Activity timeline
INC Ransom appears in 6 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 6 of 6 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 5 of 6 tracked threats
- T1133 External Remote Services — Initial Accessobserved in 5 of 6 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 4 of 6 tracked threats
- T1087 Account Discovery — Discoveryobserved in 4 of 6 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 4 of 6 tracked threats
- T1588 Obtain Capabilities — Resource Developmentobserved in 4 of 6 tracked threats
- T1595 Active Scanning — Reconnaissanceobserved in 4 of 6 tracked threats
- T1003 OS Credential Dumping — Credential Accessobserved in 3 of 6 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 3 of 6 tracked threats
- T1040 Network Sniffing — Credential Accessobserved in 3 of 6 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 6 tracked threats
- T1046 Network Service Discovery — Discoveryobserved in 3 of 6 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 3 of 6 tracked threats
- T1074 Data Staged — Collectionobserved in 3 of 6 tracked threats
Tracked threats
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)CRITICAL
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx RansomwareCRITICAL
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN GatewaysHIGH
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)CRITICAL
Related CVEs
- CVE-2026-50752
- CVE-2026-50751
- CVE-2026-25815
- CVE-2026-24858
- CVE-2026-12569
- CVE-2026-0257
- CVE-2025-68686
- CVE-2025-59719
- CVE-2025-59718
- CVE-2025-30406
- CVE-2025-14611
- CVE-2025-11371
- CVE-2024-57727
- CVE-2024-55591
- CVE-2024-53704
- CVE-2024-40766
- CVE-2024-27198
- CVE-2024-23113
- CVE-2024-21762
- CVE-2023-4966
- CVE-2023-48788
- CVE-2023-3519
- CVE-2023-27997
- CVE-2022-42475
- CVE-2022-41328
- CVE-2022-40684
- CVE-2018-13379