransomware attacks disrupt business operations, exposing sensitive data and causing significant financial, operational and reputational damage. Despite investments in security controls, ransomware groups continue to evolve their tactics through ransomware-as-a-service (RaaS) models, which lower the threshold of entry for affiliates and allow them to conduct large-scale attacks. Among the most active RaaS operations, INC ransomware has quickly established itself as one of the most relevant threats. Since its emergence in 2023, the group has expanded its capabilities, developing ransomware variants for Windows and Linux/ESXi, constantly improving its tools and growing its affiliate ecosystem. INC has also been linked to numerous high-profile incidents, impacting the entire ransomware landscape through the sale of its source code, which has contributed to the emergence of related ransomware families such as Lynx and Sinobi.
Evolution of Ransomware INC
Discovered in mid-2023, INC is a Ransomware-as-a-Service (RaaS) group that uses double extortion tactics. Since its inception, it has gained notoriety by aggressively targeting high-profile organizations across multiple sectors, with an initial focus on education and healthcare. Operationally, it evolved rapidly between 2023 and 2025. Within months, a Linux/ESXi variant observed in real-world attacks appeared, designed to target VMware infrastructures, reflecting a broader trend in the ransomware landscape: maximizing impact by encrypting hypervisors and the virtual machines they host. At the same time, the group also continued to improve the Windows variant. In more recent releases, both payloads have been rewritten in Rust, making malware analysis and detection more complex while facilitating cross-platform development and deployment.
In addition to perfecting its encryption malware, INC ransomware has expanded its network of collaborations. At the end of 2024 it was observed the Vice Society group use INC ransomware in attacks against the healthcare sector. Furthermore, following the enforcement operations that targeted LockBit and the closure of BlackCat, several affiliates of these groups would have merged into the INC ecosystem. In May 2024 the source code of INC it was also put up for sale by an underground forum user known by the name “salfetka”. Shortly after the announcement was published, the Lynx ransomware operation emerged, showing significant code overlap with INC. Then Sinobi ransomware appeared. From this point on, the evolution of INC has followed two paths: while the original brand continues to operate autonomously, parts of its code base have spread into related ransomware operations, contributing to the emergence of new threats.
Victim profile and compromise techniques
Since 2023 INC ransomware has affected over 800 organizations globally. The United States accounts for 65.3% of all victims. Followed by Australia, Canada, Germany and Taiwan. The total absence of victims from the Commonwealth of Independent States (CIS) countries suggests that the operators may be based in that geographical area and that the affiliate program includes a ban on targeting organizations located in the CIS region. The sectors most affected in 2026 are legal services, manufacturing, technology, healthcare and construction. Law firms, in particular, constitute a particularly attractive target since the data in their possession includes documents relating to transactions, disputes, non-disclosure agreements (NDA) and numerous sensitive documents.
Affiliates of INC ransomware use a wide range of tools and techniques to compromise victims. More recent campaigns continue to leverage stale edge devices as the initial access vector, steal credentials from Veeam backup servers, and use a combination of LOLBin (Living-Off-the-Land Binaries) e Commercial Remote Monitoring and Management (RMM) tools to move within compromised networks.
Mitigation and recommendations
Below are some guidelines to prevent and mitigate this threat.
- Backup and Restore: Follow the 3-2-1 backup rule, keeping at least three copies of your data on two different storage media and keeping one in a separate location. It is also critical that backups are offline or immutable.
- Endpoint protection and ransomware defense: Implement EDR (Endpoint Detection and Response) solutions and specific protection tools capable of detecting unauthorized attempts at data encryption and exfiltration.
- Identity management and access control: Require the use of multi-factor authentication (MFA) and enforce the adoption of strong, complex and periodically updated passwords.
- Network segmentation and strengthening: Reduce the attack surface by segmenting networks, disabling unnecessary services and ports, and limiting outbound traffic to unauthorized destinations.
- Patch and vulnerability management: Implement a structured vulnerability and update management program on all company systems.
- User training and awareness. Train staff on the risks related to phishing, social engineering and other techniques used by ransomware operators.






