# INC Ransom

> As of 2026-09-15, INC Ransom is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning ransomware, campaign, threat intel. Also known as INC Ransom - G1032, Lynx, INC Ransomware, GOLD IONIC. ATT&CK coverage spans 102 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1078 (Valid Accounts), T1133 (External Remote Services).

- **Nation:** Russia
- **Tracked threats:** 6
- **Categories:** RANSOMWARE, CAMPAIGN, THREAT_INTEL
- **Also known as:** INC Ransom - G1032, Lynx, INC Ransomware, GOLD IONIC, G1032, INC Ransom Group
- **As of:** 2026-09-15

## ATT&CK techniques observed

102 techniques observed across 6 of 6 tracked threats. Tactics: Command and Control (12), Credential Access (12), Discovery (11), Resource Development (10), Impact (8), Reconnaissance (7).

- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 6 of 6 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 5 of 6 tracked threats
- [T1133](https://intel.threadlinqs.com/technique/T1133) External Remote Services — Initial Access — observed in 5 of 6 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 4 of 6 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 4 of 6 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 4 of 6 tracked threats
- [T1588](https://intel.threadlinqs.com/technique/T1588) Obtain Capabilities — Resource Development — observed in 4 of 6 tracked threats
- [T1595](https://intel.threadlinqs.com/technique/T1595) Active Scanning — Reconnaissance — observed in 4 of 6 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 3 of 6 tracked threats
- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 3 of 6 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 6 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 3 of 6 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 6 tracked threats
- [T1074](https://intel.threadlinqs.com/technique/T1074) Data Staged — Collection — observed in 3 of 6 tracked threats

## Tracked threats

- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)](https://intel.threadlinqs.com/threat/TL-2026-2125) — HIGH
- [FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries)](https://intel.threadlinqs.com/threat/TL-2026-1232) — CRITICAL
- [FortiBleed Credential Theft Campaign: FortigateSniffer Tool Deployed Against 430,000+ FortiGate Firewalls, Linked to INC Ransom and Lynx Ransomware](https://intel.threadlinqs.com/threat/TL-2026-1124) — CRITICAL
- [FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways](https://intel.threadlinqs.com/threat/TL-2026-0895) — HIGH
- [INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)](https://intel.threadlinqs.com/threat/TL-2026-0199) — CRITICAL

## Related CVEs

27 CVEs referenced by tracked INC Ransom activity.

- [CVE-2026-50752](https://intel.threadlinqs.com/cve/CVE-2026-50752)
- [CVE-2026-50751](https://intel.threadlinqs.com/cve/CVE-2026-50751)
- [CVE-2026-25815](https://intel.threadlinqs.com/cve/CVE-2026-25815)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2025-68686](https://intel.threadlinqs.com/cve/CVE-2025-68686)
- [CVE-2025-59719](https://intel.threadlinqs.com/cve/CVE-2025-59719)
- [CVE-2025-59718](https://intel.threadlinqs.com/cve/CVE-2025-59718)
- [CVE-2025-30406](https://intel.threadlinqs.com/cve/CVE-2025-30406)
- [CVE-2025-14611](https://intel.threadlinqs.com/cve/CVE-2025-14611)
- [CVE-2025-11371](https://intel.threadlinqs.com/cve/CVE-2025-11371)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-27198](https://intel.threadlinqs.com/cve/CVE-2024-27198)
- [CVE-2024-23113](https://intel.threadlinqs.com/cve/CVE-2024-23113)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-48788](https://intel.threadlinqs.com/cve/CVE-2023-48788)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2022-42475](https://intel.threadlinqs.com/cve/CVE-2022-42475)
- [CVE-2022-41328](https://intel.threadlinqs.com/cve/CVE-2022-41328)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/INC%20Ransom
