Also known as: Inc Ransom
INC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits. Known victims: 783
Objectives
Executive Summary
The incransom threat actor is a medium-sophistication criminal ransomware group targeting healthcare, government, education, and manufacturing sectors in North America and Europe. They employ spear-phishing campaigns, brute-force RDP attacks, and double extortion tactics to achieve financial gain through ransomware deployments. Since their emergence in 2023, they have victimized over 783 organizations, indicating a broad attack surface and strategic targeting of sectors with high data sensitivity.
Goals & Targeting
incransom's strategic objectives are centered on achieving financial gain through ransomware deployment. They target sectors where data is highly sensitive or critical, such as healthcare, government, education, and manufacturing, which often lack robust defenses or have limited recovery options. The group’s broad targeting approach suggests they aim to maximize opportunities across various industries without concentrating efforts on specific sectors. Their geographic focus on North America and Europe reflects regions with a higher density of attractive targets and potentially more lucrative ransom payments.
Enhanced Description
incransom, also known as Inc Ransom, is a prolific ransomware-as-a-service (RaaS) operation that has been actively exploiting vulnerabilities across multiple industries. Their modus operandi includes launching spear-phishing attacks using macro-laced Office documents to gain initial access to victim networks. Once inside, they often deploy brute-force methods to compromise Remote Desktop Protocol (RDP) services, followed by the deployment of double extortion ransomware payloads. The group systematically targets healthcare providers for their sensitive patient data, government agencies for high-value information, educational institutions with limited defenses, and manufacturing firms for proprietary information. Their campaigns are characterized by a high volume of受害者 and a broad geographic focus across North America and Europe. The incransom actors have demonstrated the ability to adapt their tactics over time, indicating a level of operational maturity that aligns with medium-sophistication threat groups. Their activities have caused significant disruptions to victim organizations, leading to financial losses and reputational damage.
Key Capabilities
Software / Tooling
IOC Patterns
Recommended Actions
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
209
Campaigns
1
IOCs
0
Observed Data
0
Tactics