# INC Ransomware

> As of 2026-08-12, INC Ransomware is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, threat intel. ATT&CK coverage spans 76 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1021 (Remote Services), T1040 (Network Sniffing), T1041 (Exfiltration Over C2 Channel).

- **Tracked threats:** 2
- **Categories:** VULNERABILITY, THREAT_INTEL
- **As of:** 2026-08-12

## ATT&CK techniques observed

76 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (13), Command and Control (8), Credential Access (8), Persistence (8), Discovery (6), Lateral Movement (5).

- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 2 tracked threats
- [T1040](https://intel.threadlinqs.com/technique/T1040) Network Sniffing — Credential Access — observed in 2 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 2 of 2 tracked threats
- [T1110](https://intel.threadlinqs.com/technique/T1110) Brute Force — Credential Access — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 2 of 2 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 2 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 2 of 2 tracked threats
- [T1595](https://intel.threadlinqs.com/technique/T1595) Active Scanning — Reconnaissance — observed in 2 of 2 tracked threats

## Tracked threats

- [SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-1462) — CRITICAL
- [FortiBleed: Russian-Speaking Credential-Harvesting Campaign Against Internet-Exposed FortiGate Firewalls and SSL VPN Gateways](https://intel.threadlinqs.com/threat/TL-2026-0895) — HIGH

## Related CVEs

2 CVEs referenced by tracked INC Ransomware activity.

- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/INC%20Ransomware
