Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors incransom

Also known as: Inc Ransom

Description

INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits. Known victims: 783

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The incransom threat actor is a medium-sophistication criminal ransomware group targeting healthcare, government, education, and manufacturing sectors in North America and Europe. They employ spear-phishing campaigns, brute-force RDP attacks, and double extortion tactics to achieve financial gain through ransomware deployments. Since their emergence in 2023, they have victimized over 783 organizations, indicating a broad attack surface and strategic targeting of sectors with high data sensitivity.

Goals & Targeting

incransom's strategic objectives are centered on achieving financial gain through ransomware deployment. They target sectors where data is highly sensitive or critical, such as healthcare, government, education, and manufacturing, which often lack robust defenses or have limited recovery options. The group’s broad targeting approach suggests they aim to maximize opportunities across various industries without concentrating efforts on specific sectors. Their geographic focus on North America and Europe reflects regions with a higher density of attractive targets and potentially more lucrative ransom payments.

Enhanced Description

incransom, also known as Inc Ransom, is a prolific ransomware-as-a-service (RaaS) operation that has been actively exploiting vulnerabilities across multiple industries. Their modus operandi includes launching spear-phishing attacks using macro-laced Office documents to gain initial access to victim networks. Once inside, they often deploy brute-force methods to compromise Remote Desktop Protocol (RDP) services, followed by the deployment of double extortion ransomware payloads. The group systematically targets healthcare providers for their sensitive patient data, government agencies for high-value information, educational institutions with limited defenses, and manufacturing firms for proprietary information. Their campaigns are characterized by a high volume of受害者 and a broad geographic focus across North America and Europe. The incransom actors have demonstrated the ability to adapt their tactics over time, indicating a level of operational maturity that aligns with medium-sophistication threat groups. Their activities have caused significant disruptions to victim organizations, leading to financial losses and reputational damage.

Key Capabilities

  • Ransomware deployment
  • Spear-phishing with malicious Office attachments
  • Brute-force RDP access
  • Double extortion tactics (data exfiltration + encryption)
  • Advanced persistence techniques

Software / Tooling

Phishing kits for malicious Office documents
RDP brute-force tools
Double extortion ransomware payloads
Network monitoring tools for lateral movement

IOC Patterns

  • ip-v4, 178.20.41.208
  • url, .*incransom[.]red

Recommended Actions

  • Implement multi-factor authentication (MFA) for RDP access.
  • Enhance email filtering to detect spear-phishing attempts.
  • Conduct regular vulnerability scans and apply patches promptly.
  • Encrypt backups and store them offline or in secure cloud storage.
  • Monitor network traffic for signs of brute-force attacks and lateral movement.
  • Educate employees on phishing awareness through regular training sessions.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

209

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 6, 2023
Last Seen
Aug 8, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.