Activity timeline
INC Ransom - G1032 appears in 5 tracked threats between and ; the busiest month was 2026-07 with 2 reports.
ATT&CK techniques observed
- T1133 External Remote Services — Initial Accessobserved in 5 of 5 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 5 of 5 tracked threats
- T1078 Valid Accounts — Initial Accessobserved in 4 of 5 tracked threats
- T1595 Active Scanning — Reconnaissanceobserved in 4 of 5 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 3 of 5 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 5 tracked threats
- T1040 Network Sniffing — Credential Accessobserved in 3 of 5 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 3 of 5 tracked threats
- T1087 Account Discovery — Discoveryobserved in 3 of 5 tracked threats
- T1090 Proxy — Command and Controlobserved in 3 of 5 tracked threats
- T1098 Account Manipulation — Persistenceobserved in 3 of 5 tracked threats
- T1110 Brute Force — Credential Accessobserved in 3 of 5 tracked threats
- T1136 Create Account — Persistenceobserved in 3 of 5 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 3 of 5 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 3 of 5 tracked threats
Tracked threats
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate DevicesHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)CRITICAL
- FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx RansomwareCRITICAL
- FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN GatewaysHIGH
Related CVEs
- CVE-2026-50752
- CVE-2026-50751
- CVE-2026-25815
- CVE-2026-24858
- CVE-2026-12569
- CVE-2026-0257
- CVE-2025-68686
- CVE-2025-59719
- CVE-2025-59718
- CVE-2025-30406
- CVE-2025-14611
- CVE-2025-11371
- CVE-2024-55591
- CVE-2024-53704
- CVE-2024-40766
- CVE-2024-27198
- CVE-2024-23113
- CVE-2024-21762
- CVE-2023-4966
- CVE-2023-48788
- CVE-2023-3519
- CVE-2023-27997
- CVE-2022-42475
- CVE-2022-41328
- CVE-2022-40684
- CVE-2018-13379